IBM Tivoli and Cisco manual Middleware and application infrastructure, Dmz

Models: Tivoli and Cisco

1 516
Download 516 pages 58.69 Kb
Page 104
Image 104

The diagram in Figure 4-4provides a high-level graphical overview of the existing ABBC security infrastructure. We see that ABBC is using the IBM Tivoli Access Manager best-practice deployment methodology by incorporating dual multiple firewalls to secure the core network from external and internal users.

Mobile

Devices

Internet Browser

Business Partners

Customers

Temporary

Users

Public (Guest)

External Networks

Firewall

Wireless

Gateway

Firewall

WebSEAL

(External

users)

Internet

DMZ

Tivoli Access

WebSEAL

 

Manager

(intranet

 

Policy Server

users)

Browser

 

 

*Also connected to

InternalLDAP

Application

Server

LDAP

 

 

 

 

Directory

Middleware

 

 

 

 

Server

 

 

 

 

(MQ Integrator)

 

Firewall

Corporate

 

 

Tivoli Security

 

 

 

 

 

 

Users

 

 

Compliance

 

 

External

 

Manager

 

 

 

Server

 

 

Application

 

 

 

 

 

 

 

Server

 

 

 

*Authorized

 

 

 

 

VPN Users are

 

 

 

 

logically

 

 

 

 

included here

Clearing

 

 

 

as well.

CRM

 

 

 

System

 

 

 

 

 

 

 

 

 

Backend

 

 

Statement

Account

database

 

 

System

System

 

 

 

Internal Production Network (core)

 

Intranet

Figure 4-4 Armando Banking Brothers Company security and middlware infrastructure

Also note that in this diagram no distinction is made between the type of Internet users; in other words, local wired and wireless workstations, authorized remote access VPN sessions, and branch office connections are all considered part of the intranet and must pass through the internal firewall to access the secured applications.

We also see the Security Compliance Manager server in the core network.

4.2.4 Middleware and application infrastructure

In addition to illustrating the existing security infrastructure, Figure 4-4provides a

bit of data about the ABBC middleware and application infrastructure. Noting the external application server, we must understand that this one block represents a

86Building a Network Access Control Solution with IBM Tivoli and Cisco Systems

Page 104
Image 104
IBM Tivoli and Cisco manual Middleware and application infrastructure, Dmz