![GlobalSCAPE DMZ Gateway v3.1 Скачать руководство пользователя страница 6](http://html1.mh-extra.com/html/globalscape/dmz-gateway-v3-1/dmz-gateway-v3-1_user-manual_2233736006.webp)
DMZ Gateway User Guide
6
Technical Details
The DMZ Gateway routes all client data to the server over the server-initiated socket without any
translation or modification to the packet’s payload. Thus, if the client is using HTTPS, then HTTPS traffic
goes over that streaming connection. Unlike a network hardware bridge/router device, the DMZ Gateway
does not "pass through" modified packets. The DMZ Gateway reads in a buffer full of data from the client
TCP/IP stream (~4KB) and then sends that data over the server's TCP/IP socket. They are completely
different TCP/IP packets with different source and destination locations; however, the payload is NOT
changed at all.
The DMZ Gateway does not forward client requests. The Peer Notification Channel (PNC) is used for
brokering new incoming client connections using the process outlined above. Once the incoming client
connection and the server connection are "glued" together, the client’s requests are streamed through the
DMZ Gateway to the server.
Both external (DMZ Gateway cloud facing) and internal (server-network facing) listening ports are
specified from within the server for each supported (and enabled) protocol. These ports can be the same
or different (even for the same protocol).
Once configured to work with the DMZ Gateway, the server (when running) will always attempt to initiate,
maintain, and if necessary reconnect to the DMZ Gateway server. No further administrative action is
required in the server to establish or maintain communications after the initial setup. From the DMZ
Gateway server perspective, if the PNC channel is broken, it will refuse new (and existing) client
connections until the server re-establishes a connection.
The server periodically queries the DMZ Gateway. If a reply is not received within 10 seconds, the server
considers the connection lost, severs the current connection, and then attempts to reconnect. The DMZ
Gateway also maintains its own awareness (ping/pong) of whether the server is connected. Every 30
seconds, DMZ Gateway determines whether it has received a pong message from the server since the
last ping. If it has, it will ping again; if not, it drops the connection. This allows it to free up ports if the
server is not available (no longer responds to ping) and for error reporting. (Refer to the Knowledge Base
article "
How do EFT Server and DMZ Gateway Server communicate with each other?
" for information
about changing these defaults in EFT Server 6.2 and later and DMZ Gateway 3.0 and later.)
DMZ Gateway performs client impersonation, which means none of the sockets created via the DMZ
Gateway have the DMZ Gateway IP address and port; instead, all sockets created through the DMZ
Gateway have the IP address and port of the client connection. This results in the server’s logs showing
the actual connecting client IP addresses and ports, rather than those of the DMZ Gateway.
Because the client connection is streamed through the DMZ Gateway to the server, user authentication is
handled by the server, as if the client were logging in directly to the server from the internal network.
With EFT Server, the DMZ Gateway can restrict incoming server PNC connections based upon IP
address. The DMZ Gateway can also restrict incoming client connections via the IP address ban feature.
Any IP addresses banned (manually or automatically) in EFT Server will also be banned by the DMZ
Gateway.
The server and DMZ Gateway PNC connection does not employ username and password credentials.
There is nothing sensitive contained in the PNC notifications that requires encryption.
Содержание DMZ Gateway v3.1
Страница 1: ...GlobalSCAPE DMZ Gateway v3 1 User Guide Module for EFT Server 6 3 ...
Страница 8: ...DMZ Gateway User Guide 8 ...
Страница 9: ...What s New in DMZ Gateway 9 ...
Страница 10: ...DMZ Gateway User Guide 10 ...
Страница 11: ...What s New in DMZ Gateway 11 ...
Страница 58: ...DMZ Gateway User Guide 58 ...
Страница 60: ...DMZ Gateway User Guide 60 ...