User's Guide

Chapter 2 Description
Managing Your Remote Library
Scalar i2000 Planning Guide 27
Scenario 3: Internal clients accessing multiple libraries across an
internal firewall
2
Many customers use a layered system of firewalls to safeguard resources.
In the scenario shown in
figure 13, a customer may have multiple Scalar
i2000s which need to be administered by internal staff (for instance data
center / network operations staff) – with a firewall in between the
administrators and libraries.
Figure 13
To enable LMC access between firewall zones, two solutions are possible
depending on the customer configuration. If the two zones are on the
same IP subnet, then the firewall will provide IP address and port
blocking functionality and should follow these rules:
Inbound access to port 1099 (Java RMI server port) by client IP
addresses
Stateful access control – used with most web technologies (e.g. web
mail) to enable a server to communicate with the client that started
the connection
If the two zones are on different subnets, or an IP address translation is
performed to mask the library’s true IP address, then the firewall must
provide routing rules that allow the client IP addresses to access specific
library IP addresses.