A production website hosted on an on-premises IIS server was directly exposed to the public internet. Here's how we closed that exposure without any disruption in service.
A business serving its production website from an on-premises IIS server.
The production website was hosted on an on-premises IIS server directly exposed to the public internet, widening the organization's attack surface. It needed a secure, cloud-based entry point that could inspect and filter all inbound traffic, protect against common web-based attacks, and eliminate that direct exposure — without disrupting uptime or the existing Site-to-Site VPN connectivity to Azure.
We deployed Azure Front Door Premium in front of the client's production website and layered in Azure Web Application Firewall using Microsoft's managed rule sets to inspect and filter all inbound traffic before it ever reaches the origin. Rather than leaving the on-premises IIS server directly reachable from the internet, we pointed public DNS to Front Door and routed approved traffic back to the on-premises server through the existing Site-to-Site VPN connection, closing off the server's direct public exposure entirely.
The production website remains publicly accessible with no interruption in service, but the on-premises IIS server is no longer directly reachable from the internet. All inbound traffic is now inspected, filtered, and protected centrally through Azure Front Door and WAF, significantly reducing the external attack surface and giving the client one consolidated point of control over web traffic security.
Related service: Microsoft 365 & Cloud Support in West Palm Beach
Let’s talk about closing that exposure without touching your uptime.
Get a Free IT Assessment