Skip to main content
Solved

best practice for the publisher implementation behind the FW

  • February 19, 2024
  • 2 replies
  • 501 views

Where is the recommanded location (DMZ or Server zone) to implement the publisher in the firewall protected environment? All the port need to be opened to the back-end servers on the firewall?

is the traffice flow is correct?

End-users → tunnel  →  publisher -->(open all required ports on the FW ) → App servers

Best answer by rpastorino

Hi, it’s more End user → gw/stitcher ← publisher → |eventual firewall| → application
(publisher traffic to Netskope cloud is only outbound)
So its correct to open traffic from publisher to internal zone only to the ip and ports needed to access published application. We did a specific zone in our fw dedicated to the publishers.

 

This topic has been closed for replies.

2 replies

rpastorino
Netskope Partner
  • Answer
  • February 20, 2024

Hi, it’s more End user → gw/stitcher ← publisher → |eventual firewall| → application
(publisher traffic to Netskope cloud is only outbound)
So its correct to open traffic from publisher to internal zone only to the ip and ports needed to access published application. We did a specific zone in our fw dedicated to the publishers.

 


  • Author
  • New Member
  • February 21, 2024

Hi, it’s more End user → gw/stitcher ← publisher → |eventual firewall| → application
(publisher traffic to Netskope cloud is only outbound)
So its correct to open traffic from publisher to internal zone only to the ip and ports needed to access published application. We did a specific zone in our fw dedicated to the publishers.

 

Thank for the explaination. May I know the ports that were required from end users and publisher to the Netskope cloud? 443 only?