3.1

Table Of Contents
View Manager Administration Guide
34 VMware, Inc.
TherecommendedsecurityconfigurationforaDMZbasedsecurityserverdeployment
isthedualfirewall.Inthisconfiguration,anexternalnetworkfacing“frontend”
firewallprotectsboththeDMZandtheinternalnetwork,anda“backend”firewall
betweentheDMZandtheinternalnetworkprovidesasecondtierofsecurity.
Thefrontendfirew allisconfiguredtoallownetworktraffictoreachtheDMZ,whereas
thebackendfirewallisconfiguredtoonlyaccepttrafficthatoriginatesfromthe
serviceswithintheDMZ.ThisconfigurationisillustratedinFigure 25.
Figure 2-5. Example DMZ-Based Security Server Deployment
View Client
View Portal
HTTPS
traffic
HTTPS
traffic
fault-tolerant
load balancing
mechanism
View
Security
Server
DMZ
internal
network
View
Connection
Server
View
Connection
Server
VMware
VirtualCenter
Active
Directory
VMware
ESX servers
View
Security
Server
firewall
firewall