Merge replication security

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Elmer Miller (millere_at_empireco.nospam)
Date: 11/08/04


Date: Mon, 8 Nov 2004 10:20:59 -0500

I am doing merge replication to PocketPC devices using SSCE over the
internet and I'm wondering if I can increase security by moving the
distributor into the DMZ so that IIS will not need to connect all the way
back into our internal network (where our SQL is). We are curently using
standard security and have holes in our firewall to allow traffic from dmz
to sql. If we put the distributor into DMZ could and made the internal
domain trusted in the DMZ, could we close the firewall holes so that all
communication needs to be initiated from the internal network? That way if
someone hacked into the DMZ they couldn't take advantage of the open ports.
Would this also allow us to use integrated security with DMZ domain
accounts?
Alternatively, is there a way to use VPN on PocketPC with merge replication?
What is the best solution for this problem?
Thanks.



Relevant Pages

  • Re: What is DMZ?
    ... Please don't confuse a DMZ with the "all forward" feature on cheap NAT ... a machine that is providing a service to people on the internet will be ... This is why DMZ's were originally set-up;to apply a security policy on traffic from ... This means that the companies security design must mandate that all internal hosts will ...
    (comp.security.firewalls)
  • RES: DMZ design
    ... DMZ cannot access the Office LAN and from Office LAN just the ... necessary access to the internet (e-mail, http and any other port access ... technical IT security event. ...
    (Security-Basics)
  • Re: Exchange server in DMZ, not FE server. Is this ever ok?
    ... NICs - one for the internal network, and the other for the DMZ. ... of security. ... I am pretty sure that AD is not made to be exposed to the internet. ...
    (microsoft.public.security)
  • Re: Using with DMZ, etc.
    ... thoughts about having an FTP server in a DMZ so it would be accessable ... the Internet. ... Anything you expose to the world is an increased security risk, ... an FTP server is not usually a giant one compared to many other things. ...
    (microsoft.public.windows.server.general)
  • Risks Digest 26.65
    ... ACM FORUM ON RISKS TO THE PUBLIC IN COMPUTERS AND RELATED SYSTEMS ... Internet Amorality, and Cutting Thailand Off From the Internet ... "Face Unlock feature in Galaxy Nexus poses security risk" (Matt Hamblen via ... Facebook Settles With F.T.C. Over Deception Charges ...
    (comp.risks)