Sorry seem to be confusing people here. I was trying to say it would be faster
behind the firewall than the way he is approaching it at present.
Currently he has:
MYSQL
|
---------------
USER -| INTERNET |- WEBSERVER
---------------
Where he wants to securley connect to MySQL from the webserver. Im saying
performance and security would be better as:
------------ ------------- ---------
USER -| INTERNET |-| FIREWALL |- WEBSERVER -| DMZ |- MYSQL
------------ ------------- ---------
Or combinations there of. Hope that makes sense :/
Nick
Quoting David Marshall <[EMAIL PROTECTED]>:
> > Obviously it should be said that no matter what this set up would be more
>
> > dangerous than having a MySQL server behind the firewall where the
> apache/php
> > server is hosted, also would be terribly slow.
>
> Depending on your firewall, performance does not have to be slow. Firewalls
> must be sized for the load, just like servers.
>
> We run a CISCO ArrowPoint Load Balancing CSS in front of Apache 1.3.19
> Mod_SSL(StrongHold 3 build 3014)
> We run a CISCO PIX 520 between Apache and WebLogic 5.1.
> We run a CISCO PIX 535 between Weblogic and Oracle 8i without performance
> issues.
> The Oracle datafiles are on a Net Appliance Filer, with a 1GB ethernet from
> Oracle to the Filer.
>
> David
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]