?
Solved

SQL ports

Posted on 2014-12-20
10
Medium Priority
?
97 Views
Last Modified: 2015-07-12
I'm in need to lock down communication from our web server to the sql server, and I'm having a hard time to lock down the ports. The web server is establishing a connection via 192.168.10.200:49528 to the SQL how can I SQL to be available only through 1433?
0
Comment
Question by:jdff
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511108
<<how can I SQL to be available only through 1433?>>
Disable all protocols but TCPIP.  Disable SQL Browser Service.
0
 

Author Comment

by:jdff
ID: 40511267
Can you provide me instructions on how to do it?
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511393
It is very simple.

Go onto SQL Manager/  Select Right Click and Disable
Disable SQL Browser:  SQL Browser is a service running on 1434 aiming at resolving non TCIP IP access.  Simply identify the service on SQL Manager, right click and disable from the pop up menu.  

Note the server won't be accessible anymore using Shared Pipes anymore once you do that.
0
10 Questions to Ask when Buying Backup Software

Choosing the right backup solution for your organization can be a daunting task. To make the selection process easier, ask solution providers these 10 key questions.

 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511394
Sorry by "SQL Manager" I meant "SQL Config Manager "  It is a program you will find in your SQL Server menu.
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511405
Shortcut is the following for opening the program(simply type in): SQLSERVERMANAGER11.msc (SQL 2012)
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40511580
Is there more than one SQL Server on 192.168.10.200? Because MSSQL only chooses a different port from 1433 if that port is used already.
If port 1433 is unused, than you can set up a fixed port in the SQL Config Manager in TCP/IP properties, in the region of IPAll.
0
 
LVL 23

Accepted Solution

by:
Racim BOUDJAKDJI earned 2000 total points
ID: 40511602
<<Is there more than one SQL Server on 192.168.10.200? Because MSSQL only chooses a different port from 1433 if that port is used already.>>
On single instance, generally installed as a default instance (vs named instance) only 1433 is activated by default for TCP IP.  By default also, SQL Server will attempt to resolve  connectivity thanks to the Browser Service using UDP port 1434.  To be sure the client connects only through TCP IP, it is good practice to switch off Browser Service protocols and service and change the port from 1433 to something else.  One can then connect by entering the IP followed by a comma as 243.35.37.347, 3544.  One can finally either specify a local alias on that port or directly enter a new entry in a DNS routing scheme in centralized DNS.

<<If port 1433 is unused, than you can set up a fixed port in the SQL Config Manager in TCP/IP properties, in the region of IPAll.>>
Actually, one can specify as many ports as necessary by entering each port separated by a comma.
0
 
LVL 51

Expert Comment

by:Vitor Montalvão
ID: 40512718
Can you provide more information?
How many SQL Server instances are installed in the server? And versions and editions of each instance?
Also, disabling SQL Server Browser service isn't a good idea. Your applications may stops working.
The best thing you can do is check in the SQL Server Configuration Manager if the MSSQL instance is using dynamic port or not. If it is, just change it to use a static port. You can set it providing a port number that isn't in use by another MSSQL instance or application.
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40512872
<<Your applications may stops working.>>
True thanks for the word of caution.  I should have mentioned that I assumed this is an OFFLINE operation so apologies if disabling shared pipes created any problem.

As the OP mentioned he needs to lockdown access from the front web server so if we can assume this is OFFLINE operation just do as I said.  If not, the OP will have to work with Shared Pipes activated.  

In any case, any change in TCP IP configuration will require a service restart and get you to the OFFLINE status.  This kind of changes are better done OFFLINE.
0
 

Author Comment

by:jdff
ID: 40540949
I'm going to make the restriction this week and let you guys know, thanks for the help so far.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
Ever wondered why sometimes your SQL Server is slow or unresponsive with connections spiking up but by the time you go in, all is well? The following article will show you how to install and configure a SQL job that will send you email alerts includ…
Via a live example, show how to backup a database, simulate a failure backup the tail of the database transaction log and perform the restore.
Via a live example, show how to setup several different housekeeping processes for a SQL Server.
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question