RE: Server publishing

  • From: "Thor" <thor@xxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 1 Jul 2004 17:48:16 -0700

A few bits queried to udp1434, and your SQL Server will spill its guts as to
where multiple instances are listening.  "Hiding" is no security option.

Besides, in the model described, it doesn't matter.  You could have the DMZ
web server talking to the internal box on 341433 for that matter, and any
compromise of the web box would reveal that-- regardless of if you block the
multiple instance query or not...  The config on the web server tells all...
You'd still have to have that TCP port statically open to the internal
network, where MSSQL would be listening.  That won't stop SQL injection,
won't stop anything, really-- other than a worm that was loosed in the DMZ
itself.

The bottom line is that the ISA server, given the listed config, doesn't buy
you anything (from a server pub standpoint) other than what Shawn brought up
regarding limiting requests.

Nathan-- even if you need updates from data posted to the DMZ server to the
Internal server, that doesn't mean you can't still use one-way traffic to
accomplish this.  Just run jobs from the inside that grab the data from the
outside.  I do it all day every day with no issues.  You can even do a "run
while idle" job if you want to that would basically constantly run the job.
Of course, "run when idle" jobs require the MSSQL service to run as local
admin (or SYSTEM) so that is kinda risky.

----- Original Message ----- 
From: "josephk" <josephk@xxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Thursday, July 01, 2004 4:05 PM
Subject: [isalist] RE: Server publishing


http://www.ISAserver.org

With SQL you can hide the box on your network.  Meaning that other SQL
machines won't be able to see it.
When you use this method it changes the port that SQL uses to 2433. Then
the common types of worms
Don't know if there is anything on 1433 or not.

Thank you,

Joseph

-----Original Message-----
From: Thor [mailto:thor@xxxxxxxxxxxxxxx]
Sent: Thursday, July 01, 2004 1:49 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Server publishing


http://www.ISAserver.org

Well, it will add an "additional layer of complexity," but only in
regard to your network topology.  To be pedantic, Server Publishing 1433
won't "proxy" anything... I will just pass the traffic along
transparently (unless the back-end is a different subnet, in which case
it will be NAT'd, but still, no difference.)

t


----- Original Message ----- 
From: "Nathan Casey" <NCASEY@xxxxxxxxxxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Thursday, July 01, 2004 1:17 PM
Subject: [isalist] RE: Server publishing


> http://www.ISAserver.org
>
> We want the ISA server to add an additional layer of complexity for
> external access to internal resources. The ISA server would be set as
> a reverse proxy to pass requests, authentication, etc to the SQL
> server
>
> >>> Shawn.Quillman@xxxxxxxxxxxx 7/1/2004 12:11:18 PM >>>
> http://www.ISAserver.org
>
>
> Yes.  The only time you can have 1 adapter is when ISA is
> in cache-only
> mode in which situation you can only web publish.  The
> config you show
> doesn't really make sense, the ISA would be redundant.  You would just
> publish the SQL server via the internal PIX.  What is it
> you're trying
> to accomplish with the ISA?
>
> -Shawn
>
>
> -----
> Shawn R. Quillman
> Robert Bosch Corporation RBNA/CSA1
> 38000 Hills Tech Drive
> Farmington Hills, MI 48331
> (248) 553-1164 (P) (248) 848-6969 (F) shawn.quillman@xxxxxxxxxxxx
>
> -----Original Message-----
> From: nathan [mailto:ncasey@xxxxxxxxxxxxxxxxx]
> Sent: Thursday, July 01, 2004 3:40 PM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] Server publishing
>
> http://www.ISAserver.org
>
> With server publishing, if I publish a SQL server that sits on the
> internal network, does my ISA server need 2 adapters? The
> SQL server is
> acting as a back-end database server for a Web site which
> is hosted on
> web server in a PIX DMZ.
> If I do need 2 adapters for server publishing can they both
> reside in
> PIX DMZ's? My network security guy wants all incoming
> traffic to go
> trough the PIX firewall
>
> Internet Router
>    (Public IP)
> |
> |
> PIX FIREWALL
> |
> |
>   Web server
> |
> |
> PIX FIREWALL
> *internal Network*
> |
> |
> ISA SERVER
> |
> |
> SQL SERVER
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter:
> http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ:
> http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking:
> http://www.windowsnetworking.com Leading
> Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site:
> http://www.msexchange.org Windows
> Security Resource Site: http://www.windowsecurity.com/
> Network Security
> Library: http://www.secinf.net/ Windows 2000/NT Fax
> Solutions:
> http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org
> Discussion List as:
> shawn.quillman@xxxxxxxxxxxx To unsubscribe visit
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
>
>
> ------------------------------------------------------
> List Archives:
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter:
> http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ:
> http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking:
> http://www.windowsnetworking.com
> Leading Network Software Directory:
> http://www.serverfiles.com
> No.1 Exchange Server Resource Site:
> http://www.msexchange.org
> Windows Security Resource Site:
> http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org
> Discussion List as: ncasey@xxxxxxxxxxxxxxxxx
> To unsubscribe visit
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking: http://www.windowsnetworking.com
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
thor@xxxxxxxxxxxxxxx
> To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=isalist
>


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
josephk@xxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
thor@xxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist



Other related posts: