Designing SRA Deployment Scenarios
112
Portal Server 6 2005Q1 • Deployment Planning Guide
Basic SRA Configuration
Figure 5-10 shows the most simple configuration possible for SRA. The figure
shows a client browser running NetFile and Netlet. The Gateway is installed on a
separate machine in the DMZ between two firewalls. The Portal Server is located
on a machine beyond the second firewall in the intranet. The other application
hosts that the client accesses are also located beyond the second firewall in the
intranet.
The Gateway is in the DMZ with the external port open in the firewall through
which the client browser communicates with the Gateway. In the second firewall,
for HTTP or HTTPS traffic, the Gateway can communicate directly with internal
hosts. If security policies do not permit it, use SRA proxies between the Gateway
and the internal hosts. For Netlet traffic, the connection is direct from the Gateway
to the destination host.
Without a SRA proxy, the SSL traffic is limited to the Gateway and the traffic is
unencrypted from the Gateway to the internal host (unless the internal host is
running in HTTPS mode). Any internal host to which the Gateway has to initiate a
Netlet connection should be directly accessible from DMZ. This can be a potential
security problem and hence this configuration is recommended only for the
simplest of installations.
Figure 5-10
Basic SRA Configuration
Gateway
Client
Portal
Server
Host
NetFile
Netlet
Netlet traffic
HTTP traffic
Proxylet
Summary of Contents for Portal Server 6 2005Q1
Page 8: ...8 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 10: ...10 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 12: ...12 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 20: ...Sun Welcomes Your Comments 20 Portal Server Secure Remote Access 6 2005Q1 Administration Guide...
Page 36: ...A Typical Portal Server Installation 36 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 50: ...Proxylet 50 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 78: ...SRA Sizing 78 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 132: ...Identity and Directory Structure Design 132 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 142: ...Configuration Files 142 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 152: ...Tuning Parameters for etc system 152 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 178: ...Portal Design Task List 178 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 182: ...182 Portal Server 6 2005Q1 Deployment Planning Guide...
Page 192: ...Section X 192 Portal Server 6 2005Q1 Deployment Planning Guide...