User`s guide

29
DMZ Proxy
DMZ Proxy Overview
OneBridge Sync Server includes a component that can be installed within a corporate DMZ or Firewalling Gateway to bolster
security for devices connecting to the Sync Server from outside the corporate network. The DMZ Proxy is a proxy server, or an
application-specific firewall for Sync Server. The use of DMZ Proxy software makes utilizing filtering/firewalling significantly less
complex to set up, while enhancing security and ease of use for such functions as auditing (for intrusion detection or usage
monitoring). The DMZ Proxy understands the OneBridge protocol. It makes it possible to disallow any connections from the
Internet to the private network. The DMZ Proxy examines and authenticates each connection and checks OneBridge protocol
packets for validity.
The DMZ Proxy can be configured to define which host to forward to, which port to use to connect to that host on, and what
protocol to use (http/https). However, the use of https would be redundant and an unnecessary incremental degradation to
performance, because the communications are already encrypted, even over http. The firewalling/filtering rules between the
DMZ and the private network should be set up to only allow connections to the Sync Server from the DMZ Proxy.
Installing the DMZ Proxy Software
This procedure performs a basic installation of the DMZ Proxy software. The DMZ Proxy software is installed on a server in the
DMZ network. It forwards client requests to the OneBridge Sync Server in the private network.
1. From the Installer screen of the CD-ROM, select Sync Server and click install now.
2. Click Yes to accept the License Agreement.
3. Click Multiple Node Configuration.
4. Click DMZ Proxy Software.
5. Choose the install directory for the program and click Next.
6. Choose the data directory for the program and click Next. The data directory stores configuration and user backup
information. You may want to select a location that is available for backups, such as a network drive.
7. Configure the OneBridge Service. See Configuring the OneBridge Service.