[H]ard Users and SysAdmins are the Best, So I'll pose this question to you guys:
(Precursor, I'm a fairly New Network Admin, I inherited a mess with the position and I'm fixing it piece by piece)
We dont use Certificates inside our internal network, as much as I would prefer to, so Im not really up to snuff on my SSL. But here is the scenario I need help with:
We will be using a Hosted service to handle/present(Web) some customer information for a database/Software we use. The External company needs to query OUR internal Database server VIA ODBC (Our SQL Server is handling more than just the single database).
We recently installed an IPS device. We plan on setting up an ISA server to handle authentication on the Edge to work WITH the IPS device.
So The dataflow would be:
External Server ---> IPS(Untrusted) ---> ISA ---> IPS (Trusted)--> OURSQLSERVER
The External Hosted Service obviously Requires an SSL Certificate on our side to encrypt the data before we send it off to them. My Question is - Where the hell do I install this SSL Cert? Their handshake will technically be with our ISA server, So is that where I install the Certificate, leaving the SQL Unencrypted to the ISA, Or do I really need two SSL Certs here, One for the Specific SQL Instance to the ISA, and one to the External Hosted Service?
Thanks for the help guys, I appreciate it!
TJ Wenger
(Precursor, I'm a fairly New Network Admin, I inherited a mess with the position and I'm fixing it piece by piece)
We dont use Certificates inside our internal network, as much as I would prefer to, so Im not really up to snuff on my SSL. But here is the scenario I need help with:
We will be using a Hosted service to handle/present(Web) some customer information for a database/Software we use. The External company needs to query OUR internal Database server VIA ODBC (Our SQL Server is handling more than just the single database).
We recently installed an IPS device. We plan on setting up an ISA server to handle authentication on the Edge to work WITH the IPS device.
So The dataflow would be:
External Server ---> IPS(Untrusted) ---> ISA ---> IPS (Trusted)--> OURSQLSERVER
The External Hosted Service obviously Requires an SSL Certificate on our side to encrypt the data before we send it off to them. My Question is - Where the hell do I install this SSL Cert? Their handshake will technically be with our ISA server, So is that where I install the Certificate, leaving the SQL Unencrypted to the ISA, Or do I really need two SSL Certs here, One for the Specific SQL Instance to the ISA, and one to the External Hosted Service?
Thanks for the help guys, I appreciate it!
TJ Wenger