![]() |
#1 |
Участник
|
Microsoft Dynamics CRM Team Blog: How to Deploy Microsoft Dynamics CRM and SharePoint in Security Zones
Источник: http://blogs.msdn.com/b/crm/archive/...ity-zones.aspx
============== Begin by considering what the customer wants to achieve from the perspective of security/risk versus cost/complexity. Fewer zones means fewer firewalls, less configuration, lower costs, and so on, while not necessarily leading to a lower level of security, primarily on the lower layers (OS, and so on). Analyze the “zones” defined by network segments between two firewalls – or those that are directly connected to a leg of a three-way firewall. A zone with Internet- or extranet-facing servers is often referred to a de-militarized zone, or DMZ. Note that if there are no components in between two firewalls, there normally is no zone serving as an efficient additional layer of defense; two firewalls connected directly do not create a zone that provides a good defense-in-depth strategy. In this case, each zone only complements the missing features of the associated zone, such that one may be a reverse-proxy while the other performs address/port filtering. In these types of scenarios, consider if the layout of zones and use of firewalls provides optional security and manageability; a high number of firewalls itself will not necessarily improve security but certainly add complexity. Unless there are very special reasons to maintain four separate DMZs, create additional barriers rather than building parallel zones:
For the best division of zones, put as few components as possible in Zones 1 and 2:
access to SQL on port 1433. A summary of this information is presented in the following table. Option: With UAG/TMG/similar Direct to front-end Notes Zone 1 UAG/TMG/similar SSL termination and AuthN Zone 2 CRM Front-end CRM Front-end Need access to CRM DB Zone 3 CRM Back-end CRM Back-end Zone 3 or “4” if desired CRM DB + AD + … CRM DB + AD + … Bernt Bisgaard Caspersen Dynamics Solutions Architect | Microsoft Center of Excellence Источник: http://blogs.msdn.com/b/crm/archive/...ity-zones.aspx
__________________
Расскажите о новых и интересных блогах по Microsoft Dynamics, напишите личное сообщение администратору. |
|
|
|