
82 IBM Tivoli Remote Control Across Firewalls
We should also point out that a Tivoli Endpoint Gateway was already deployed 
before the Tivoli Firewall Security Toolbox technology had been announced, in 
order to manage the Endpoints in the Servers zone.
Figure 2-3 depicts the current CSI Corporation Tivoli environment prior to the 
IBM Tivoli Remote Control Proxy solution deployment. The External zone 
represents the site where the first and second level support location. The DMZ, 
Internal, and Servers zones are all located at CSI’s main site.
Figure 2-3   Case study scenario without RC Proxy architecture
Based on Figure 2-3, there can be several ways to implement A Remote Control 
solution for CSI. The following sections present two possible implementation 
planning as follows:
Using a combination of Standalone and Non-Standalone solutions
Using Non-Standalone mode solution only
Endpoint A Enpoint D
TMR Server
DMZ
Gateway Proxy Endpoint Proxy
External
Firewall 2 Firewall 3Firewall 1
Relay 1 TFST
Endpoint GW
Endpoint GW
Endpoint GW
Servers
Internal
Endpoint  B
Endpoint C