22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

158 Lotus Security Handbook<br />

7. Data Access to Data Access zone policies<br />

Table 4-7 Data Access to Data Access zone (Site-to-Site)<br />

Application Protocol Port DataAccess DataAccess Comments<br />

HTTP TCP 80 X X Inter-site Admin / XML<br />

Non-Confidential Data)<br />

HTTPS<br />

(SSL)<br />

TCP 443 X X Inter-site Admin / XML<br />

(Confidential Data)<br />

LDAP TCP 389 X X Master and Replicas (Non<br />

Confidential Data)<br />

LDAP (SSL) TCP 636 X X Master and Replicas<br />

(Confidential Data)<br />

Domino<br />

Replication<br />

TCP 1352 X X Master and Replicas (Non<br />

Confidential Data)<br />

H - host specific filters<br />

X - network filters<br />

8. Data Access to Internet zone policies<br />

Table 4-8 Data Access to Internet zone flows (Outbound) - NAT/PAT<br />

Application Protocol Port DataAccess Internet Comments<br />

HTTP TCP 80 H X Via NAT/PAT on Data Access<br />

to Proxy firewall.<br />

HTTPS<br />

(SSL)<br />

TCP 443 H X Via NAT/PAT on Data Access<br />

to Proxy firewall.<br />

H - host specific filters<br />

X - network filters<br />

9. Intranet to Internet zone policies<br />

The Intranet to Internet flow policies are data services that are not part of<br />

providing external access to internal resources, but are used for internal network<br />

clients accessing external resources. These are generally workstations in the<br />

Intranet zone that need to access external servers. Your policies may vary widely<br />

from what we allow within <strong>IBM</strong>. For example, some organizations only permit<br />

HTTP connections from their Intranet zone to a Proxy zone where a forward<br />

HTTP proxy resides. In this case, only the forward HTTP proxy would be<br />

permitted to connect on ports 80 and 443 to a resource in the Internet zone.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!