Solved

Clustering IIS6 in DMZ with no domain

Posted on 2009-05-08
5
698 Views
Last Modified: 2012-05-06
I am to understand the following are requirements for Clustering with Windows 2003
1.)  Need Enterprise Version
2.)  Both servers require access to a domain (member of domain).
3.)  NLB seems to be the preferred method by many over Failover Clustering.
4.)  Require shared storage.
5.)  Granting access to domains inside the private network is a security risk.  shouldn't do it.

So with the above being said... points 2.) and 5.) is my delimma.

** How can I create a cluster in the DMZ with no domain?  Is there a safe way for the cluster to be members of the domain via tight Firewall rules?  What are other people doing to address this.   What bothers me most is the fact that it seems everyone is clustering web servers, but how are they doing it without causing security issues?

I'm reading a lot of conflicting information on this topic and would like someone who has 1st hand experience on this and can explain what the best way... most common accepted way of creating a clustered IIS server.
0
Comment
Question by:rdelrosario
  • 3
  • 2
5 Comments
 
LVL 51

Expert Comment

by:tedbilly
ID: 24341936
This article describes the issues with clustering IIS 6: http://news.zdnet.co.uk/hardware/0,1000000091,2124314,00.htm

Very few people do it.  Clustering is more common with SQL.

I'd recommend you simply using NLB for your web applications and then issues #1, #2, #4 and #5 disappear.  The one problem is NLB only supports automatic failover at the OS level.  It means you need to use a custom tool to monitor each server in the farm and if the wbe application fails restart IIS automatically.  However, to be honest if you're web application is poorly written it will likely fail on both servers.
0
 

Author Comment

by:rdelrosario
ID: 24343681
When you say OS level.. Do you mean application and service hangs? Just about every web shop runs some sort of high availability solution...are you saying all of them... Most of them just run nlb?  
0
 
LVL 51

Expert Comment

by:tedbilly
ID: 24346765
If the application or service hangs there is no failover and yes most shops only run NLB.  In my many years of experience there are two reasons for application errors.  The underlying hardware or O/S has a fault or the application design is flawed.  If the application design is flawed it will affect ALL servers.

What most companies (ours included) does is monitor each server for a variety of conditions:
- Out of disk space
- Out of memory
- Exceptions in the event/system logs

We then react accordingly which sometimes means as script takes the server offline and our 24/7 data center looks into it based on the SLA (Service Level Agreement.
0
 

Author Comment

by:rdelrosario
ID: 24353555
Tedbilly,
On a side note... have you any opinions of 2008 Server NLB or Clustering over 2003?  I can deploy either and wanted to know if you had any good/bad experience or opinions on 2008 server..
0
 
LVL 51

Accepted Solution

by:
tedbilly earned 500 total points
ID: 24361112
I don't have personal experience with 2008, however I have second hand confirmation from peers where I work that are very happy with it.  I tend to be conservative with technology and if an older OS works I tend to stick with it, better the devil you know! ;)

However, 2008 has been out awhile and I haven't read any bad press so I'd say go for it.

Cheers
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Here are the symptoms: You start receiving calls from users that one of your legacy web apps isn't coming up, so you log into your IIS 5 server to check it out.  When you pull up the services, you notice that the WWW Publishing service isn't runn…
Logparser is the smartest tool I have ever used in parsing IIS log files and there are many interesting things I wanted to share with everyone one of the  real-world  scenario from my current project. Let's get started with  scenario - How do w…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now