Backup across firewall

AndyRH

ADSM.ORG Senior Member
Joined
Oct 23, 2002
Messages
301
Reaction score
1
Points
0
Location
Ft. Worth
Website
Visit site
We need to backup several servers in a DMZ. We will begin testing ideas tomorrow. What we have in mind are:

0. Allow incoming TSM port from the DMZ servers. (This goes with all other solutions)

1. NAT all DMZ servers to 1 internal address. Possible problem if two jobs run at one time.

2. Add route statements to TSM server. Might allow TSM to work normally.

3. NAT each DMZ server with a unique internal address. We are very short on addresses.



Does anyone else have any ideas or experience?



Andy
 
Well, 0, 3 sounds most logical, you can if the DMZ machines are Win machines also choose to encrypt the data it passes to the TSM server. The big advantage in any way you do it is that you only need to open 1 port.
 
After our testing, we went with Option #1 (you have to do #0). We have two clients setup using 1 internal address through the magic of NAT. We ran the two backups simultaneously without any problems, we also did simultaneous restores.

Since #1 was our preferred solution, we did not test the others.



Andy
 
Back
Top