Solved

Access SQL Server 2005 over internet connection (Best security)

Posted on 2007-11-28
10
1,164 Views
Last Modified: 2010-08-05
SQL Server 2005/ADO.NET 1.1/VisualStudio 2003 C#

Hi,
 I have an application need to communicate with SQL Server 2005 outside a network. My Customer need to have a Hight Level of security and he could not open SQL Server port. All my others customer, use VPN Connection to manage this problem. But in this situation, my customer doesn't have a VPN and we need to access with Hight Security Level my SQL database. I know that it's possible to build my own server, or access sql with a web service but i don't have time to do this. I need your help to find the best way to resolve this problem and propose solution to our customer : (I forget!  We use a mixed mode security in SQL Server)

Proxy ?
SSL ?
VPN ?
Web Service ?
Custom Server ?
Others

How to implement your best way with ADO.net ? How to pass in connectstring ?
 
It's really important to know that we need to keep performance on SQL Access.

Thanks.

0
Comment
Question by:TelDig
  • 6
  • 4
10 Comments
 
LVL 18

Expert Comment

by:Yveau
ID: 20368740
SSL is easy (once the certificate is installed) and very widely supported. Any connection can use it out of the box (except for JDBC) and it's a matter of one certificate on the server and it works ...
It's very secure. Did my own sniffing with wireshark, nothing that gets over the line is recognizable in any way.

Try this:
http://support.microsoft.com/kb/316898

Hope this helps ...
0
 

Author Comment

by:TelDig
ID: 20368807
thanks for your anwser, but i'm a beginner in security - SSL in SQL Server, I would like to know if you know some problems with SSL during implementation ?

thanks
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368823
No, just the certificate is a bit difficult ... Once that is in place, works like a charm !

Hope this helps ...
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 

Author Comment

by:TelDig
ID: 20368827
When we use SSL, did you need to open a SQL port on internet ?
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368848
Didn't run in on the Internet, so didn't had that issue ... good question. My first guess it would be running on port 1433 ...

0
 

Author Comment

by:TelDig
ID: 20368863
ok but is my biggest issue. I need to certified to my customer then SQL Server can't be hack outside his network. How it's possible to do it ?
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368889
If you open the port for yourself ... anybody could use that port ... so that is a pretty tough one.
The VPN server would be the best option I guess ...

Try:
http://openvpn.net/
I use it myself, very simple to setup.

Hope this helps ...
0
 

Author Comment

by:TelDig
ID: 20373047
ok, Exept VPN and SSL, Witch mode do you suggest ?
Thanks
0
 
LVL 18

Accepted Solution

by:
Yveau earned 500 total points
ID: 20380092
VPN is probably the most secure ... I would go for VPN. And even then you could do SSL which is always good if going over the Internet.

Hope this helps ...
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20381255
Glad I could be of any help and thanks for the grade !
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Read about achieving the basic levels of HRIS security in the workplace.
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question