DMZ Clients and one central Gateway Server (in Company LAN)
Is this supported and a working scenario, when I just set up one gateway server in my compay lan and all my DMZ client are communicating with this server? Are there any restrictions?
May 28th, 2011 5:28pm
The point of using a gateway is normally to have just 1 port open in the firewall for 1 ip, so the gateway would typically be placed in a dmz. For a dmz client there is no need to go over a gateway it could just directly connect to a management server
as long as it can authenticate with it (certificates).Rob Korving
http://jama00.wordpress.com/
Free Windows Admin Tool Kit Click here and download it now
May 29th, 2011 3:53am
Exactly. If you dont place the gateway in the dmz itself in order to have a single point of communication for the dmz clients and one communication channel between DMZ gateway and central management servers, you can just point all agents to a management
server as well. If you have a fair number of dmz machines you could place a gateway in the dmz. If you only have a few you might just make the choice of leting them talk directly to an internal management server (only 1 port and uses certificates for the communication).Bob Cornelissen - BICTT (My BICTT Blog)
May 29th, 2011 4:54am
Have a look at Pete Zerger's blog: http://systemcentercentral.com/BlogDetails/tabid/143/IndexID/31342/Default.aspx
Free Windows Admin Tool Kit Click here and download it now
May 29th, 2011 5:19am