RE: Server publishing

  • From: "josephk" <josephk@xxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Thu, 1 Jul 2004 18:01:11 -0700

Read what I said dude.  I said that other SQL machines won't be able to
connect to it. I did not mention that it
Would fix security issues. The configuration that I sent Nathan has been
tested and used here and at many sites.
MSN.COM uses something similar. If someone gets that far into your
network then you have serious problems.

If real time is not an issue then maybe setting up MSMQ to do transfers
would work.  There is some programming 
Involved but would still work.  Or you could create secure web services
to do data reading and updating.

It really depends on how paranoid you are.

Joseph
 
-----Original Message-----
From: Thor [mailto:thor@xxxxxxxxxxxxxxx] 
Sent: Thursday, July 01, 2004 5:48 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Server publishing


http://www.ISAserver.org

A few bits queried to udp1434, and your SQL Server will spill its guts
as to where multiple instances are listening.  "Hiding" is no security
option.

Besides, in the model described, it doesn't matter.  You could have the
DMZ web server talking to the internal box on 341433 for that matter,
and any compromise of the web box would reveal that-- regardless of if
you block the multiple instance query or not...  The config on the web
server tells all... You'd still have to have that TCP port statically
open to the internal network, where MSSQL would be listening.  That
won't stop SQL injection, won't stop anything, really-- other than a
worm that was loosed in the DMZ itself.

The bottom line is that the ISA server, given the listed config, doesn't
buy you anything (from a server pub standpoint) other than what Shawn
brought up regarding limiting requests.

Nathan-- even if you need updates from data posted to the DMZ server to
the Internal server, that doesn't mean you can't still use one-way
traffic to accomplish this.  Just run jobs from the inside that grab the
data from the outside.  I do it all day every day with no issues.  You
can even do a "run while idle" job if you want to that would basically
constantly run the job. Of course, "run when idle" jobs require the
MSSQL service to run as local admin (or SYSTEM) so that is kinda risky.

----- Original Message ----- 
From: "josephk" <josephk@xxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Thursday, July 01, 2004 4:05 PM
Subject: [isalist] RE: Server publishing


http://www.ISAserver.org

With SQL you can hide the box on your network.  Meaning that other SQL
machines won't be able to see it. When you use this method it changes
the port that SQL uses to 2433. Then the common types of worms Don't
know if there is anything on 1433 or not.

Thank you,

Joseph

-----Original Message-----
From: Thor [mailto:thor@xxxxxxxxxxxxxxx]
Sent: Thursday, July 01, 2004 1:49 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Server publishing


http://www.ISAserver.org

Well, it will add an "additional layer of complexity," but only in
regard to your network topology.  To be pedantic, Server Publishing 1433
won't "proxy" anything... I will just pass the traffic along
transparently (unless the back-end is a different subnet, in which case
it will be NAT'd, but still, no difference.)

t


----- Original Message ----- 
From: "Nathan Casey" <NCASEY@xxxxxxxxxxxxxxxxx>
To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
Sent: Thursday, July 01, 2004 1:17 PM
Subject: [isalist] RE: Server publishing


> http://www.ISAserver.org
>
> We want the ISA server to add an additional layer of complexity for 
> external access to internal resources. The ISA server would be set as 
> a reverse proxy to pass requests, authentication, etc to the SQL 
> server
>
> >>> Shawn.Quillman@xxxxxxxxxxxx 7/1/2004 12:11:18 PM >>>
> http://www.ISAserver.org
>
>
> Yes.  The only time you can have 1 adapter is when ISA is
> in cache-only
> mode in which situation you can only web publish.  The
> config you show
> doesn't really make sense, the ISA would be redundant.  You would just

> publish the SQL server via the internal PIX.  What is it you're trying
> to accomplish with the ISA?
>
> -Shawn
>
>
> -----
> Shawn R. Quillman
> Robert Bosch Corporation RBNA/CSA1
> 38000 Hills Tech Drive
> Farmington Hills, MI 48331
> (248) 553-1164 (P) (248) 848-6969 (F) shawn.quillman@xxxxxxxxxxxx
>
> -----Original Message-----
> From: nathan [mailto:ncasey@xxxxxxxxxxxxxxxxx]
> Sent: Thursday, July 01, 2004 3:40 PM
> To: [ISAserver.org Discussion List]
> Subject: [isalist] Server publishing
>
> http://www.ISAserver.org
>
> With server publishing, if I publish a SQL server that sits on the 
> internal network, does my ISA server need 2 adapters? The SQL server 
> is acting as a back-end database server for a Web site which
> is hosted on
> web server in a PIX DMZ.
> If I do need 2 adapters for server publishing can they both
> reside in
> PIX DMZ's? My network security guy wants all incoming
> traffic to go
> trough the PIX firewall
>
> Internet Router
>    (Public IP)
> |
> |
> PIX FIREWALL
> |
> |
>   Web server
> |
> |
> PIX FIREWALL
> *internal Network*
> |
> |
> ISA SERVER
> |
> |
> SQL SERVER
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ:
> http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking:
> http://www.windowsnetworking.com Leading
> Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site:
> http://www.msexchange.org Windows
> Security Resource Site: http://www.windowsecurity.com/
> Network Security
> Library: http://www.secinf.net/ Windows 2000/NT Fax
> Solutions:
> http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org
> Discussion List as:
> shawn.quillman@xxxxxxxxxxxx To unsubscribe visit
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
>
>
> ------------------------------------------------------
> List Archives:
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter:
> http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ:
> http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking:
> http://www.windowsnetworking.com
> Leading Network Software Directory:
> http://www.serverfiles.com
> No.1 Exchange Server Resource Site:
> http://www.msexchange.org
> Windows Security Resource Site:
> http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org
> Discussion List as: ncasey@xxxxxxxxxxxxxxxxx
> To unsubscribe visit
> http://www.webelists.com/cgi/lyris.pl?enter=isalist
>
> ------------------------------------------------------
> List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
> ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
> ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
> ------------------------------------------------------
> Other Internet Software Marketing Sites:
> World of Windows Networking: http://www.windowsnetworking.com
> Leading Network Software Directory: http://www.serverfiles.com
> No.1 Exchange Server Resource Site: http://www.msexchange.org
> Windows Security Resource Site: http://www.windowsecurity.com/
> Network Security Library: http://www.secinf.net/
> Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
> ------------------------------------------------------
> You are currently subscribed to this ISAserver.org Discussion List as:
thor@xxxxxxxxxxxxxxx
> To unsubscribe visit
http://www.webelists.com/cgi/lyris.pl?enter=isalist
>


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
josephk@xxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
thor@xxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist


------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
josephk@xxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist


Other related posts: