10.2.4. External Service Hosts
Bastion hosts that exist solely to provide services to the Internet
(for instance, web servers used to provide service to customers) have
special concerns. They are extremely visible, which makes them
popular targets for attack, and increases the visibility of
successful attacks. If a machine that provides mail service for
internal users is compromised, it's not going to be immediately
obvious to outsiders, and it's unlikely to make it into the
newspaper. If your web site is replaced by somebody else's
page, or a clever satire of your web site, that's something
people outside your site will notice and care about.
Although these machines have increased needs for security, they have
some features that make them easier to secure. They need only limited
access to the internal network; they usually provide only a few
services, with well-defined security characteristics; and they
don't need to support internal users (often, they don't
need to support any users at all).