SQL Server and ISA Server on the web

From: Julia Lerman (jlerman@thedatafarm.com)
Date: 07/22/02


From: "Julia Lerman" <jlerman@thedatafarm.com>
Date: Mon, 22 Jul 2002 11:43:28 -0400


We are about to open up our own network onto the web via ISA Server.

Currently we are using Win2K Server, SQL Server 7, IIS 5.0 and the latest sp
of ISA Server.

Let me preface this by saying: "I'm just the programmer!!" and, by default,
the SQL Server admin, but that's just because nobody else knows anything
about it and I want to make sure that all of my inhouse apps functino
properly!

The network guy who has decided he feels safe opening up this stuff so that
we don't have to deal with ftp replication to another webhost etc, has asked
me (who ain't no internet security expert) to make sure that the SQL Server
data will be safe.

I'm very nervous about this responsibility and may just end up passing it on
to someone with more expertise!

Currently, we have two databases in the SQL Server. One is the main in-house
database used by our in-house desktop apps. The other is a replicated
database (based on queries from the main) that is used by our internal
website. So the database connections in the asp pages go to the replicated
database. They don't touch the first one. The internal website is what we
are going to expose so that employees can get at it remotely.

There is a hardware firewall and ISA Server on top of all of this (which I
know very little about). And access to the website is password protected
using a login table in the database (including pages that check for that
valid login before access those specific pages), what should I be looking at
in terms of potentially exposing the databases? The network guy (mentioned
above) says he wants to "lock down" the server as much as possible. We
already have a handful of computers that are having trouble with the website
internally since he put in the ISA server.

So, since this is a complicated issue, and obviously affected by a lot of
variables, WHERE should I be looking for information on this?

Thanks much.

Julia Lerman



Relevant Pages

  • Re: Gracefull shutdown firewall after logging error
    ... why can't the logging service obtain a lock on the db. ... The ISA Server Web filter was unable to connect to MSDE database. ... Could not obtain exclusive lock on database 'MODEL'. ...
    (microsoft.public.windows.server.sbs)
  • Re: Gracefull shutdown firewall after logging error
    ... The ISA Server Web filter was unable to connect to MSDE database. ... The MSDE Error description is: Could not obtain exclusive lock on database 'MODEL'. ... on the right hand side click on configure firewall logging ...
    (microsoft.public.windows.server.sbs)
  • ISA Server DestinationSet Performance
    ... I'm retreiving 41140 rows from the database, storing them in a hash table ... Getting 41140 rows from the ISA server destination set takes me an awsome ... I use a enumerator to work through the FPCDestinationSet (there is no other ...
    (microsoft.public.dotnet.languages.csharp)
  • ISA + PIX525 cant publish website
    ... connect internet, ISA server only one network card,it is NAT by pix525.we ... want publish inside network website, ...
    (microsoft.public.isaserver)
  • Re: logging question
    ... ISA Server includes a log maintenance feature, ... storage limits" and "Log storage format." ... and by default logging is done to this database. ...
    (microsoft.public.isa)

Quantcast