hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Colocation and Data Centers : network setup (win2K)
Reply

Colocation and Data Centers Find data centers, server hardware, bandwidth providers, and techniques for colocation purposes. Get advice on colocation web hosting, review providers and offer suggestions on choosing colocation hosting services and the right datacenter. If your service is unavailable, please click here.
Forum Jump

network setup (win2K)

Reply Post New Thread In Colocation and Data Centers Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 02-09-2004, 06:44 PM
tveye tveye is offline
Newbie
 
Join Date: Nov 2003
Posts: 22

network setup (win2K)


Getting ready to install 4 servers (2 database and 2 web). I'll have 5 usable IPs. Plan to manage everything via Terminal Services (Remote Desktop).

1) Should I set up Active Directory (which requires running DNS on at least one) or make them all standalone servers?

2) For security purposes and to make the best use of the 5 IPs, I wanted to give the database servers private IPs only, but on second thought wouldn't that prevent me from accessing them with Terminal Services? What's the best way?

Thanks

Reply With Quote


Sponsored Links
  #2  
Old 02-10-2004, 04:18 AM
Jay Suds Jay Suds is online now
Web Hosting Master
 
Join Date: Jun 2001
Location: Denver, CO
Posts: 3,233
You will likely see very few benefits of running AD with just 4 servers.

From a security POV, if you don't want your database servers externally accessible, but you still want to be able to manage them remotely, you can do a few things, but they could get costly.

- Cheapo method, would require 2 NICs per web server and 2 switches:

Data Center Uplink
|
switch #1
| |
Web1 Web2
| |
switch #2
| |
DB1 DB2

With this method, you would relay a TS connection through either web server to your DB servers.

- More Expensive - Requires firewall (such as SonicWall SOHO5 + VPN)

Data Center Uplink
|
Firewall / VPN Device
| | | |
Web1 Web2 DB1 DB2

Configure firewall to only allow only neccessary traffic, do not allow external SQL connections or RDP traffic. Setup a VPN tunnel with the firewall, which will provide you with full remote access to your servers over an encrypted link.

Most Expensive -
Same idea as with one firewall, but use two firewalls. The first firewall will use an external subnet with the web servers hanging off of it. The second firewall will use a non-routeable subnet, and only allow port 1433 traffic through, from the external subnet facing it only. Second firewall is uplinked to the first firewall. Same as before, you would setup a VPN tunnel for management / TS access. In order to "route" the non-routeable subnet locally, your firewall devices would have to support static routing (most do).

I'm sure there's more/better solutions to this, but hey - it's 3:20AM

__________________
Jay Sudowski // Handy Networks LLC // Co-Founder & CTO
AS30475 - Level(3), HE, Telia, XO and Cogent. Noction optimized network.
Offering Dedicated Server and Colocation Hosting from our SSAE 16 SOC 2, Type 2 Certified Data Center.
Current specials here. Check them out.

Reply With Quote
  #3  
Old 02-10-2004, 10:43 AM
tveye tveye is offline
Newbie
 
Join Date: Nov 2003
Posts: 22
Thanks for your help Jay! With the first method, how do you relay a TS connection?

Reply With Quote
Sponsored Links
  #4  
Old 02-10-2004, 11:57 AM
Jay Suds Jay Suds is online now
Web Hosting Master
 
Join Date: Jun 2001
Location: Denver, CO
Posts: 3,233
Install TS Client on the web server. The, TS to the Web Server, open TS client on the Web Server and TS to the SQL Server.

__________________
Jay Sudowski // Handy Networks LLC // Co-Founder & CTO
AS30475 - Level(3), HE, Telia, XO and Cogent. Noction optimized network.
Offering Dedicated Server and Colocation Hosting from our SSAE 16 SOC 2, Type 2 Certified Data Center.
Current specials here. Check them out.

Reply With Quote
  #5  
Old 02-10-2004, 01:56 PM
tveye tveye is offline
Newbie
 
Join Date: Nov 2003
Posts: 22
Thanks Jay. I thought that's what you meant but wasn't sure.

So for the first method (just to make sure I'm clear) you're suggesting to plug uplink, web1_nic1, and web2_nic1 into switch_1. Then connect web1_nic2, web2_nic2, db1_nic1, and db2_nic1 into switch_2. Correct?

With that setup could the web servers use all 5 public IPs (say 3 on one, 2 on the other) while the DB boxes use private IPs?

Reply With Quote
  #6  
Old 02-10-2004, 02:40 PM
RackMy.com RackMy.com is offline
Web Hosting Master
 
Join Date: Apr 2001
Location: St. Louis, MO
Posts: 2,508
Don't run AD if you don't

__________________
Mike @ Xiolink.com
http://www.xiolink.com 1-877-4-XIOLINK
Advanced Managed Microsoft Hosting
"Your data... always within reach"

Reply With Quote
  #7  
Old 02-10-2004, 03:02 PM
tveye tveye is offline
Newbie
 
Join Date: Nov 2003
Posts: 22
Quote:
Originally posted by RackMy.com
Don't run AD if you don't
Huh? Don't run it if I don't what?

Reply With Quote
  #8  
Old 02-10-2004, 07:59 PM
Jay Suds Jay Suds is online now
Web Hosting Master
 
Join Date: Jun 2001
Location: Denver, CO
Posts: 3,233
I think it should have read "Don't run AD if you don't [have to]". Anyhow, you have understood things correctly. The web servers would get all of the external IPs, and you would load private IPs on nic_2 on the web servers and the SQL servers.

__________________
Jay Sudowski // Handy Networks LLC // Co-Founder & CTO
AS30475 - Level(3), HE, Telia, XO and Cogent. Noction optimized network.
Offering Dedicated Server and Colocation Hosting from our SSAE 16 SOC 2, Type 2 Certified Data Center.
Current specials here. Check them out.

Reply With Quote
  #9  
Old 02-10-2004, 09:49 PM
Potsie Potsie is offline
Junior Guru
 
Join Date: Jan 2002
Posts: 229
You really don't need the second NIC and switch if you're cool with the "TS in a TS session" method.
Be warned that it can be slow. It does work fine for me on a 256K up Cable connection from home, but is much more responsive on the 512k SDSL at the office. Not sure why, but the upload seems to make a difference.

Reply With Quote
  #10  
Old 02-11-2004, 08:11 AM
Avatar Avatar is offline
WHT Addict
 
Join Date: Mar 2002
Posts: 159
You could also use an managed switch with support for VLAN's instead of 2 switches.

__________________
Alex Threlfall
Cyberprog New Media
www.cyberprog.net
I don't have to look for trouble. It seems to know pretty much all the time where I am.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Vodien Launches Full Rack Colocation Solution at Singapore Data Center Web Hosting News 2012-12-27 16:07:25
Web Host Rackspace Introduces Cloud Network Isolation Technology Web Hosting News 2012-10-30 11:35:37
Web Host JaguarPC Upgrades Network Infrastructure to Meet Customer Demand Web Hosting News 2012-03-06 16:32:14
Cloud Storage Firm IceWeb Offers Customers Five Minute Set-Up Guarantee Web Hosting News 2012-01-27 12:31:55
Web Host 100TB.com Launches Content Delivery Network Web Hosting News 2011-08-05 19:39:08


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?