82 IBM Tivoli Remote Control Across Firewalls
We should also point out that a Tivoli Endpoint Gateway was already deployed
before the Tivoli Firewall Security Toolbox technology had been announced, in
order to manage the Endpoints in the Servers zone.
Figure 2-3 depicts the current CSI Corporation Tivoli environment prior to the
IBM Tivoli Remote Control Proxy solution deployment. The External zone
represents the site where the first and second level support location. The DMZ,
Internal, and Servers zones are all located at CSI’s main site.
Figure 2-3 Case study scenario without RC Proxy architecture
Based on Figure 2-3, there can be several ways to implement A Remote Control
solution for CSI. The following sections present two possible implementation
planning as follows:
Using a combination of Standalone and Non-Standalone solutions
Using Non-Standalone mode solution only
Endpoint A
Enpoint D
TMR Server
DMZ
Gateway Proxy Endpoint Proxy
External
Firewall 2 Firewall 3Firewall 1
Relay 1 TFST
Endpoint GW
Endpoint GW
Endpoint GW
Servers
Internal
Endpoint B
Endpoint C