SQL cluster firewall question



We have been running a standalone SQL2005 box which uses a dedicated
webserver for the last 12 months and both sit on our perimeter (DMZ) zone.
The SQL box is now due to be replaced by a failover SQL cluster. Failover
clusters requires domain access and therefore it will have to sit on the
TRUSTED zone but now we face a real security issue with how the webserver
(in the DMZ) can safely talk to the cluster (in the TRUST) without
compromising security. I can maybe live with opening 1433 for SQL as it will
still require authentication, but .NET on the DMZ webserver will still
require port 80 to be open to the cluster. Am I missing something here,
surely this can't be done safely? I fear the only "safe" method is to create
a new standalone domain in the DMZ to facilitate the SQL cluster as this
seems to be the only way for the failover cluster to sit in the DMZ. How
else can the DMZ webserver talk to the SQL Cluster if the cluster sits in
the Trusted zone? Is PAT a safe alternative? Any advice appreciated Thanks


.



Relevant Pages

  • SQL cluster firewall question
    ... webserver for the last 12 months and both sit on our perimeter (DMZ) zone. ... The SQL box is now due to be replaced by a failover SQL cluster. ...
    (microsoft.public.sqlserver.clustering)
  • Re: Deploy Exchange on DMZ or backend?
    ... > software upgrade downtime. ... >> are on the internal network you don't need to install anything in a DMZ. ... >> like to cluster exchange to have some type of redundancy. ...
    (microsoft.public.exchange.design)
  • Re: HTTPs WebServerVeröffentlichung, mehrere HTTPS-Sites auf einem WEBServer
    ... > Hier veruche ich eine SecureWebSerververöffentlichung auf einen WebServer ... > in der DMZ zu machen. ... Wie sind bei dir denn die Listener konfiguriert? ... Veröffentlichung eine externe IP Adresse auf dem ISA und der Listener darf ...
    (microsoft.public.de.german.isaserver)
  • Re: DMZ =?ISO-8859-15?Q?Verst=E4ndnis?=
    ... Bedeutet DMZ eigentlich immer, ... Firewall gesteuert: ... In der DMZ befindet sich der Rechner auf dem der Webserver läuft. ... LAN -> Internet ...
    (de.comp.security.firewall)
  • Re: DMZ Problematik
    ... versuchweise die externe IP-Adresse des ISA vom DMZ Hosts anpingen. ... auch nicht, vom Internet ging es. ... > Da wir noch einen internen Webserver haben, ... > vom interne Netz kann ich auf diesen Webserver zugreifen. ...
    (microsoft.public.de.german.isaserver)