Appendix A. Tivoli Firewall Security Toolbox overview  187
Effective Utilization of TFST across firewallsThe following key points of TFST provide minimum filter rules on the firewall and 
securely and efficiently configure Tivoli Management Framework across 
firewalls:
Select the Endpoint Proxy to the Relay or Gateway Proxy as unidirectional to 
permit connections initiated by only one machine.
Select the Relay connect to the parent Relay or Endpoint Proxy as 
unidirectional to permit connections initiated by only one machine.
Select the Relay connect to the child Relay or Gateway Proxy as bidirectional 
to permit connections initiated by either machine.
Select the Gateway Proxy connect to the Relay or Gateway Proxy as 
bidirectional to permit connections initiated by either machine.