22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 14-20 Not Authorized<br />

The reverse proxy server will only allow connections to the Domino Directory<br />

(names.nsf) and to the mail directory (/mail). The Domino Directory needs to be<br />

accessible for user authentications. By only allowing the Reverse Proxy server<br />

access to certain files and directories, it provides an added layer of security.<br />

14.2.3 Firewall configuration<br />

The WebSphere Edge Server reverse proxy server was placed in the DMZ of our<br />

lab’s firewall. This allows connections to be made to it from the simulated<br />

Internet, and also allows the reverse proxy server to be configured with access to<br />

the Domino server. The Domino, QuickPlace, and Sametime servers were<br />

placed inside the firewall. They are accessible to any user inside the network.<br />

The firewall was configured to only allow port 80 and port 443 connections from<br />

the Internet into the DMZ and to the reverse proxy server. The firewall rules are<br />

shown in Figure 14-21.<br />

The firewall was also configured to only allow connections from the reverse proxy<br />

server into the internal network to the Domino server.<br />

Chapter 14. Scenario implementation details 609

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!