sql behind firewall

From: Brian Cidern (brian.cidern@noemail.please)
Date: 11/01/02


From: "Brian Cidern" <brian.cidern@noemail.please>
Date: Fri, 1 Nov 2002 14:28:01 -0800


Hi Antonio.

What we've done is to keep SQL Server behind the firewall,
opening port 1433. Then for apps to run, like EM and QA,
set up a VPN server that gets you inside your network and
you can connect to SQL via Windows Authentication.

What I did on my personal network is install Sygate
Personal Firewall Pro 5.x. and open the ports that I need
so that I can access the server resources (in and out).

By no means do I consider myself a security expert, I'm
just relaying what has worked for me in the past. Hope
this offers some insight.

Brian

>-----Original Message-----
>hi we want to put sql server 2000 behind a firewall
inside our domain.
> it is not for exposing to the internet but to protect it
from
>employees..
>
>should we install something like zone alarm or use a real
firewall
>box? we need to be able to have programs like terminal
server, ftp,
>antivirus updates, query analyser and enterprise manager
work through
>the firewall ..
>
>what is best to do?
>
>thanks friends
>ap
>.
>



Relevant Pages

  • Re: IS IT SAFE TO HOST SQL SERVER AND IIS SERVER ON THE SAME MACHINE
    ... > safe to host a web application on a mchine outside of our firewall ... and the sql server would reside on this one machine. ... The vulnerabilities of Windows, IIS and SQL are well known, so you ...
    (microsoft.public.inetserver.iis.security)
  • Re: Clickonce and license question question
    ... would prefer to change the way we license / register the application. ... updates the SQL server at our ISP that the license key is now in use. ... What about just meaking the company open their firewall for the server? ...
    (microsoft.public.dotnet.framework.windowsforms)
  • Re: Connection error from VBScript
    ... The only firewall we use is Windows Firewall and that is disabled by default ... -2147467259 from MS OLE DB Provider, Specified SQL Server not found. ... you only need TCP/IP connectivity and TCP port 1433 to ...
    (microsoft.public.data.ado)
  • Re: Replication over a firewall
    ... inbound access is required to pull the updates from the server. ... Most projects I've done where the firewall admin won't open a port ... for replication use a VPN to get around it. ... make sure you're running sql server and sql server agent under an ...
    (microsoft.public.sqlserver.ce)
  • Re: SQL Server 2000 behind ZoneAlarm Pro 4
    ... >it is creating a log file which is not manageable. ... ZoneAlarm is not really the best thing to protect a server. ... should have a hardware firewall for better ... allow SQL Server to access Trusted, and act as server for Trusted ...
    (comp.security.firewalls)