Article

Imagen de ScorpionSting
article
Reads:

%count lecturas

Score:
0
0
 
Comments:

2

DMZ Configuration with Access Manager

Author Info

30 May 2007 - 6:44am
Submitted by: ScorpionSting

(View Disclaimer)

Problem

A Forum reader recently asked:

"I am setting up NAM in the lab, with the configuration of the Identity Server and Access Gateway in the DMZ. I am not experienced it this type of setup, since we currently have iChian on the inside of the network, so this is going to be a completely different setup.

The IDP sever in the illustration of the "Setting Up Firewalls" section of the setup guide appears to have TWO NICS, and the Access Gateway appears to be set up that way. Or is this illustration indicating that the IDP server has a hole in the firewall to communicate to the LDAP server, and a hole in the firewall to communicate with the Admistration Console? I assume the LAG has to have two NICS, one for outside communication and the other for reverse proxies - correct?"

And here's the response from Ben Walter ...

Solution

You could use physical interfaces to do the segregation, but it'd be easier and cheaper to have the firewall doing all the port routing and restrictions.

Required ports between components is well documented in the official Novell Documentation

That shows most ports used between AM3 components.

AdjuntoTamaño
AM3_Traffic.gif234.87 KB

Disclaimer: As with everything else at Cool Solutions, this content is definitely not supported by Novell (so don't even think of calling Support if you try something and it blows up).

It was contributed by a community member and is published "as is." It seems to have worked for at least one person, and might work for you. But please be sure to test, test, test before you do anything drastic with it.




User Comments

Imagen de jwilleke

Plese check the link

Submitted by jwilleke on 6 June 2008 - 2:51am.

I get not found error. Thanks

Imagen de mfaris01

Does anyone have this image?

Submitted by mfaris01 on 5 April 2010 - 8:33am.

The original (old cools) link points to a novell site in nz and the link is no longer valid.
If anyone has AM3_Traffic.gif, can you please send it to Coolguys so this can be updated?
Or at least send a link of where it is.

This was a really good NAM map and I've lost mine.

Thanks,
Mike...

© 2013 Novell