3.0.1

Table Of Contents
VMware, Inc. 33
Chapter 2 Installation
TherecommendedsecurityconfigurationforaDMZbasedsecurityserverdeployment
isthedualfirewall.Inthisconfiguration,anexternalnetworkfacing“frontend”
firewallprotectsboththeDMZandtheinternalnetwork,anda“backend”firewall
betweentheDMZandtheinternalnetworkprovidesasecondtierofsecurity.
Thefrontendfi
rewallisconfiguredtoallownetworktraffictoreachtheDMZ,whereas
thebackendfirewallisconfiguredtoonlyaccepttrafficthatoriginatesfromthe
serviceswithintheDMZ.ThisconfigurationisillustratedinFigure 25.
Figure 2-5. Example DMZ-Based Security Server Deployment
View Client
View Portal
HTTPS
traffic
HTTPS
traffic
fault-tolerant
load balancing
mechanism
View
Security
Server
DMZ
internal
network
View
Connection
Server
View
Connection
Server
VMware
VirtualCenter
Active
Directory
VMware
ESX servers
View
Security
Server
firewall
firewall