Backend SQL Networking Questions

From: Tim Meyer (tim@quickservicesoftware.com)
Date: 12/01/02


From: "Tim Meyer" <tim@quickservicesoftware.com>
Date: Sun, 1 Dec 2002 15:07:45 -0400


First off, thanks for any input you might have. This is going to deal
mostly with network security and how to best access my SQL DB.

I currently have 3 machines on our internal network that run WLBS (wink2k
AS) to host a website that connects to our backed SQL DB. Each system has
2 nics and is running WLBS in unicast mode. I'm using 1 to 1 nat on our
firewall to allow
access to the internal load balanced IP. What I want to do is to move these
3 systems to our DMZ and assign an external IP to the cluster and eliminate
NAT.

What I need to know is could I move the load balanced nic on each of these 3
machines to the DMZ (with the appropriate tcp/ip param of course) and still
have my other NIC connected to the LAN switch without leaving our internal
LAN open to hacking?

Requests made to the load balanced IP will need to pull data from our
backend SQL DB. How should this be handled? Should I just allow access
from that external IP on the SQL port # into the LAN? Or is there someway
that I can have the the machine that handles the request to use it's other
NIC (domain) to connect to the SQL DB and then transfer back over the
external IP.

If I'm way off base here let me know. I can take critisism with the best of
them.

Thanks

Tim



Relevant Pages

  • Re: SBS2003 Std Config Question
    ... Not sure I fully understand yhe use of the SQL box. ... If it is storing Data ... for an application used by users on the LAN then it should be on the ... > 2 NICS in server ...
    (microsoft.public.windows.server.sbs)
  • Webhosting Network Question
    ... AS) to host a website for internet clients. ... Each system has 2 nics and is ... LAN open to hacking? ... backend SQL DB. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Cluster name with multiple IP addresses?
    ... Senior SQL Infrastructure Consultant ... I did not see any dialog/screen that allowed for the addition of new network - only to modify node membership. ... the NICs and networks defined in the cluser configuration, you run the SQL setup wizard to add the networks to SQL Server. ... The cluster name "SQLCLST" and the virtual machine name "SQLSVR" have been defined with IP addresses on the public/client network. ...
    (microsoft.public.sqlserver.clustering)
  • Re: two NICs, SQL2000 and SQL2005 on the same machine
    ... By default both SQL Servers will listen on both ports You can force SQL 2005 to only listen on specific NICs. ... named instances will not use conlicting ports. ... this can be a different port for each NIC. ...
    (microsoft.public.sqlserver.setup)
  • Re: Webhosting Network Question
    ... IPX/SPX) run between your WWW & SQL. ... the point of a DMZ is ... would you want the machines to have NICs on ... >>> AS) to host a website for internet clients. ...
    (microsoft.public.inetserver.iis.security)