Solved

DMZ vs Reverse Proxy

Posted on 2004-03-25
6
1,072 Views
Last Modified: 2013-12-25
In the past, our company has had our web site hosted off site.  We are in the process of setting up a web server in house and doing our own hosting.  We are having an internal disagreement about the value of having a DMZ vs. using a reverse proxy.

One school of thought is to set up the web server and the database server inside a DMZ.  The other is to put the web server inside the LAN and protect it by using reverse proxy and to use the existing production DB server as the web DB server.

We will be running IIS, SQL Server, and use BorderManager as our firewall.

Any input will be greatly appreciated.

Thanks in advance,
HawkeyeNash
0
Comment
Question by:HawkeyeNash
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 17

Expert Comment

by:Tacobell777
ID: 10683757
Go DMZ, use it for what it is made for.

Reverse proxy will most likely slow things down as well.

0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691011
I agree fullheartedly with Tacobell - why expose your production databases that AREN'T going to be used on the web to the potential of being hacked?  I'd keep internal production databases entirely separate from the web databases.
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691061
To elaborate, the primary rules in security that apply here are:

* The Most secure data is the data that nobody knows you have

* Allowing limited access to a resource gives the possibility of someone finding (or creating) a vulnerability that gives them greater access

* Only expose those items that you want to be found out about.

Using these rules, you keep all things that you want the outside world to find out about OUTSIDE of your internal network (I.e. in the DMV), and you keep the information that you want to keep secure entirely separate, in an area that the outside world has zero access to.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:HawkeyeNash
ID: 10691162
Thanks for the input.

I do understand the philosphy of the DMZ.

I guess the real issue is that one camp beleives that the Reverse Proxy offers all of the protection that a DMZ offers and states that there is no need to set up a DMZ because we are just a protected by the reverse proxy.

I need laid out in concrete terms what a DMZ offers that the reverse proxy does not.  Why am I safer with a DMZ then with reverse proxy alone?



0
 
LVL 15

Accepted Solution

by:
periwinkle earned 100 total points
ID: 10691541
Here's one reason:

http://archives.neohapsis.com/archives/firewalls/2001-q1/1335.html

Apparently, Microsoft doesn't support SSL connections between the server and the reverse proxy - so that means that the information travels as plain text.

Another good article on DMZ:

http://www.giac.org/practical/gsec/Scott_Young_GSEC.pdf

... the part on Page 5 that is entitled "Why do I want a DMZ" is particularly good - some quotes:

"If you don't have a DMZ and your initial frontline perimeter is broken then the game is up. (...) A DMZ hides your important information an extra step away from an attacker."

Here's another interesting article on setting up your security policy:

Designing and Planning Windows NT External Security
By Tom Dodds, Eric Miyadi, and Tom Fuchs, Microsoft Consulting Services, Southern California
http://www.microsoft.com/technet/prodtechnol/winntas/maintain/ntextsec.mspx

While this is angled towards Windows NT, it looks like it would be good advise for any flavor of Windows, really.

Intriguingly, it argues that a reverse proxy could make sense for the scenario that you describe, particularly if data being out of synch is of concern.  It's a balancing act.

No one will argue that it's more secure to keep things accessed from the outside from your internal network.  However, if it is extremely important that your data needs to be up to the minute accurate (i.e. very 'fresh'), then a reverse proxy will make sense...

I guess part of what needs to be answered is:

(1) How much interaction between the internal databases and external databases is needed?  I.e. does the data that is used by the web site come from a database that is kept to date on the inside or that needs to be 'up to the minute' fresh?

(2) How static is the data? If the data doesn't change often, then it makes a lot of sense to put it in the DMZ to keep it separate from your internal systems and to reduce one more potential security risk.

(3) If you are writing to the database, is the information something that could be imported into your internal network on a periodic basis, or does it need to be constantly updated?  If you can import the data on a daily basis into your internal network, then you have shorter periods of vulnerability... i.e. the connection to the internal and the external can be made available for a shorter amount of time.
0
 
LVL 15

Expert Comment

by:periwinkle
ID: 10691630
I'm glad to have helped.  There's a wealth of information at Microsoft.com - go to:

http://search.microsoft.com 

and use the terms:

DMZ reverse proxy

... you'll get a lot of great resources at your fingertips.

You may also find the topics at the Microsoft Security Guidance Center: Server Security Index useful:

http://www.microsoft.com/security/guidance/topics/ServerSecurity.mspx
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Let’s list some of the technologies that enable smooth teleworking. 
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question