Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9209423
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 18, 20262026-06-18T00:50:21+00:00 2026-06-18T00:50:21+00:00

I have been writing WCF services for internal use for quite a while (alongside

  • 0

I have been writing WCF services for internal use for quite a while (alongside WinForms and MVC web apps). However, I now need to expose one of the services to the great unwashed!

Since this is from a single source company I proposed the following:

Architecture

  • Company uses VPN to send request to our DMZ server over HTTPS/SSL
    • DMZ firewall only allows specific Company IP
  • DMZ IIS server passes request to our internal IIS server
    • Internal firewall only allows DMZ server INTERNAL FACING IP
  • Internal IIS WCF service consumes request and sends response back up the chain.

However, my IT manager wants more than this and more…in detail.

e.g.

  • What accounts to use or create, and what permissions to give them.
  • How to limit public facing IIS server from being DoS’d, hacked, etc.
  • How to stop public facing IIS server displaying “secure” details accidentally
    • What to turn off inside server/IIS
    • What files to restrict access to e.g. trace.axd

I can understand his reasons too – if it all goes ttsup, then he carries the can…whcih means ultimately I carry the can! From a background in mainframe and IBM/Websphere, all he hears about is how IIS is “not secure”.

I suspect that what he really hears is “devs/admins are not securing IIS/WCF properly”…so I want to try to do it “properly” !

(for info, I am going through Troy Hunt’s posts…but there’s a lot in here! I’ve tried going through MSDN’s reams of “kids drawing paper” and find oit very hard ot extract what I need to know from the endless “lets make this paragraph longer and sounds more important while hiding the salient facts” filler in there!)

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-18T00:50:23+00:00Added an answer on June 18, 2026 at 12:50 am

    Windows Server and IIS are secure. However, if you’re going to use this for say credit card transactions or other items that you don’t wan’t fall into the wrong hands, then you’ll need to secure the server further than the out of the box settings.

    This is a guide I used to hammer down a Windows 2008 R2 server with IIS 7.5 (patched to current standards) recently. You don’t have to use them all but it will help to secure the server at an extremely granular level. Also, the IIS link below is for 7.0 but it applies to 7.5 as well.

    Windows Server 2008 r2

    http://web.nvd.nist.gov/view/ncp/repository/checklistDetail?id=377

    IIS

    http://web.nvd.nist.gov/view/ncp/repository/checklistDetail?id=400

    It will take some time to go through as you will soon see but you be able to show what needs to be done to secure the server and product from the out of the box settings. You will also be able to draw up a document to give to your boss in what is going to be needed to secure your server.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have been writing web applications for quite sometime in PHP with MySQL. I
I have been writing linear winforms for couple of months and now I am
I have been writing DLL on C++, that will be use in C#. DLL
All, I have been writting Windows Services for a while in C# deriving from
I have been writing an OpenGL game engine for a while which uses SDL
I have been writing a small web application in C# .NET4.0 to try and
I have been writing simple bash scripts for a while now, and I was
I have been writing java for a while, and today I encountered the following
I have been writing apps for my Droid x2 using the new Android update
I am fairly new to web development & web services. I have been playing

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.