Designing SRA Deployment Scenarios
Netlet and Rewriter Proxies on Separate Nodes
To reduce the load on the Portal Server node and still provide the same level of security at increased performance, you can install Netlet and Rewriter Proxies on separate nodes. This deployment has an added advantage in that you can use a proxy and shield the Portal Server from the DMZ. The node that runs these proxies needs to be directly accessible from the DMZ.
Figure 5-15 shows the Netlet Proxy and Rewriter Proxy on separate nodes. Traffic from the Gateway is directed to the separate node, which in turn directs the traffic through the proxies and to the required intranet hosts.
You can have multiple instances or installations of Netlet and Rewriter Proxies. You can configure each Gateway to try to contact various instances of the proxies in a round robin manner depending on availability.
Figure
Client
NetFile
Netlet
Client
NetFile
Netlet
Proxies on Separate Nodes
Gateway
Gateway
HTTP traffic
Netlet traffic
Rewriter
Proxy
Netlet
Proxy
Portal ServerPortal
Host
Host
Host