Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Odd Connection problem (Proxy + internal)

Status
Not open for further replies.

kgoods

MIS
Jun 14, 2001
70
US
Hope someone has some ideas on this one because I'm fresh out! :)
I have a SQL server on our internal network behind a linux firewall and Proxy server 2.0 (WinNT 4.0). It is the backend for an accounting system and can not be placed facing the internet (even in the DMZ). I have several users connecting to it from their workstations in the same
subnet. We have a sister company that has an accounting manager here that belongs to our network and also connects to this accounting package. Now the tough part, he has an assistant here that doesn't belong to our network but rather VPN's via a wireless internet connection to the sister company to access systems there. Now he wants this assistant to be able to access the accounting package (via file DSN's) to our internal SQL server.

I have read KB216415 where it shows how to access SQL through Proxy 2.0 by installing the Winsock proxy on the SQL server and mapping the ip address to the external IP of the proxy machine. But then it states that the SQL instance will no longer be listening on the (internal) IP
address but rather the winsock proxy as shown here:

2002-02-12 17:11:32.28 server SQL server listening on Winsock Proxy, Shared Memory, Named Pipes.

I'm guessing here.... but it seems like this would break the current connections and I really don't want to do that.

The assistant can not join our network and VPN out through the proxy machine as 2.0 doesn't support it. Besides, their network has had problems with malware and I'd rather not have any kind of direct connection between mine and theirs. I also thought about putting another nic in the assistant's machine and a firewall between that card and our network to limit access but this seems to be overkill.

Ideally, SQL listening on the current IP address and at the same time listening on the winsock proxy would solve the problem but I've not read anything that mentions this as a possibility.

Any ideas would be appreciated much.

Thanks,
Ken


 
Does the assistant need real time access? Will he/she be doing updates or actually using the package for anything but research?

If the answer to both is no, then maybe you can co-opt an older server, rebuild it and then set up Log Shipping from your main server to this one and set up this one with the WinSock stuff.



Catadmin - MCDBA, MCSA
"The only stupid question is the one that *wasn't* asked.
 
Thanks for the response Catadmin,

However, yes, the requirement is that she is working on the same dataset in real time. I've been doing this for some time now and this is a real head-scratcher.

If worse comes to worse I'll just build up a Linux firewall from the boneyard and pop another nic in her machine and be done with it. I just wish there was something a little "cleaner". :)

Kind regards,
ken
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top