Collocating DMZ Roles with Internal Roles

It would be normal for Edge Servers and reverse proxies to be on a dedicated DMZ host. This is because the Edge Server is designed to sit in a perimeter network surrounded by firewalls on both sides.

In reality, some smaller organizations will probably deploy Edge Servers on the same host as other virtual machines. With the capability to tag individual virtual machine adapters with a specific VLAN, the perimeter network traffic can be directed to only the adapters assigned to Edge Servers. Of course, this means the perimeter network traffic passes through the host hypervisor at some level. Of course, the proper firewall rules should be in place to protect both the host and the guest operating systems. However, it continues to be best practice to have a dedicated DMZ host or hosts.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset