Configure Perimeter Servers to Manage Secure Proxy Communications

A perimeter server is used by Secure Proxy to manage inbound and outbound TCP communication. This software tool enables you to manage the communications flow between outer layers of your network and the TCP-based transport adapters. Perimeter servers can be used to restrict areas where TCP connections are initiated from more secure areas to less secure areas.

During the Secure Proxy installation, a perimeter server is installed. This perimeter server is referred to as the local perimeter server. You can use this default local perimeter server to restrict connections or you can install other perimeter server instances as needed. You can install additional perimeter servers on different computers or you can install different instances on the same computer, if you want to use different network cards for inbound and outbound traffic. A perimeter server requires a perimeter server definition in Secure Proxy. When you create multiple perimeter server definitions for your engines, use unique port numbers for each listener.

After you install and configure a remote perimeter server, you need to map how the perimeter server is used:
  • inbound
  • outbound
  • External Authentication
Refer to Map Perimeter Servers.

Before you configure remote perimeter servers in Secure Proxy, complete the installation procedures outlined in Install a Remote Perimeter Server Overview.

Typical Installation

The following figure illustrates a typical Secure Proxy installation with perimeter servers:


Typical Secure Proxy installation with perimeter

The preceding figure shows the following:
  • The persistent connection is established from the perimeter server in the internal trusted network to Secure Proxy in the DMZ. This allows for only an outbound hole to be configured in the Firewall 2 (no inbound hole is needed with this configuration)
  • Secure Proxy has an HTTP server adapter configured for two scenarios, one secure HTTP (HTTPS) and the other non-secure HTTP.
  • Two trading partners with separate host and port numbers are configured to communicate with Secure Proxy.

A perimeter server and all adapters that communicate with the local perimeter server must be configured on the same Secure Proxy engine. An engine can have more then one perimeter server but a perimeter server can be used by only one engine.You can configure a perimeter server for one trading partner with large files and low transaction volume, and another perimeter server on the same engine for a different trading partner with smaller files and high transaction volume. By configuring each perimeter server according to the trading partner, you increase Secure Proxy performance.

Sample Remote Perimeter Server Configurations

Use remote perimeter servers with Secure Proxy if you want to:
  • Eliminate an inbound hole in your firewall to allow connections from less secure to more secure areas.
  • Send data to your customers from the perimeter server as the originating IP address.
  • Use different network cards for inbound and outbound traffic.
  • Implement multiple DMZ scenarios. You can use perimeter servers in your outer DMZ with Secure Proxy in the internal DMZ.
You have flexible deployment options for using perimeter servers with Secure Proxy: from a simple IP break to no inbound holes in the firewall. Following are sample deployment options:
  • Deployment Option Example—Two Remote Perimeter Servers on a Computer with Two NIC Cards
  • Deployment Option Example—From More Secure to Less Secure
  • Deployment Option Example—From Less Secure to More Secure
  • Deployment Option Example —External Authentication Perimeter Server