Re: Is there a better way

From: Adam Machanic (amachanic_at_hotmail._removetoemail_.com)
Date: 12/13/04


Date: Mon, 13 Dec 2004 11:42:45 -0500


"Russell Stevens" <rastevens@aol.com> wrote in message
news:uQmuf7w3EHA.4072@TK2MSFTNGP10.phx.gbl...
>
> Since this is such a common problem (anyone with an open 1433 is
probably
> being attacked numerous times each week) I was hoping there was a standard
> solution (I am not familiar with a real time scriptable firewall but that
> sounds like what is necessary - after x bad attempts, add IP to black list
> or if not an sa login add to white list if password is OK).

    The fact is, SQL Server just wasn't designed to be used as an open
internet server. It's made to sit well behind a firewall, protected by the
firewall, intermediate app and web servers, etc. I doubt that MS will ever
provide a truly hardened solution. It doesn't really mesh, IMO, with the
goals of a back-end database server.

-- 
Adam Machanic
SQL Server MVP
http://www.sqljunkies.com/weblog/amachanic
--


Relevant Pages

  • Re: Using Windows server as an internet gateway
    ... SBSPremium when you already have invested in the Standard Version ??? ... The point still remains that a correctly configured software firewall on the ... everyone who uses SBS Premium. ... As a package SBS2003 server is intended to be ...
    (microsoft.public.windows.server.sbs)
  • Re: Problems Printing through Netgear PS110
    ... but my issue seems to be with ISA which isn't with the ... If the firewall part of ISA is off, ... > Is this with both SBS2003 Premium and standard, ... > server running standard, and I recently bought a PS110 to network two old ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS Standard Internet Connection Sharing
    ... Actually there's a group policy on the server that stops that. ... There is a RRAS based firewall in standard... ... >>SBS standard edition to networked users. ...
    (microsoft.public.windows.server.sbs)
  • Re: New SBS2003 in a peer-2-peer network (with Goldmine)
    ... > 1) Server Config ... > configured to provide optimal security? ... > the standard implementation guide or is there something ... > provide a better firewall situation. ...
    (microsoft.public.windows.server.sbs)
  • Re: Intranet site displays to only some client pcs
    ... > I have standard so know firewall. ... > DCHP on the router NAT on LAN side of router. ... The SBS server is a fixed ip ...
    (microsoft.public.backoffice.smallbiz2000)