A few bits queried to udp1434, and your SQL Server will spill its guts as to where multiple instances are listening. "Hiding" is no security option. Besides, in the model described, it doesn't matter. You could have the DMZ web server talking to the internal box on 341433 for that matter, and any compromise of the web box would reveal that-- regardless of if you block the multiple instance query or not... The config on the web server tells all... You'd still have to have that TCP port statically open to the internal network, where MSSQL would be listening. That won't stop SQL injection, won't stop anything, really-- other than a worm that was loosed in the DMZ itself. The bottom line is that the ISA server, given the listed config, doesn't buy you anything (from a server pub standpoint) other than what Shawn brought up regarding limiting requests. Nathan-- even if you need updates from data posted to the DMZ server to the Internal server, that doesn't mean you can't still use one-way traffic to accomplish this. Just run jobs from the inside that grab the data from the outside. I do it all day every day with no issues. You can even do a "run while idle" job if you want to that would basically constantly run the job. Of course, "run when idle" jobs require the MSSQL service to run as local admin (or SYSTEM) so that is kinda risky. ----- Original Message ----- From: "josephk" <josephk@xxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Thursday, July 01, 2004 4:05 PM Subject: [isalist] RE: Server publishing http://www.ISAserver.org With SQL you can hide the box on your network. Meaning that other SQL machines won't be able to see it. When you use this method it changes the port that SQL uses to 2433. Then the common types of worms Don't know if there is anything on 1433 or not. Thank you, Joseph -----Original Message----- From: Thor [mailto:thor@xxxxxxxxxxxxxxx] Sent: Thursday, July 01, 2004 1:49 PM To: [ISAserver.org Discussion List] Subject: [isalist] RE: Server publishing http://www.ISAserver.org Well, it will add an "additional layer of complexity," but only in regard to your network topology. To be pedantic, Server Publishing 1433 won't "proxy" anything... I will just pass the traffic along transparently (unless the back-end is a different subnet, in which case it will be NAT'd, but still, no difference.) t ----- Original Message ----- From: "Nathan Casey" <NCASEY@xxxxxxxxxxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Thursday, July 01, 2004 1:17 PM Subject: [isalist] RE: Server publishing > http://www.ISAserver.org > > We want the ISA server to add an additional layer of complexity for > external access to internal resources. The ISA server would be set as > a reverse proxy to pass requests, authentication, etc to the SQL > server > > >>> Shawn.Quillman@xxxxxxxxxxxx 7/1/2004 12:11:18 PM >>> > http://www.ISAserver.org > > > Yes. The only time you can have 1 adapter is when ISA is > in cache-only > mode in which situation you can only web publish. The > config you show > doesn't really make sense, the ISA would be redundant. You would just > publish the SQL server via the internal PIX. What is it > you're trying > to accomplish with the ISA? > > -Shawn > > > ----- > Shawn R. Quillman > Robert Bosch Corporation RBNA/CSA1 > 38000 Hills Tech Drive > Farmington Hills, MI 48331 > (248) 553-1164 (P) (248) 848-6969 (F) shawn.quillman@xxxxxxxxxxxx > > -----Original Message----- > From: nathan [mailto:ncasey@xxxxxxxxxxxxxxxxx] > Sent: Thursday, July 01, 2004 3:40 PM > To: [ISAserver.org Discussion List] > Subject: [isalist] Server publishing > > http://www.ISAserver.org > > With server publishing, if I publish a SQL server that sits on the > internal network, does my ISA server need 2 adapters? The > SQL server is > acting as a back-end database server for a Web site which > is hosted on > web server in a PIX DMZ. > If I do need 2 adapters for server publishing can they both > reside in > PIX DMZ's? My network security guy wants all incoming > traffic to go > trough the PIX firewall > > Internet Router > (Public IP) > | > | > PIX FIREWALL > | > | > Web server > | > | > PIX FIREWALL > *internal Network* > | > | > ISA SERVER > | > | > SQL SERVER > > ------------------------------------------------------ > List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist > ISA Server Newsletter: > http://www.isaserver.org/pages/newsletter.asp > ISA Server FAQ: > http://www.isaserver.org/pages/larticle.asp?type=FAQ > ------------------------------------------------------ > Other Internet Software Marketing Sites: > World of Windows Networking: > http://www.windowsnetworking.com Leading > Network Software Directory: http://www.serverfiles.com > No.1 Exchange Server Resource Site: > http://www.msexchange.org Windows > Security Resource Site: http://www.windowsecurity.com/ > Network Security > Library: http://www.secinf.net/ Windows 2000/NT Fax > Solutions: > http://www.ntfaxfaq.com > ------------------------------------------------------ > You are currently subscribed to this ISAserver.org > Discussion List as: > shawn.quillman@xxxxxxxxxxxx To unsubscribe visit > http://www.webelists.com/cgi/lyris.pl?enter=isalist > > > ------------------------------------------------------ > List Archives: > http://www.webelists.com/cgi/lyris.pl?enter=isalist > ISA Server Newsletter: > http://www.isaserver.org/pages/newsletter.asp > ISA Server FAQ: > http://www.isaserver.org/pages/larticle.asp?type=FAQ > ------------------------------------------------------ > Other Internet Software Marketing Sites: > World of Windows Networking: > http://www.windowsnetworking.com > Leading Network Software Directory: > http://www.serverfiles.com > No.1 Exchange Server Resource Site: > http://www.msexchange.org > Windows Security Resource Site: > http://www.windowsecurity.com/ > Network Security Library: http://www.secinf.net/ > Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com > ------------------------------------------------------ > You are currently subscribed to this ISAserver.org > Discussion List as: ncasey@xxxxxxxxxxxxxxxxx > To unsubscribe visit > http://www.webelists.com/cgi/lyris.pl?enter=isalist > > ------------------------------------------------------ > List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist > ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp > ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ > ------------------------------------------------------ > Other Internet Software Marketing Sites: > World of Windows Networking: http://www.windowsnetworking.com > Leading Network Software Directory: http://www.serverfiles.com > No.1 Exchange Server Resource Site: http://www.msexchange.org > Windows Security Resource Site: http://www.windowsecurity.com/ > Network Security Library: http://www.secinf.net/ > Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com > ------------------------------------------------------ > You are currently subscribed to this ISAserver.org Discussion List as: thor@xxxxxxxxxxxxxxx > To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist > ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: josephk@xxxxxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: thor@xxxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist