|
Customers share the services lodged in this zone.
These are:
Backup
Oracle.
Shared data base access
Shared
disk. Access to network disk
NTP.
Time synchronization
Two Web networks (backend) connect these services
with the client's server.
The center provides the connection ports. The result
is that the client connects to Internet by one zone, and by another
zone accesses data services. Thus, traffic and security are separated.
There are two aspects are of special consideration
in the data zone network:
Traffic volume: this network should be able to bear a great volume of traffic, due to its within shared disk. Many servers will access to disk by NFS, or CIFS, etc. protocols. For that reason, a firewall between the clients and the service's network in not included.
Security: all clients are connected to the same data network. To avoid that the clients could be connected among themselves throughout this network, is it unacceptable. A logical router is created (implemented in the own CISCO WS-C6509 switches) that establishes connections (routes) one to one between clients and services, and therefore impeding the connection in between customers.
|