  Marilla I Am My Own Arbiter Premium join:2002-12-06 Belpre, OH
| reply to karan79 Re: Windows 2000 server
In my opinion, you need an external firewall for -any- web server. I feel that host-based firewalls (a sort of one of which is built in to Windows 2000, actually) are good, and all that.. but that a dedicated firewall appliance/server is a must for every single gateway to the Internet.
That said, Windows 2000 has built in two methods to permit only certain IPs to access a web site.
First, the built-in IPSec filtering can be used to prevent communications to certain ports/IPs on the server from certain IPs/networks, or allow ONLY from certain IPs/Networks (once you get a default block policy in)
Second, any web server software itself can be configured to permit connections only from certain networks/IPs, as well (including IIS and Apache, one of which you almost certainly will be using, I'm guessing).
However, on a side-note, I will re-iterate the importance of having a separate firewall protecting this system, as well. That could be an additional software-based one (though consumer-level products don't often easily work with server-level operating systems - purposefully), or a separate hardware firewall. The problem is, even if you protect your one site how you want, you still have lots of other things exposed on that server which need to be protected by a firewall. The built-in IPSec functionality can be used to help, but there are known ways around that. -- Windows, Mac, Linux, BSD - just use the right tool for the right job... end the OS Politics!
Real politics is much more interesting! www.georgewbush.com |