3.9 Ensure that SharePoint application servers are protected by a reverse proxy

Information

A reverse proxy is server component that sits between the internet and the web servers. It accepts HTTP requests, provides various services, and forwards the requests to one or many servers.
Rationale:
Having a point at which one can inspect, transform and route HTTP requests before they reach the SharePoint web servers provides significant benefits. A reverse proxy can hide the topology and characteristics of the back-end SharePoint servers by removing the need for direct internet access. A reverse proxy can be placed in an internet facing DMZ, and hide the SharePoint web servers inside a non-public subnet.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Implement a reverse proxy to process all HTTP requests and route them to the SharePoint servers.
Impact:
A malicious attacker can directly attack a SharePoint server that is placed in the DMZ.

See Also

https://workbench.cisecurity.org/files/2031

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|12

Plugin: Windows

Control ID: 7383c884f0751fa688161692f61ab3a8f6a899b089f270be6d4526bd570726a8