Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

DTS Security 1

Status
Not open for further replies.

link9

Programmer
Nov 28, 2000
3,387
US
Hello all,

I have a question about DTS security. There is no shortage of information about securing access to a particular DTS package, but I'm unable to find anything about the security of the actual data transfer.

For example, if we use DTS for replication between a site in Los Angeles & Atlanta, how secure is that data as it whizzes across 2000+ miles of internet?

For web security, we use SSL to encrypt the communication between the client and the server for transferring credit card information, etc... but how does DTS protect my data while it's moving from server to server?

Any articles, thoughts, links, etc... would be greatly appreciated.

Thanks,
Paul

penny.gif
penny.gif

The answer to getting answered -- faq855-2992
 
Paul,
Moving data through DTS uses the same security that SQL Server normally uses when sending data to any other client. There is basically no security on the data between the client (the other server) and the server.

If you have two data centers in LA and ATL in this case, you should already have a secure VPN connection going between the data centers to encrypt all your other data between offices. If you do then your security is already taken care of. If not, you have a couple of options. These will all require additional CPU load on the part of both servers.

1. You could use IPSec to secure the communication between the two servers.
2. You can configre SQL Server to use a certificate which will encypt the traffic between the client (other server) and the server.
3. Get some VPN routers and have them make a L2TP VPN connection between them selves (one at each site) and route the traffic over this connection instead of the unsecured connection. (This has no impact on the CPU load of the Servers).

The best option is to encrypt the traffic at the router using a L2TP VPN connection between sites. Your network should be setup like this no matter what, so that prying eyes can't see all the docs and email that you are passing between the two data centers.

For options 1 and 2 you should have no problem getting info from support.microsoft.com.

Denny

--Anything is possible. All it takes is a little research. (Me)
 
Outstanding, Denny.

Thank you for your input.

-paul

penny.gif
penny.gif

The answer to getting answered -- faq855-2992
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top