Re: Hosting, in or out?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Holz wrote:
Our client has an SBS 2003 with a SQL server installed, 40 users, the proprietary SQL based application is the core of the business.
A new requirement calls for a report only server, one that will obtain the data from the SQL server and allow outside customers to pull their own status reports. The server will run ASP, .NET framework 3.5, all built with Visual Studio.
I suggested we host it outside on their ISP (he offers dedicated Windows hosting) rather then inside, their developer insists on inside hosting, i guess for ease of development. There is a good Cisco perimeter, however my concern is bandwidth and overall security.
I would like to hear more opinions.


I don't think you really need to, do you? It sounds as if the client's business stands or falls with the server, so they need to start by asking the developer how much insurance he carries to cover his work, and to decide whether that is sufficient to recover the business in the worst-case scenario.

My preference would be to not only host the web part of the application outside, but also to feed it from a slave database on the same server, synchronised to the master by push, so that the SBS SQL Server never needs to be exposed either to the Net or to a web application.

It is reasonable for the developer to have confidence in the security of his own designs, but it is not reasonable for him to assert that he never makes mistakes, nor to expect the whole basis of the client's business to rest on the integrity of his work. SBS is inevitably very much an all-the-eggs-in-one-basket system already: the least you can do is to carry the basket as carefully as possible.
--
Joe
.



Relevant Pages

  • Re: Linked Server Security
    ... security flaw) by creating a sql user on the dev box that did ... corporate db security because of a developer who used his sql login to ... create a linked server on a box he manages. ... However, before you do this, I suggest that you request that this developer ...
    (microsoft.public.sqlserver.security)
  • Re: But a fool with a tool is still a fool
    ... The design patterns used in OPF is ideal *and* cool. ... how creative other developers get in writing SQL in code (ex. ... If the developer had placed the business logic on the server (each country ...
    (borland.public.delphi.non-technical)
  • Re: So our software providor got gobbled up
    ... have done deployments on Oracle and SQL. ... should plan long term business strategies around such a company. ... or money on a high-zoot server can be well-served by Xserve. ... Timberwoof http://www.timberwoof.com ...
    (comp.sys.mac.advocacy)
  • Re: SBS2003 Partitioning
    ... It doesn't matter how small the business is it is a bad practice to sell a workstation for use as a server. ... Businesses come to rely on a server very quickly and within a matter of months may no longer be able to function effectively if the server goes down. ... There is no real advantage to moving the page file from the system partition in a small server with one drive/array, and yes it's a good idea to keep Exchange and SQL on separate partitions but given the size of drive you intend on using probably two partitions, at most three, is your best option. ...
    (microsoft.public.windows.server.sbs)
  • Re: Fault Tolerence on SBS2003 Prem.
    ... > Too often this topic is approached without defining any scale or costs. ... There is always a compromise involved in any business ... > server equipment that improved the recovery time from an annual event from ...
    (microsoft.public.windows.server.sbs)