Hi,

I am having trouble with a form built with Front Page 2003, running on SBS
2003 (and using FPSE). When someone external to my network tries to submit
the form, they get the error message "You are not authorized to view this
page"...."HTTP Error 403.6 - Forbidden: IP address of the client has been
rejected.".

If I submit the form from internally, everything works fine.

The form is set to write to a file in the _private folder, and send an
email. Both of these are happening okay when performed internally.

I've checked the security settings for the pages and they all seem okay,
meaning anonymous access has been granted, and there are no restrictions on
IP addresses.

The only thing I can see is that the folder _VTI_BIN has restrictions on the
IP addresses (set to my server IP and 127.0.0.1). I'm not sure if I should
remove these IP restrictions in case I'm opening up a security hole.

Any ideas?

Thanks in advance.

Regards
Antony

Re: Security Settings on _vti_bin Folder by Antony

Antony
Mon May 09 08:04:01 CDT 2005

Update: By removing the IP address restrictions for the _VTI_BIN folder,
outside users can now submit the form successfully.

Any thoughts on security concerns by doing this?


Regards
Antony


"Antony" <antony@nodomainname.com> wrote in message
news:0WIfe.7807$31.183@news-server.bigpond.net.au...
> Hi,
>
> I am having trouble with a form built with Front Page 2003, running on SBS
> 2003 (and using FPSE). When someone external to my network tries to submit
> the form, they get the error message "You are not authorized to view this
> page"...."HTTP Error 403.6 - Forbidden: IP address of the client has been
> rejected.".
>
> If I submit the form from internally, everything works fine.
>
> The form is set to write to a file in the _private folder, and send an
> email. Both of these are happening okay when performed internally.
>
> I've checked the security settings for the pages and they all seem okay,
> meaning anonymous access has been granted, and there are no restrictions
> on IP addresses.
>
> The only thing I can see is that the folder _VTI_BIN has restrictions on
> the IP addresses (set to my server IP and 127.0.0.1). I'm not sure if I
> should remove these IP restrictions in case I'm opening up a security
> hole.
>
> Any ideas?
>
> Thanks in advance.
>
> Regards
> Antony
>