178 IBM Tivoli Remote C ontrol Across Firewalls
Just as multiple Gateways can connect to a single Gateway and multiple
Gateways to a single Tivoli server, multiples Endpoints can connect to a single
Gateway Proxy and multiple Gateway proxies can connect to a single Endpoint
Proxy. And the communication between these Tivoli components is based on a
Tivoli Proprietary protocol over TCP/IP.
Tivoli environments with multiple firewalls
In this scenario, although Gateway Proxy and Endpoint Proxy continue to
communicate with Endpoint and Gateway respectively, they no longer
communicate directly across multiple firewalls. Instead, TFST provides Relays,
which are installed between the layers of firewall in DMZs. These Relays pass on
the information from each other and finally to/from the Endpoint Proxy and the
Gateway Proxy. FigureA-2 shows an example of this configuration.
Figure A-2 Relay connecting Endpoint and Gateway proxies through a DMZ
Endpoint
Gateway
Firewall
less secure
Endpoint Proxy
Gateway Proxy
Endpoint
Endpoint
more secure
Firewall
DMZ
Relay