• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1513
  • Last Modified:

How to Restrict access by IP address range to SQL Box


I have inherited a SQL machine that has both internal (192.168.x.x) and public internet ip addresses, with web sites, assigned to it. The machine is constantly hammered by brute force connections to MS-SQL-S with logon attempts.

Is there a way to have SQL only bind to the internal IP address ?

- Or -

Can I limited the connections to the public IP address to only HTTP or FTP ?

Or something of this sort that will remove the exposure of the SQL server to the world at large ?

Thanks,

TMacT


0
TMacT
Asked:
TMacT
2 Solutions
 
TMacTAuthor Commented:

Note: this machine a stand-alone on a DSL link. My client does not have, and is not interested at this point, in a firewall.

0
 
chadCommented:
Microsoft SQL Server
a firewall can be configured to allow only the ports you want Such as 80 for http.  Or you can block the sql specific ports.


http://www.microsoft.com/smallbusiness/gtm/securityguidance/articles/ref_net_ports_ms_prod.mspx
Microsoft SQL Server 2000 provides a powerful and comprehensive data management platform. The ports used by each instance of SQL Server can be configured through the Server Network Utility.

System Service Name SQLSERVR

Application protocol Protocol Port
SQL over TCP
 TCP
 1433
 
SQL Probe
 UDP
 1434
 
0
 
TMacTAuthor Commented:
::: More info :::
SQL 7.0, Windows 2K SP4, Single NIC (Can install another if need to filter by NIC). Single Private address. Multiple Public addresses.

0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
TMacTAuthor Commented:
kabaam,

Thanks for your quick answer. Unfortunately, I can not configure a firewall at this time, and the Server Network Utility would let me change the ports, but not restrict access to the IP Address. I do not want to change the SQL port as the system is in production.

Still open ...
0
 
gwalkeriqCommented:
Actually, even though there are other solutions, the recommended solution is to reconfigure the windows NT Sever hosting your database  so that it is not visible to the Internet at all. I.e, put the DB server on a subnet that is private. This not only avoids the hammering from the internet, it also closes a significant security hole. Leaving any machine exposed to the Internet without cause is just asking for trouble.
0
 
TMacTAuthor Commented:
Hi gwalkeriq,

>> put the DB server on a subnet that is private

My clients SQL server/web server is already running, and they just want to prevent external connections to the SQL. I need to put some quick solutions on the SQL box, then I can discuss moving the SQL to another system and getting a firewall.

... TMacT
0
 
ShogunWadeCommented:
IMHO,  If your client is not interested in getting a firewall then he deserved to be hit.   The wole world knows about 1433 and xp_cmdshell !!!!!!

0
 
TMacTAuthor Commented:
Hi TheLearned One,

While I appreciate the effort from the experts above, none of them actually answered the question I was asking.

After being in this business for 15 years, I tire of answers from hotshots like ShogunWade who do not demonstrate any experience working to resolve an issue within the stated limitations.

I was specifically asking for help implementing IP security on a SQL /  Win2K server. I did not get that answer. For everyone's reference, I found the solution here (http://www.analogx.com/contents/articles/ipsec.htm) , and have implemented it. I now have the breathing room to rework the network.

Althought I answered my own question, I am unlikely to ask 110 questions and use up my all my available points, so please split the points between kabaam, and qwalkeriq, who at least provided constructive alternatives and suggestions.

... TMacT

0
 
ShogunWadeCommented:
Tmac,   Im sorry that you "tire of answers from hotshots like ShogunWade"   However perhaphs I shouldnt have had to make this observation to someone "being in this business for 15 years"
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

Tackle projects and never again get stuck behind a technical roadblock.
Join Now