Re: Sharing intranet & Internet DB server
Posted in 1997
Paul.Stewart@jocoks.com wrote: > > We're in the process of developing a pilot intranet application. We also have > the goal of soon providing dynamic web pages for access over the Internet. A > proposal has been made within our organization to share a single Informix > database server between the 2 types of access--intranet and Internet. We > currently have an Altavista firewall between the Internet and our network and > at this point have not allowed any access from the Internet to our internal > network. > Well, here's a free tip from your uncle mike: What you do behind your firewall, is your own business. (Just use UNIX vs NT!)[No JOKE!] At the firewall, you will want to limit the communication comming in to the network. What I have recommended to clients is actually creating a "thick " firewall. That is, create a "network" between two routers with the firewall on one side and your internet/intranet app server between them. -->Internet Cloud ---->| Router 1 | --->{Firewall Box} | | | (Web Server)<=== | | [Internal Network]| <----| Router 2 | <------| (Hopefully this map made it in one piece.) The idea is that you can now filter out traffic to and from the internet, and allow both sides to see your web server. Then you limit access to your web server box. You allow it to hit your databases (Informix/DB2/etc) on your side of the intranet. For those really paranoid, you create smaller databases/repositories which the webserver accesses so that your corporate data is still secure. These smaller databases could be kept in sync with the repository on a as needed basis. While this solution may cost more, think about this. 1) How much will is cost you to repair the damage of someone getting your data? 2) You are protecting your company, read e-mail, internal servers, day to day operations against possible attack. > Just wondering if anyone else has or will try this setup and if there are any > opinions or suggestions about it. Thanks. Just a tip from your uncle mikey. HTH. -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************