Forum Post: RE: Best practice for deploying webservice with webserver within a DMZ

  • Thread starter Thread starter bronco
  • Start date Start date
Status
Not open for further replies.
B

bronco

Guest
I would go for the second option Michael suggests. Setup a reverse proxy in the DMZ and let that point to a machine in your LAN. This LAN machine could run the entire OE stack (ie. db, AppServer and WSA). From a security point of view it's easier to maintain because this obscures most of Tomcat (WSA), except the URL you want obviously. Moreover, you don't have to access you DMZ for deployments of your webservices. Apart from IIS & Apache I can recommend the nginx webserver for this task. It's lightweight in both footprint and at runtime (and it serves 15% of the websites worldwide, so proven technology).

Continue reading...
 
Status
Not open for further replies.
Back
Top