
178 IBM Tivoli Remote C ontrol Across Firewalls
Just as multiple Gateways can connect to a single Gateway and multiple 
Gateways to a single Tivoli server, multiples Endpoints can connect to a single 
Gateway Proxy and multiple Gateway proxies can connect to a single Endpoint 
Proxy. And the communication between these Tivoli components is based on a 
Tivoli Proprietary protocol over TCP/IP.
Tivoli environments with multiple firewallsIn this scenario, although Gateway Proxy and Endpoint Proxy continue to 
communicate with Endpoint and Gateway respectively, they no longer 
communicate directly across multiple firewalls. Instead, TFST provides Relays, 
which are installed between the layers of firewall in DMZs. These Relays pass on 
the information from each other and finally to/from the Endpoint Proxy and the 
Gateway Proxy. FigureA-2 shows an example of this configuration.
Figure A-2   Relay connecting Endpoint and Gateway proxies through a DMZ
Endpoint 
Gateway
Firewall
less secure
Endpoint Proxy
 Gateway Proxy
Endpoint 
Endpoint 
more secure
Firewall
DMZ
 Relay