[dba-SQLServer] X-posted: Security issue, opening SQL server port over internet

Erwin Craps - IT Helps Erwin.Craps at ithelps.be
Fri Oct 8 01:58:56 CDT 2004


 
Hi Group
A new POS software supplier for a customer from me, asks to open up the
SQL server port over the ADSL/Internet.
He needs this to synchronise database between two sites.
 
I however, have always understood that opening the SQL server port over
the internet is a serious security issue and should be avoided. Due to
the numerous security bugs I seen passing the catwalk I find this my
personal opinion to.
Next to that, the own SQL security system needs to be tuned/activated
because by default everything is wide open.
 
I am wondering what the opinion /experiance of the Access group is in
this matter.
I'm also wondering if the SQL server (I believe version 7) data is
encypted when sending over the internet?
 
I personaly would use a VPN connection and connect to to SQL server over
that VPN. I know this has some speed drawbacks but its safe...
 
 

 

Erwin Craps

Zaakvoerder 

www.ithelps.be/jonathan

 

This E-mail is confidential, may be legally privileged, and is for the
intended recipient only. Access, disclosure, copying, distribution, or
reliance on any of it by anyone else is prohibited and may be a criminal
offence. Please delete if obtained in error and E-mail confirmation to
the sender.

IT Helps - I.T. Help Center  ***  Box Office Belgium & Luxembourg

www.ithelps.be <http://www.ithelps.be/>   *  www.boxoffice.be
<http://www.boxoffice.be/>   *  www.stadleuven.be
<http://www.stadleuven.be/> 

IT Helps bvba* ** Mercatorpad 3 **  3000 Leuven

IT Helps  *  Phone: +32 16 296 404  *  Fax: +32 16 296 405 E-mail:
Info at ithelps.be 

Box Office **  Fax: +32 16 296 406 **  Box Office E-mail:
Staff at boxoffice.be <mailto:figures at boxoffice.be> 

 
--
_______________________________________________
AccessD mailing list
AccessD at databaseadvisors.com
http://databaseadvisors.com/mailman/listinfo/accessd
Website: http://www.databaseadvisors.com



More information about the dba-SQLServer mailing list