Security Enterprise Production Deployment
3 min
this deployment is based on the enterprise production deployment docid\ bhapgl 9cpnjelwecs8ll with a dmz added to provide security where users log in from outside of the company network we recommend the following dmz configurations dmz with web servers dmz with reverse proxy servers the dmz is configured for authenticated access when web servers are in the dmz, each user must enter his user name and password to log into this architecture involves the additional cost of setting up and maintaining two firewalls where you implement reverse proxy servers, you can add another layer of access authentication this architecture involves the additional cost of setting up and maintaining two reverse proxy servers and a load balancer about using a dmz with web servers this option offers a greater level of security than placing your web servers outside of a single company firewall placing a second firewall between the internet and the web servers forms a semi trusted network that prevents external access to your process servers and databases we recommend that you harden the web servers by taking the following actions disabling all unnecessary services running necessary services with the lowest possible privileges requiring strong passwords locking an account after a certain number of login failures deleting or disabling unnecessary user accounts, such as the guest user account renaming or changing the description of the administrator account installing the latest security updates and patches on the server enabling security logging and checking the logs frequently the same components are installed on the web servers when they are located in the dmz as when they are located outside of the company firewall see about installing the neurons for itsm for the enterprise production deployment docid\ bhapgl 9cpnjelwecs8ll example of an enterprise deployment with web servers in the dmz about using a dmz with reverse proxy servers this option offers the greatest level of security by placing your web servers inside the company firewall by placing reverse proxy servers in the dmz, you prevent direct user login to the web servers in addition, by locating the web servers on the same network as the process servers and databases, you achieve a true three tier architecture the same components are installed on the web servers when they are located inside the firewalls as when the servers are located outside this architecture involves the additional costs of servers to host the reverse proxy service, as well as setting up and maintaining a second firewall see about installing the neurons for itsm for the enterprise production deployment docid\ bhapgl 9cpnjelwecs8ll example of an enterprise deployment with reverse proxy servers in the dmz
