Re: To DMZ or not DMZ

From: Steve Thompson (stevethompson_at_nomail.please)
Date: 12/22/04


Date: Wed, 22 Dec 2004 09:45:03 -0500


"Peter Kaufman" <pmkdatabase_at_yahoo_dot_ca> wrote in message
news:me4is01h9f3qbm3d10g7k2r73fir3551vo@4ax.com...
> I have an sql database that is accessed both from Intranet and a few
> users on the Internet. I am having a hard time deciding whether to put
> the database server on a DMZ and set up a second one for internal
> usage or just continue on with the server behind a good firewall but
> on the LAN, and a member of the internal domain.
>
> It is going to be a hassle (and expensive) to use two SQL servers for
> this - not only will I have to keep them synced, now the outside users
> authenticate with AD user names/passwords.
>
> What would you guys do?

There may be a third option, which is keep the server internal and use a
secure VPN tunnel to connect.

However, look at any proposed solution from a hackers point of view, in
which location is the server OS and SQL Server more easily compromised?
Would you keep company sensitive data on a server in the DMZ? What is the
cost if this data were exploited?

Steve



Relevant Pages

  • Re: Search Issues persist event id 2424 remains
    ... but my two WFEs and SQL are on the same network ... the DNZ and the SQL Server in your Intranet. ... where is the equivalent Internet setting? ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: SBS 2003 SP2 Memory
    ... currently and most of these users only utilize Exchange. ... respond for a period of time I dont know how to see which if any of the SQL ... second server. ... Symantec Backup Exec (sql database) ...
    (microsoft.public.windows.server.sbs)
  • Re: Import aus einer Web Tabelle
    ... Ich bin im Internet ... was ich bei der Beispieltabelle angeben soll. ... > Web benötigen damit sie konform mit der SQL Server Tabelle gehen. ...
    (microsoft.public.de.sqlserver)
  • Re: some thoughts on the Slammer fiasco
    ... UCX POP server and assumes the ... >>internet was brought down by a poorly written application. ... >>does that ATM network have any connections to the internet. ... >>>WTF are you running a software firewall on an SQL box for. ...
    (microsoft.public.sqlserver.security)
  • Re: Unable to Browse Internet
    ... The SQL injection attack is the result of a defect in the way an application ... Prevent/Limit access to the internet from the DMZ in order to ... >> (e.g. why would you need to surf from web and SQL server? ...
    (microsoft.public.windows.server.general)