Deploying Biztalk Web Service to DMZ
We have a DMZ with an IIS Web Server, and BizTalk 2009 on a LAN. I'd like to know what is the best way to deploy a BizTalk Web Service so that it is publicly accessible on the Internet, but inline with security best practices. Should we deploy the BizTalk-generated Web Service to the IIS box? Should we host the Web Service on the BizTalk box and expose BizTalk to the world (for specific ports and specific external IP's only)? Should we use IIS as a reverse proxy and host the Web Service on BizTalk? Any guidance much appreciated. I would seriously think about separating the web service from the