Solved

DMZ vs Reverse Proxy

Posted on 2004-03-25
6
1,042 Views
Last Modified: 2013-12-25
In the past, our company has had our web site hosted off site.  We are in the process of setting up a web server in house and doing our own hosting.  We are having an internal disagreement about the value of having a DMZ vs. using a reverse proxy.

One school of thought is to set up the web server and the database server inside a DMZ.  The other is to put the web server inside the LAN and protect it by using reverse proxy and to use the existing production DB server as the web DB server.

We will be running IIS, SQL Server, and use BorderManager as our firewall.

Any input will be greatly appreciated.

Thanks in advance,
HawkeyeNash
0
Comment
Question by:HawkeyeNash
  • 4
6 Comments
 
LVL 17

Expert Comment

by:Tacobell777
ID: 10683757
Go DMZ, use it for what it is made for.

Reverse proxy will most likely slow things down as well.

0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691011
I agree fullheartedly with Tacobell - why expose your production databases that AREN'T going to be used on the web to the potential of being hacked?  I'd keep internal production databases entirely separate from the web databases.
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691061
To elaborate, the primary rules in security that apply here are:

* The Most secure data is the data that nobody knows you have

* Allowing limited access to a resource gives the possibility of someone finding (or creating) a vulnerability that gives them greater access

* Only expose those items that you want to be found out about.

Using these rules, you keep all things that you want the outside world to find out about OUTSIDE of your internal network (I.e. in the DMV), and you keep the information that you want to keep secure entirely separate, in an area that the outside world has zero access to.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 

Author Comment

by:HawkeyeNash
ID: 10691162
Thanks for the input.

I do understand the philosphy of the DMZ.

I guess the real issue is that one camp beleives that the Reverse Proxy offers all of the protection that a DMZ offers and states that there is no need to set up a DMZ because we are just a protected by the reverse proxy.

I need laid out in concrete terms what a DMZ offers that the reverse proxy does not.  Why am I safer with a DMZ then with reverse proxy alone?



0
 
LVL 15

Accepted Solution

by:
periwinkle earned 100 total points
ID: 10691541
Here's one reason:

http://archives.neohapsis.com/archives/firewalls/2001-q1/1335.html

Apparently, Microsoft doesn't support SSL connections between the server and the reverse proxy - so that means that the information travels as plain text.

Another good article on DMZ:

http://www.giac.org/practical/gsec/Scott_Young_GSEC.pdf

... the part on Page 5 that is entitled "Why do I want a DMZ" is particularly good - some quotes:

"If you don't have a DMZ and your initial frontline perimeter is broken then the game is up. (...) A DMZ hides your important information an extra step away from an attacker."

Here's another interesting article on setting up your security policy:

Designing and Planning Windows NT External Security
By Tom Dodds, Eric Miyadi, and Tom Fuchs, Microsoft Consulting Services, Southern California
http://www.microsoft.com/technet/prodtechnol/winntas/maintain/ntextsec.mspx

While this is angled towards Windows NT, it looks like it would be good advise for any flavor of Windows, really.

Intriguingly, it argues that a reverse proxy could make sense for the scenario that you describe, particularly if data being out of synch is of concern.  It's a balancing act.

No one will argue that it's more secure to keep things accessed from the outside from your internal network.  However, if it is extremely important that your data needs to be up to the minute accurate (i.e. very 'fresh'), then a reverse proxy will make sense...

I guess part of what needs to be answered is:

(1) How much interaction between the internal databases and external databases is needed?  I.e. does the data that is used by the web site come from a database that is kept to date on the inside or that needs to be 'up to the minute' fresh?

(2) How static is the data? If the data doesn't change often, then it makes a lot of sense to put it in the DMZ to keep it separate from your internal systems and to reduce one more potential security risk.

(3) If you are writing to the database, is the information something that could be imported into your internal network on a periodic basis, or does it need to be constantly updated?  If you can import the data on a daily basis into your internal network, then you have shorter periods of vulnerability... i.e. the connection to the internal and the external can be made available for a shorter amount of time.
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691630
I'm glad to have helped.  There's a wealth of information at Microsoft.com - go to:

http://search.microsoft.com 

and use the terms:

DMZ reverse proxy

... you'll get a lot of great resources at your fingertips.

You may also find the topics at the Microsoft Security Guidance Center: Server Security Index useful:

http://www.microsoft.com/security/guidance/topics/ServerSecurity.mspx
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now