Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  1. Fotoware Alto
    • Release Notes
    • End-User Manual
    • Solutions
    • Terminology
    • User Guides
    • API Changelog
  2. Fotoware Veloz
    • Fotoware Veloz releases
    • Managing users and groups
    • Configuring archives
    • Configuring workflows
    • Configuring site behavior
    • Navigating and searching to find your assets
    • Working with your assets
    • Editing asset metadata
    • Uploading files
    • Version Control in Fotoware
    • Albums - Creating and sharing collections
    • Placing assets in a Content Management System (CMS)
    • Working with the Fotoware Pro interface
    • Using the Fotoware plugins
    • Consent management
    • User guide to FotoWeb for iPad (Legacy)
    • Picture conferencing with FotoWeb Screens (Legacy)
    • What's what in Fotoware
    • GDPR
    • Activity Exports
    • Example workflows
  3. Fotostation
    • Getting started with Fotostation
    • Viewing, selecting and sorting files
    • Managing your assets with archives
    • Adding metadata to assets in Fotostation
    • Searching for assets
    • Working with your assets
    • Version Control in Fotostation
    • Automating tasks with Actions
    • Configuring metadata fields and editors
    • Configuring Fotostation
    • Configuring Fotostation for multi-user environments
    • Troubleshooting Fotostation
  4. Fotoware Flow
    • About Flow
    • Getting started
    • Flow dictionary
  5. Fotoware On-premises
    • Fotoware On-premises releases
    • Getting started
    • Index Manager
    • FotoWeb
    • Color Factory
    • Connect
    • Operations Center Guide
  6. Integrations and APIs
    • Fotoware Alto API
    • Fotoware Veloz and On-premises API
  7. Fotoware Mobile
    • User guide for Fotoware Mobile for iPhone and Android
    • User guide to FotoWeb for iPad (Legacy)
    • User guide to FotoWeb for iPhone and Android (Legacy)

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

Support

Table of Contents

Overview Implications of securing a web server Network security Placing your server directly on the Internet Protecting your internal LAN behind a firewall Placing FotoWeb in a DMZ Placing all servers in the DMZ Using mirrored systems
  • Home
  • Fotoware On-premises
  • FotoWeb
  • Securing your server (On-premises)

Choosing where to place FotoWeb in your network

04. August 2026

Elaine Foley

Table of Contents

Overview Implications of securing a web server Network security Placing your server directly on the Internet Protecting your internal LAN behind a firewall Placing FotoWeb in a DMZ Placing all servers in the DMZ Using mirrored systems

Overview

This topic discusses how your FotoWeb can be implemented in your network and the effect this has on security.

Implications of securing a web server

Running a web server on the Internet requires knowledge about many security issues. FotoWeb has been designed to fit into the Windows security model. The concepts for managing security in FotoWeb should therefore already be known by those familiar with Windows security.

FotoWeb uses the Process Account configured in the Operations Center to run the system. The account password is stored in encrypted form in the FotoWeb configuration files. If you change the account passwords in Windows, you must always remember to update the password in the Operations Center, and in IIS if your FotoWeb is hosted on that web server. If you try to start FotoWeb with the wrong password, the account may be locked out by Windows, and FotoWeb will not work correctly until you enter the correct password and unlock the account using the user administration tools in Windows.

Network security

Even if FotoWeb is designed to be secure, most hackers will exploit vulnerabilities in widely known network hardware and software. You should always consult someone with strong knowledge of these areas before putting your server on the Internet.

The network topologies shown in this chapter are examples of different configurations, each with different tradeoffs in security, functionality, and performance. Which one you choose to implement, or whether you choose a different topology, depends on your security needs, which functionality is important to you, and your budget. This chapter is included in this document for informational purposes only. Always consult someone with first-hand knowledge of security before choosing or implementing any of these suggestions. Other solutions not mentioned here may also prove better in your scenario.
 

Placing your server directly on the Internet

Placing your server directly on the Internet is an affordable solution. It ensures that a firewall completely protects your internal LAN. It is also an optimal solution for performance, as users have direct access to the FotoWeb server.

With this topology, it is difficult, or even impossible, to secure the operating system from hacker attacks, and it is not recommended unless performance or budget is a key issue.
 

Protecting your internal LAN behind a firewall

Another affordable option is to place the FotoWeb server on your internal LAN, which is protected by a firewall or a packet filtering router. The firewall must be configured to allow HTTP traffic to pass through to the FotoWeb server.

In addition to providing basic protection for your server behind a firewall, this setup allows your internal users to work directly with the archive using the Fotostation or FotoWeb clients. It is easy to manage your servers, and your internal users have optimal performance when accessing the archives.

However, if a hacker compromises your web server, your entire network will be vulnerable to attack.
 

Placing FotoWeb in a DMZ

 

More advanced firewalls can be configured with one or more ‘Demilitarized Zones’. A DMZ is a separate network where you can place servers that are accessible from the Internet. In this configuration, internal users can work with the archive using Fotostation at full speed and with functionality. The firewall needs to be configured so that the FotoWeb server can access the share containing the documents on the Index Manager server and to communicate with the Index Manager server over IP (port 7000 by default). FotoWeb accesses the document folders using standard Windows shares (using the NETBIOS protocol).

This solution is not optimal from a performance standpoint. FotoWeb needs to access all the files through the firewall, which can significantly affect performance. A hacker may also be able to exploit this tunnel in the firewall to attack the internal LAN after compromising the web server.
 

Placing all servers in the DMZ

Using a firewall with DMZ capability, you can place both the Index Manager and FotoWeb servers in the DMZ. The firewall allows traffic to the DMZ, but not to the internal LAN. Even if a user can compromise your web server, it is still impossible to attack the internal LAN.

This solution affects the performance of internal users. If they are using Fotostation to manage the archive, all access must pass through the firewall, which is slower than when the server is on the same network. However, the security gained by this solution may justify the performance degradation.
 

Using mirrored systems

If you have a large production workflow on your servers, it may not be a good option to access the document archive through the firewall as in the previous example. In this case, you may benefit from running duplicate servers. One set of servers is accessible from the internet, while another set is private to your internal LAN. This introduces complexity in duplicating data between the systems, but ensures maximum performance and security. However, it introduces the costs of licensing the software for more servers.

If you have a production workflow in your internal system and only provide a subset of the documents in the external archive (for example, the production results), this solution is ideal.

A one-way mirror is also quite easy to implement. However, if changes are made in both systems, this solution may present challenges that are either very difficult or impossible to implement.

 
 
network placement location selection

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Installing Index Manager
  • Installing FotoWeb - choosing the right process
  • Installing Fotoware in an offline environment
eco-lighthouse-miljøfyrtårn

Company

  • About us
  • Resellers
  • Careers
  • Contact us

Help & support

  • Support center
  • Consultancy
  • Tech partners
  • Fotostation
  • System status

Trust Center

  • Legal
  • Security
  • Sustainability & ESG

Locations

Fotoware AS (HQ)
Tollbugata 35
0157 OSLO
Norway
Fotoware Switzerland AG
Brown Boveri Str.7
5400 Baden
Switzerland

Copyright 2026 Fotoware All rights reserved.

  • Terms of service
  • Privacy policy
  • Cookie policy

Knowledge Base Software powered by Helpjuice

Expand