Solved

SQL ports

Posted on 2014-12-20
10
95 Views
Last Modified: 2015-07-12
I'm in need to lock down communication from our web server to the sql server, and I'm having a hard time to lock down the ports. The web server is establishing a connection via 192.168.10.200:49528 to the SQL how can I SQL to be available only through 1433?
0
Comment
Question by:jdff
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511108
<<how can I SQL to be available only through 1433?>>
Disable all protocols but TCPIP.  Disable SQL Browser Service.
0
 

Author Comment

by:jdff
ID: 40511267
Can you provide me instructions on how to do it?
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511393
It is very simple.

Go onto SQL Manager/  Select Right Click and Disable
Disable SQL Browser:  SQL Browser is a service running on 1434 aiming at resolving non TCIP IP access.  Simply identify the service on SQL Manager, right click and disable from the pop up menu.  

Note the server won't be accessible anymore using Shared Pipes anymore once you do that.
0
Transaction Monitoring Vs. Real User Monitoring

Synthetic Transaction Monitoring Vs. Real User Monitoring: When To Use Each Approach? In this article, we will discuss two major monitoring approaches: Synthetic Transaction and Real User Monitoring.

 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511394
Sorry by "SQL Manager" I meant "SQL Config Manager "  It is a program you will find in your SQL Server menu.
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40511405
Shortcut is the following for opening the program(simply type in): SQLSERVERMANAGER11.msc (SQL 2012)
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 40511580
Is there more than one SQL Server on 192.168.10.200? Because MSSQL only chooses a different port from 1433 if that port is used already.
If port 1433 is unused, than you can set up a fixed port in the SQL Config Manager in TCP/IP properties, in the region of IPAll.
0
 
LVL 23

Accepted Solution

by:
Racim BOUDJAKDJI earned 500 total points
ID: 40511602
<<Is there more than one SQL Server on 192.168.10.200? Because MSSQL only chooses a different port from 1433 if that port is used already.>>
On single instance, generally installed as a default instance (vs named instance) only 1433 is activated by default for TCP IP.  By default also, SQL Server will attempt to resolve  connectivity thanks to the Browser Service using UDP port 1434.  To be sure the client connects only through TCP IP, it is good practice to switch off Browser Service protocols and service and change the port from 1433 to something else.  One can then connect by entering the IP followed by a comma as 243.35.37.347, 3544.  One can finally either specify a local alias on that port or directly enter a new entry in a DNS routing scheme in centralized DNS.

<<If port 1433 is unused, than you can set up a fixed port in the SQL Config Manager in TCP/IP properties, in the region of IPAll.>>
Actually, one can specify as many ports as necessary by entering each port separated by a comma.
0
 
LVL 50

Expert Comment

by:Vitor Montalvão
ID: 40512718
Can you provide more information?
How many SQL Server instances are installed in the server? And versions and editions of each instance?
Also, disabling SQL Server Browser service isn't a good idea. Your applications may stops working.
The best thing you can do is check in the SQL Server Configuration Manager if the MSSQL instance is using dynamic port or not. If it is, just change it to use a static port. You can set it providing a port number that isn't in use by another MSSQL instance or application.
0
 
LVL 23

Expert Comment

by:Racim BOUDJAKDJI
ID: 40512872
<<Your applications may stops working.>>
True thanks for the word of caution.  I should have mentioned that I assumed this is an OFFLINE operation so apologies if disabling shared pipes created any problem.

As the OP mentioned he needs to lockdown access from the front web server so if we can assume this is OFFLINE operation just do as I said.  If not, the OP will have to work with Shared Pipes activated.  

In any case, any change in TCP IP configuration will require a service restart and get you to the OFFLINE status.  This kind of changes are better done OFFLINE.
0
 

Author Comment

by:jdff
ID: 40540949
I'm going to make the restriction this week and let you guys know, thanks for the help so far.
0

Featured Post

[Webinar] How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them. Thursday, July 13, 2017 10:00 A.M. PDT

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

International Data Corporation (IDC) prognosticates that before the current the year gets over disbursing on IT framework products to be sent in cloud environs will be $37.1B.
A Stored Procedure in Microsoft SQL Server is a powerful feature that it can be used to execute the Data Manipulation Language (DML) or Data Definition Language (DDL). Depending on business requirements, a single Stored Procedure can return differe…
Via a live example combined with referencing Books Online, show some of the information that can be extracted from the Catalog Views in SQL Server.
Using examples as well as descriptions, and references to Books Online, show the documentation available for datatypes, explain the available data types and show how data can be passed into and out of variables.

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question