Article
Problem
A Forum reader recently asked:
"I am setting up NAM in the lab, with the configuration of the Identity Server and Access Gateway in the DMZ. I am not experienced it this type of setup, since we currently have iChian on the inside of the network, so this is going to be a completely different setup.
The IDP sever in the illustration of the "Setting Up Firewalls" section of the setup guide appears to have TWO NICS, and the Access Gateway appears to be set up that way. Or is this illustration indicating that the IDP server has a hole in the firewall to communicate to the LDAP server, and a hole in the firewall to communicate with the Admistration Console? I assume the LAG has to have two NICS, one for outside communication and the other for reverse proxies - correct?"
And here's the response from Ben Walter ...
Solution
You could use physical interfaces to do the segregation, but it'd be easier and cheaper to have the firewall doing all the port routing and restrictions.
Required ports between components is well documented in the official Novell Documentation
That shows most ports used between AM3 components.
| Adjunto | Tamaño |
|---|---|
| AM3_Traffic.gif | 234.87 KB |
Disclaimer: As with everything else at Cool Solutions, this content is definitely not supported by Novell (so don't even think of calling Support if you try something and it blows up).
It was contributed by a community member and is published "as is." It seems to have worked for at least one person, and might work for you. But please be sure to test, test, test before you do anything drastic with it.
Related Articles
User Comments
- Be the first to comment! To leave a comment you need to Login or Register
Does anyone have this image?
Submitted by mfaris01 on 5 April 2010 - 8:33am.
The original (old cools) link points to a novell site in nz and the link is no longer valid.
If anyone has AM3_Traffic.gif, can you please send it to Coolguys so this can be updated?
Or at least send a link of where it is.
This was a really good NAM map and I've lost mine.
Thanks,
Mike...
- Be the first to comment! To leave a comment you need to Login or Register


2