
1 — Overview
Alcatel-Lucent OmniAccess 8550 WSG Installation Guide, Release 2.0
1-3
September 2007
3HE03334AAAATQZZA Edition 02
Virtualized internal services for external consumption
Figure
1-1
shows the 8550 WSG in the Enterprise1 network deployed
for virtualized internal web service for external users and partners.
The 8550 WSG processes and transforms web service requests and
responses. To the right of the 8550 WSG, the partner and external user
client applications are shown addressing web service requests to the
8550 WSG. The 8550 WSG forwards the requests to the actual web
services, shown to the left of the 8550 WSG. The 8550 WSG is located
within the DMZ with the services on the internal network and clients
in the Internet domain.
For external partners and individual users to consume services
virtualized by the 8550 WSG, the following firewall configuration is
necessary at Enterprise1:
•
The external firewall must be configured to permit inbound web
sessions to the 8550 WSG data port(s).
•
The internal firewall must be configured to permit inbound web
connections from the 8550 WSG to the WS App1 and WS App2.
Web service clients at partner sites and individual external users
access the virtualized web services at the 8550 WSG. This
configuration allows a single point in the network to enforce
Authentication and Authorization policy to all services used by
external users.
Note 1 —
The location of the 8550 WSG relative to the DMZ varies
by deployment scenario.
Note 2 —
Firewall settings dictate the flow of data to and from
Enterprise sites, as well as from where the 8550 WSG management
interface can be accessed. The scenarios in this section describe the
firewall configuration requirements.
Note 3 —
See section
3.6
for the typical network connections
required for these deployments.