Heres the scenario. There are 2 servers. One is win2k which is a web server with .net framework. The other is a win2003 with sql db server. These servers are on different segments of a Cisco pix firewall. The web server is the DMZ and the db server is on a more restricted segment. I want to setup VPN tunneling between the two servers.
Basically the db server should not be talking to any other server other than the web server. The web server should be able to talk to the db server as well allow clients from outside the firewall. Currently the web server allows clients connections from outside.
I thought this is what I should be doing to set up the VPN tunneling. Set up the DB server IPSec policy as Require security and specify the IP address of the web server. Set up the Web server IPSec policy as Client-Respond only (and add the IPaddress of the DB server ??). I guess I will also have to configure pix to allow ipsec traffic between the 2 servers.
Kindly let me know if I am in the right direction here. If yes, then can you kindly point me to detailed guides, step-by-step howtos to help me set it up the way I want to. Dont worry about configuring the pix part. If not, then could you point me in the right direction with the same guides and howtos.
Thanks
Basically the db server should not be talking to any other server other than the web server. The web server should be able to talk to the db server as well allow clients from outside the firewall. Currently the web server allows clients connections from outside.
I thought this is what I should be doing to set up the VPN tunneling. Set up the DB server IPSec policy as Require security and specify the IP address of the web server. Set up the Web server IPSec policy as Client-Respond only (and add the IPaddress of the DB server ??). I guess I will also have to configure pix to allow ipsec traffic between the 2 servers.
Kindly let me know if I am in the right direction here. If yes, then can you kindly point me to detailed guides, step-by-step howtos to help me set it up the way I want to. Dont worry about configuring the pix part. If not, then could you point me in the right direction with the same guides and howtos.
Thanks