Solved

Access SQL Server 2005 over internet connection (Best security)

Posted on 2007-11-28
10
1,166 Views
Last Modified: 2010-08-05
SQL Server 2005/ADO.NET 1.1/VisualStudio 2003 C#

Hi,
 I have an application need to communicate with SQL Server 2005 outside a network. My Customer need to have a Hight Level of security and he could not open SQL Server port. All my others customer, use VPN Connection to manage this problem. But in this situation, my customer doesn't have a VPN and we need to access with Hight Security Level my SQL database. I know that it's possible to build my own server, or access sql with a web service but i don't have time to do this. I need your help to find the best way to resolve this problem and propose solution to our customer : (I forget!  We use a mixed mode security in SQL Server)

Proxy ?
SSL ?
VPN ?
Web Service ?
Custom Server ?
Others

How to implement your best way with ADO.net ? How to pass in connectstring ?
 
It's really important to know that we need to keep performance on SQL Access.

Thanks.

0
Comment
Question by:TelDig
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 4
10 Comments
 
LVL 18

Expert Comment

by:Yveau
ID: 20368740
SSL is easy (once the certificate is installed) and very widely supported. Any connection can use it out of the box (except for JDBC) and it's a matter of one certificate on the server and it works ...
It's very secure. Did my own sniffing with wireshark, nothing that gets over the line is recognizable in any way.

Try this:
http://support.microsoft.com/kb/316898

Hope this helps ...
0
 

Author Comment

by:TelDig
ID: 20368807
thanks for your anwser, but i'm a beginner in security - SSL in SQL Server, I would like to know if you know some problems with SSL during implementation ?

thanks
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368823
No, just the certificate is a bit difficult ... Once that is in place, works like a charm !

Hope this helps ...
0
Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

 

Author Comment

by:TelDig
ID: 20368827
When we use SSL, did you need to open a SQL port on internet ?
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368848
Didn't run in on the Internet, so didn't had that issue ... good question. My first guess it would be running on port 1433 ...

0
 

Author Comment

by:TelDig
ID: 20368863
ok but is my biggest issue. I need to certified to my customer then SQL Server can't be hack outside his network. How it's possible to do it ?
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20368889
If you open the port for yourself ... anybody could use that port ... so that is a pretty tough one.
The VPN server would be the best option I guess ...

Try:
http://openvpn.net/
I use it myself, very simple to setup.

Hope this helps ...
0
 

Author Comment

by:TelDig
ID: 20373047
ok, Exept VPN and SSL, Witch mode do you suggest ?
Thanks
0
 
LVL 18

Accepted Solution

by:
Yveau earned 500 total points
ID: 20380092
VPN is probably the most secure ... I would go for VPN. And even then you could do SSL which is always good if going over the Internet.

Hope this helps ...
0
 
LVL 18

Expert Comment

by:Yveau
ID: 20381255
Glad I could be of any help and thanks for the grade !
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to reset the password of the sa account on a Microsoft SQL Server.  The steps in this article work in SQL 2005, 2008, 2008 R2, 2012, 2014 and 2016.
This article investigates the question of whether a computer can really be cleaned once it has been infected, and what the best ways of cleaning a computer might be (in this author's opinion).
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question