Tavve zoneranger User Manual page 29

Table of Contents

Advertisement

Figure 8-4. RGVI Architecture
The RGVI Client is configured with the addresses of one or more Ranger Gateway servers to which it
can connect in order to provide proxy services. When the RGVI client is initialized on the Management
Application Server, it creates a virtual point-to-point interface which is used to intercept traffic destined
for managed devices, similar to the approach used for GVI, then attempts to connect to one of the
configured Ranger Gateway servers. When the connection to a Ranger Gateway server is established,
the Ranger Gateway will send the RGVI client a list of individual IP addresses and subnets that the
RGVI client should intercept. On receipt of this list, the RGVI client will configure corresponding static
routes on the management application server so that traffic destined for devices located in firewall-
partitioned networks is routed to its associated virtual interface (1). The RGVI client, as the
creator/owner of the virtual interface, receives all traffic that is routed to the virtual interface (2), then
relays this traffic to the Ranger Gateway server to which it has connected (3)(4). Within the Ranger
Gateway, this traffic is received by the RGVI service which consults with the Proxy Access Control
service in the Ranger Gateway to determine if the traffic should be allowed, and to identify the protocol-
specific proxy service (e.g. SNMP proxy, TCP proxy) that should handle the traffic. If the request is
allowed, the RGVI service forwards the traffic to the selected proxy service (5). The proxy service
consults the Proxy Map service in the Ranger Gateway in order to identify identify a ZoneRanger that is
able to relay the traffic to the target device, and to translate the target address, if necessary, and then
forwards the traffic to the selected ZoneRanger (6), which in turn, forwards the traffic to the target DMZ
device (7). As in the case of GVI, where applicable, proxy services may also perform validation and
filtering of the management traffic, as appropriate for the service being used.
The RGVI mechanism allows a single Ranger Gateway server to support multiple management
application servers, as illustrated in the following figure.
ZoneRanger 5.5 User's Guide
29

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents