Linux Netfilter discussions
 help / color / mirror / Atom feed
* What is best protection for RDBMS backend of web-server in DMZ
@ 2004-08-22 15:43 Sanjay Arora
  2004-08-22 16:54 ` Antony Stone
  2004-08-23  2:36 ` John A. Sullivan III
  0 siblings, 2 replies; 5+ messages in thread
From: Sanjay Arora @ 2004-08-22 15:43 UTC (permalink / raw)
  To: Netfilter Mailing List

Hi all

What are the issues involved in securing a RDBMS that is serving a web-server in DMZ. RDBMS is postgreSQL, OS is Linux, Webserver is Apache.

Application is CRM, Customer Registration/Editing is the main part that interacts with the web, Rest of the CRM application works in the Green subnet protected by an iptables firewall, specicically IPcop v. 1.3 presently. 

Should I bifurcate the DB and put the registration part in DMZ or should I put a copy of the registration part in DMZ and sync it periodically with the main DB. Or should I keep full DB on the Green Network & create a pinhole to access the RDBMS from the Green subnet, maybe in some kind of ssh tunnel. Any other ideas unknown to me that may be workable?

Can some one point me to resources that discuss these issues. Also, I would like the experienced people to please comment on pros & cons of various methodologies and pointers to security literature/checklists for Web-server/RDBMS security issues, especially on a shoestring budget with netfilter, linux & other open source tools. Please touch on various subjects like monitoring, recovery etc., so as to give me broad idea of scope of my research and pointers to resources.

With best regards and thanks in advance.
Sanjay.




^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2004-08-23 15:31 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-08-22 15:43 What is best protection for RDBMS backend of web-server in DMZ Sanjay Arora
2004-08-22 16:54 ` Antony Stone
2004-08-23  2:36 ` John A. Sullivan III
2004-08-23 11:46   ` Sanjay Arora
2004-08-23 15:31     ` John A. Sullivan III

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox