Solved

Separating IIS and SQL for security

Posted on 2014-01-07
7
316 Views
Last Modified: 2014-03-04
Hello,

     I have a decent sized box that is running Windows Server 2008 R2, IIS (open to the Internet), and SQL 2008 R2. Currently SQL sole purpose is to feed data to the IIS interface. The box is behind a firewall with only port 80 (HTTP) open to the Internet. Other than performance gains, if secured properly, should I bother to separate SQL and IIS into two machines? What are the PROs and CONs of this?
Thanks in advance..
0
Comment
Question by:FNDAdmin
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 10

Accepted Solution

by:
PadawanDBA earned 125 total points
ID: 39762278
Just my 2 cents:

Cons: Increased data access latency (network latency), addition of another point of failure (network layer), more complex management, and additional hardware (or additional resource utilization of your hypervisor if you're virtualized)

Pros: Increased security (i'm always extremely loathe to have any SQL Server instance directly bordering the public world), better utilization of hardware (memory is dedicated to SQL Server only and it doesn't have to share), and better scaleability options with separate, dedicated tiers.
0
 
LVL 9

Expert Comment

by:Trenton Knew
ID: 39762415
Yeah, if you want to add an additional layer of seperation, you could put the SQL server in a VM.  the difficulty there is you need a windows license to install in the Virtual Machine.  The Microsoft Hyper-V server will allow you to configure the network adapter on your VM so that only your web server can communicate with it.
0
 

Author Comment

by:FNDAdmin
ID: 39762807
No virutalization available! Physical boxes
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 9

Assisted Solution

by:Trenton Knew
Trenton Knew earned 125 total points
ID: 39762923
Honestly, if it were me... I wouldn't worry about it unless you actually started to see issues with either performance OR security.  If you start getting a lot of database calls on your SQL server and it slows down the web application, then maybe get a bigger beefier box for that then, but if there's no problems atm, why fix what isn't broken?  you can probably configure your firewall to block remote connections to the SQL server so that only localhost can access it.  The only risk of threat then is someone compromising your web server box, in which case, it probably wouldn't matter if they were seperate anyway.  If you have a good firewall appliance in place, you probably could block remote attempts to connect to your SQL service on the box anyway.
0
 
LVL 75

Assisted Solution

by:Anthony Perkins
Anthony Perkins earned 250 total points
ID: 39762944
should I bother to separate SQL and IIS into two machines?
Absolutely, it is a must.  The way you are running both SQL and IIS on the same server is never recommended, unless this is for a small site with little traffic.  Both applications are just competing for resources.
0
 

Author Comment

by:FNDAdmin
ID: 39769135
The current box this IIS/SQL machine is running on is a Dell R320 E5-2407 2.2GHz CPU and 16GB of RAM. SQL is currently consuming 1.4GB of RAM with a total system usage of 4.2GB RAM. (26% usage).

     My primary concern is security. Sorry that I did not stress that in my initial questions/post.
0
 
LVL 75

Assisted Solution

by:Anthony Perkins
Anthony Perkins earned 250 total points
ID: 39769927
My primary concern is security. Sorry that I did not stress that in my initial questions/post.
You did, it is in the title.  I was just surprised that you were using a SQL Server installation in what is clearly not a recommended setup.  And even more surprised that your users are not complaining because of lousy performance.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
TSQL convert date to string 4 34
where to find DTS instalation package for sql 2014 64 bit 3 10
Parse this column 6 27
SQL Recursion schedule 13 14
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
Familiarize people with the process of utilizing SQL Server functions from within Microsoft Access. Microsoft Access is a very powerful client/server development tool. One of the SQL Server objects that you can interact with from within Microsoft Ac…
This videos aims to give the viewer a basic demonstration of how a user can query current session information by using the SYS_CONTEXT function

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question