Customer wants to access webclient via internet. Using NAT on Port 80, he can access Director and Webclient on port 80. What are the dangers of this?
Announcement
Collapse
Welcome to ShoreTelForums.com
Welcome to ShoreTelForums.com!
This site was created as a place to share stories, tips, and troubleshooting help with ShoreTel/Mitel systems. ShoreTel/Mitel is obviously the MOST exciting VoiP platform on the market right now, and we realized there was no centralized place to discuss this platform, but now there is. Please feel free to join and share your experiences.
Please Note: This site IS NOT owned, funded, or managed by ShoreTel/Mitel, Inc. although you may find ShoreTel/Mitel employees sharing there experiences and expertise. If you would like more information on ShoreTel/Mitel systems, contact BTX at [email protected]
As always please support the advertisers that help support our site.
Thank You,
BTX
This site was created as a place to share stories, tips, and troubleshooting help with ShoreTel/Mitel systems. ShoreTel/Mitel is obviously the MOST exciting VoiP platform on the market right now, and we realized there was no centralized place to discuss this platform, but now there is. Please feel free to join and share your experiences.
Please Note: This site IS NOT owned, funded, or managed by ShoreTel/Mitel, Inc. although you may find ShoreTel/Mitel employees sharing there experiences and expertise. If you would like more information on ShoreTel/Mitel systems, contact BTX at [email protected]
As always please support the advertisers that help support our site.
Thank You,
BTX
See more
See less
X
-
THe danger in this is that all traffic over port 80 is in plain text. I have not really tested the ST site to see how secure it is. You can do a couple of things to secure it more.
If you firewall supports protocol translation you could do it that way. Meaning send the traffic over the Internet over 443 and then translated it to port 80 on the LAN side. A Sonicwall Pro 2040 with enhanced OS can do this as well as many other high end Firewalls.
You could limit the source address allowed to connect to the sites inside of IIS. If you do this you will need to readded the changes after an upgrade, as the site setting revert back to default after an upgrade. You would want to grant all of you LAN address and only the addresses on the Internet that you want to access the director fromThere are 10 types of people in the world, those that understand binary and those that don’t.
-
Comment