<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Patching Webserver on DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/patching-webserver-on-dmz/m-p/805687#M977307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is good practice if at all possible to not allow connections from the DMZ into your internal network. Obviously this is not always possible but if you can avoid i you should. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the SUS server can push updates to the web server in the DMZ that is preferable to the web server contacting the SUS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise as you say you can deploy a SUS server in the DMZ which is then used to update the web server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Jun 2007 07:46:55 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-06-29T07:46:55Z</dc:date>
    <item>
      <title>Patching Webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/patching-webserver-on-dmz/m-p/805686#M977306</link>
      <description>&lt;P&gt;I would like to know what other companys out there doing to patch servers that's in the DMZ.  Do you allow connections between the Webserver in the DMZ to your Internal/Inside SUS? if not, do you have an SUS server on the DMZ that have internet access and collect security updates and push this security updates to the Webserver in the DMZ?  i would like to know the best practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/patching-webserver-on-dmz/m-p/805686#M977306</guid>
      <dc:creator>nocret808</dc:creator>
      <dc:date>2019-03-11T10:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Patching Webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/patching-webserver-on-dmz/m-p/805687#M977307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is good practice if at all possible to not allow connections from the DMZ into your internal network. Obviously this is not always possible but if you can avoid i you should. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the SUS server can push updates to the web server in the DMZ that is preferable to the web server contacting the SUS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise as you say you can deploy a SUS server in the DMZ which is then used to update the web server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2007 07:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/patching-webserver-on-dmz/m-p/805687#M977307</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-06-29T07:46:55Z</dc:date>
    </item>
  </channel>
</rss>

