Networking Forums

Networking Forums > Computer Networking > Windows Networking > Webserver and two networks...

Reply
Thread Tools Display Modes

Webserver and two networks...

 
 
callindril@gmail.com
Guest
Posts: n/a

 
      06-22-2007, 08:07 PM
Howdy,

I am setting up an application that requires a webserver to be
available to the internet at large, and an internal network with the
Oracle database on it that needs to be protected from the internet at
large...

I have two dedicated Class C IPs, and two router/firewall boxes I can
use. I also have 2 server 2003 boxes, one running tomcat as the
webserver with 2 nic cards and the other running Oracle as the
database server...

One of the Class-C IPs is assigned to a router/firewall box and
provides nat/dhcp and internet access to nodes on the internal
network.

The database server needs to sit behind the firewall for users of the
internal network to access it, but also be available to the webserver
for application data requests..

What I would like to have is the database server be on the internal
network and only be accessible by users on the internal network and
the tomcat application on the web server. And have the webserver be
available to the internet at large, and use the two nic cards in this
box as a 'security blanket' to protect the internal network (and the
database server) from outside access.

So folks coming in via the internet hit the webserver application.
The application talks to the Database via the internal network
connection, and the internet folks never know about the internal
network side of the world...

One other caveat is that the internal network users will also need to
use the application via the internal network connection...

So am I out of my gourd in thinking this will work, or is there a
better solution that provides the security the database and internal
network requires, and still allows the webserver to sit on the
Internet and talk to the database server...

Thanks!!
Cal

 
Reply With Quote
 
 
 
 
Robert L [MVP - Networking]
Guest
Posts: n/a

 
      06-22-2007, 08:48 PM
In this case, you can enable NAT/Firewall on the webserver.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
<(E-Mail Removed)> wrote in message news:(E-Mail Removed) ups.com...
Howdy,

I am setting up an application that requires a webserver to be
available to the internet at large, and an internal network with the
Oracle database on it that needs to be protected from the internet at
large...

I have two dedicated Class C IPs, and two router/firewall boxes I can
use. I also have 2 server 2003 boxes, one running tomcat as the
webserver with 2 nic cards and the other running Oracle as the
database server...

One of the Class-C IPs is assigned to a router/firewall box and
provides nat/dhcp and internet access to nodes on the internal
network.

The database server needs to sit behind the firewall for users of the
internal network to access it, but also be available to the webserver
for application data requests..

What I would like to have is the database server be on the internal
network and only be accessible by users on the internal network and
the tomcat application on the web server. And have the webserver be
available to the internet at large, and use the two nic cards in this
box as a 'security blanket' to protect the internal network (and the
database server) from outside access.

So folks coming in via the internet hit the webserver application.
The application talks to the Database via the internal network
connection, and the internet folks never know about the internal
network side of the world...

One other caveat is that the internal network users will also need to
use the application via the internal network connection...

So am I out of my gourd in thinking this will work, or is there a
better solution that provides the security the database and internal
network requires, and still allows the webserver to sit on the
Internet and talk to the database server...

Thanks!!
Cal

 
Reply With Quote
 
callindril@gmail.com
Guest
Posts: n/a

 
      06-23-2007, 12:47 AM
On Jun 22, 4:48 pm, "Robert L [MVP - Networking]"
<nore...@hotmail.com> wrote:
> In this case, you can enable NAT/Firewall on the webserver.
>


Sorry..I dont follow....

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WE BUY used, new and refurbed Sun, Cisco, Lucent, Nortel, Alcatel,3com, IBM, HP, Compaq, Dell, Madge, Cabletron, Juniper Networks, Bintec,Siemens, Foundry, Networks, Extreme Networks, Fore/Marconi, TellabsLucent/Avaya/Ascend, Xylogics, Brocade, Int Mike Linux Networking 0 02-16-2008 08:35 PM
WE BUY used, new and refurbed Sun, Cisco, Lucent, Nortel, Alcatel,3com, IBM, HP, Compaq, Dell, Madge, Cabletron, Juniper Networks, Bintec,Siemens, Foundry, Networks, Extreme Networks, Fore/Marconi, TellabsLucent/Avaya/Ascend, Xylogics, Brocade, Int Mike Broadband 0 02-16-2008 01:48 AM
WE BUY used, new and refurbed Sun, Cisco, Lucent, Nortel, Alcatel,3com, IBM, HP, Compaq, Dell, Madge, Cabletron, Juniper Networks, Bintec,Siemens, Foundry, Networks, Extreme Networks, Fore/Marconi, TellabsLucent/Avaya/Ascend, Xylogics, Brocade, Int Mike Broadband 0 01-12-2008 09:35 AM
WE BUY used, new and refurbed Sun, Cisco, Lucent, Nortel, Alcatel,3com, IBM, HP, Compaq, Dell, Madge, Cabletron, Juniper Networks, Bintec,Siemens, Foundry, Networks, Extreme Networks, Fore/Marconi, TellabsLucent/Avaya/Ascend, Xylogics, Brocade, Int buyonet@hotmail.com Broadband 0 11-18-2007 10:58 AM
webserver to webserver access via VPN ton de w Windows Networking 3 01-17-2007 08:12 PM



1 2 3 4 5 6 7 8 9 10 11