In my organization we have a Win2003+IIS6.0 server with a website available
on the Internet. Such webserver resides in the internal network. File &
Print Sharing for MS Networks is enabled on this box. We have internal users
that access this server via UNC path and update the website there by dumping
content to the \\myserver\share-iis.
Question is this, if I use a reverse proxy (ISA 2004) to publish such
website that resides on this Win2003 server, do you consider it is alright
leaving this box as is ? I mean, leave it with access via NetBIOS (F&P
sharing) enabled so that people can use from the internal network ?
Or it would be considerably more secure work setting up a staging server and
leave this box only as a webserver ? Then put a tool on the Webserver that
could upload content from the 'staging' server ?
The point is here is this, do you think the fact I am publishing this via
ISA 2004 (or any similar product) makes this secure enough to keep File &
Print sharing turned on ?