The Community is now in read-only mode to prepare for the launch of the new Flexera Community. During this time, you will be unable to register, log in, or access customer resources. Click here for more information.
‎May 21, 2019 07:41 AM
If I'm understanding your scenario right, I understand that a beacon in the secured LAN area would be able to initiate a connection in to the normal LAN area where the admin server is. In this case you should be fine: a parent admin server/beacon (in the normal LAN area) does not have any need to initiate any network connections to child beacons (in the secured LAN area).
‎May 22, 2019 01:34 AM
Hi,
Sorry to jump in your topic, but I'm in the same situation, I have some secured LAN where the communication is allowed only from Secure LAN -> Normal LAN where the admin servers are. I was thinking to implement a ZTI solution using only the core of the agent, and scripting command to upload inventory via https to a beacon in normal LAN. But this solution have some limitation, like the agent will be unmanaged, and no automatic update of the agent will take place with the new version update. My question to @ChrisG is: do the normal agent (I mean the one that is managed by admin servers) need both way communication or only from secure LAN -> normal LAN is allowed?
‎May 22, 2019 01:53 AM
Communication during regular agent and beacon operations is always one way, from "child" (agent or beacon) to "parent" (beacon):
@adrian_ritz - in your scenario, you could have:
There is nothing in the scenario you have described that would require or benefit from the use of a ZTI approach.
‎May 22, 2019 02:29 AM
Hi Chris,
Thank you for your quick reply, will take this info to security team.
‎May 22, 2019 02:36 AM
If it was the other way around and the child beacon could not talk to its parent beacon, I think all communication is file based. What I could imagine:
‎May 22, 2019 06:31 AM
‎May 22, 2019 06:55 AM
I have multiple different variations of this type of configuration.
Send me a direct message since most security departments get nervous about the specifics of how to move in and out of a secure DMZ.
‎May 23, 2019 09:51 AM