« Getting Hitched | Main | Blackle - Saving Power »

Securing DMZ Application

In this article i would like to discuss in brief about DMZ Implementations. Many times Customers have a requirement to setup DMZ Environment for Externally Visible Applications such as iStore, iRecruitment etc...but the next question they have is can they share the File System (i.e. appltop, comntop, iAS/806) with the external DMZ Server. Technically sharing the file system between the Internal Server and External Server is possible but it defeats the whole purpose of Setting up the DMZ Server, here is the explanation

             ||                            ||

Internet  || External Web Tier   || Internal Web Tier/Database Tier

             ||                            ||

            FW1                         FW2

If you share an appltop/comntop between External and Internal Server you are violating the concept of DMZ. A hacker playing with External Filesystem is also playing with your Internal Filesystem making your second Firewall useless.

It is also documented in Metalink Note 287176.1, However if you are having one or more servers inside the DMZ then you can Implement Shared Appltop among all the External Middle Tiers.

DMZ:

TrackBack

TrackBack URL for this entry:
http://blogs.oracle.com/mte1521/mt-tb.cgi/534

Comments (3)

Hi Murali,

Can we use the same external server for different product like irecruitment and isupplier and with different domain name...

Thanks,
Kalpit

Murali:

Yes, Refer to 217368.1 "Virtual Servers and Port Configuration"

Murali:

Yes, Refer to 217368.1 "Virtual Servers and Port Configuration"

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About This Entry

This page contains a single entry from the blog posted on June 14, 2007 2:35 PM.

The previous post in this blog was Getting Hitched.

The next post in this blog is Blackle - Saving Power.

Many more can be found on the main index page or by looking through the archives.

Top Tags

Powered by
Movable Type and Oracle