Security: IIS Login to server w. SQL Server only

I want to add a webinterface to an existing windows based solution running
SQL server 2005 and MS Access. The SQL server is based on the company's
intranet.
I'm thinking of:
1) Adding a new server, NewSrvr, (2003) running IIS 6 outside a firewall and
2) Making whatever restrictions necessary to prevent any security breaches.

NewSrvr will be stand alone and not running other sites.
I intend to have the web app. developed in asp.net 2.0 and communicating
with the SQL Server only by means of Stored Procedures.

Will a simple firewall be enough in order to achieve 2) ?
I suppose it is the safest NOT to let NewSrvr join any domains?

Any comments on the setup of IIS in this regard is also welcome.

--
Ruben Lysemose, Systems Consultant
RubenL [ Mi, 05 September 2007 16:08 ] [ ID #1813047 ]
Webserver » microsoft.public.inetserver.iis.security » Security: IIS Login to server w. SQL Server only

Vorheriges Thema: restrict website access to single IP
Nächstes Thema: Client Certificate Auth only for certain urls handled by ISAPI fil