YOUR CHANNEL IS LOADING
  • 1

    Trusting Systems

  • 2

    Understanding HA

  • 3

    How do you solve T-SQL problems?

  • 4

    Morphing Microsoft

  • 5

    The Control Poll

The Voice of the DBA Layers of Security

MEVIOtoday

Dec 05, 2011 Layers of Security

I haven't configured many firewalls in my time, but if I were doing that job, I'm sure I'd be included in this report that says half of all firewalls are improperly configured. Firewalls are confusing, complicated, and it's incredibly easy to make a mistake when you are dealing with the complex rules of Windows networking and various application requirements. These days I call a friend, who's a firewall expert, to do any changes for me, and let him implement the rules. It's a slow, annoying process to watch, but I also understand that it's complex and he does a much better job than I'd do. Probably because he's more patient.

For the database administrator, however, this should be a wake-up call that lets you know you can't rely on the firewall to protect you. If you have a small 3 machine, one subnet network, maybe, but in most enterprises there are many subnets and complex rules to implement. That means that your company might not be a soft chewy center protected by a hard shell. It might be a soft center protected by Swiss cheese that does little to limit the influx of unauthorized requests.

 

Read the rest of "Layers of Security" at SQLServerCentral.