Home > Ask the Windows Server Experts > Questions & Answers > Is it possible to password protect a Web server remotely?
Ask The Windows Server Expert: Questions & Answers
EMAIL THIS

Is it possible to password protect a Web server remotely?

Tony Northrup EXPERT RESPONSE FROM: Tony Northrup

Pose a Question
Other Windows Server Categories
Meet all Windows Server Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 February 2004
We have a Windows 2000 Server running IIS 5 on a university campus. I would like to know if it is possible to password protect the Web server if accessed from outside the campus. Also, can we allow 'no password' access from within the campus? We achieved this with our Linux Web server which runs Apache, but we still need a Windows Web server as well.

>

This is a bit tricky, but I think it will work. First, configure your IIS server with two IP addresses: one for the internal Web site, and one for the external Web site.

Second, modify the Web server's record on your internal DNS server so that it resolves to the Web site's internal IP address. The Web server's public DNS record should still resolve to the Web site's external IP address.

Third, create a second Web site within IIS and configure it exactly the same as the current Web site except for one key difference: it listens for requests on the external IP address only. To modify this setting, launch Internet Services Manager, view the external Web site's properties, and then click the Web Site tab. Click the Advanced button, click the Add button, and specify the external IP address. Click OK to return to the Web Site Properties dialog, and then click the Directory Security tab. Click the Edit button in the "Anonymous Access And Authentication Control" grouping, and clear the Anonymous Access checkbox. Now you have one Web site that requires authentication.

Finally, view the properties of the original (now the internal) Web site. Click the Directory Security tab, and then click the Edit button in the "IP Address And Domain Name Restrictions" grouping. Select the Denied Access radio button. Then, click the Add button. On the Deny Access On dialog, select Group Of Computers, and specify the Network ID and Subnet Mask of a subnet on your campus that you do not want to require authentication for. Repeat this process until every network address has been added.

That should do it. Good luck. If you have development skills, you could create an ISAPI filter or an ASP.NET application to handle this, but I prefer solutions that don't involve writing code.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Windows Server Solutions - Intel Hardware Solutions
HomeTopicsBlogsITKnowledge ExchangeTipsNewsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts