HOME LITERATURE TechNotes
|
TechNote: ZoneRanger Allows Single eHealth® Server to Monitor DMZ Devices |
|
The ChallengeCA (Concord ) eHealth provides availability, latency and capacity planning for network devices and server. These reports are used for capacity planning and fault management. Trend reports that show where network traffic is increasing can be used to identify where network upgrades will provide the best ROI. Baseline reporting allows for easy detection of abnormal network conditions and lead to quicker fault isolation and repair. eHealth Live Health can process traps from the DMZ devices for real-time problem solving.
eHealth collects it’s data by using ICMP to verify device availability and to record network latency. SNMP is used to collect data for reporting. Many sites do not allow ICMP or SNMP access through the firewall into the DMZ. The eHealth solution is to put a remote collector into the DMZ (Distributed eHealth) and to ftp this data up to the main eHealth console. This allows eHealth to monitor DMZ devices but not in real time. This configuration requires an additional server deployed in the DMZ and Distributed eHealth software. The ZoneRanger SolutionTavve’s ZoneRanger appliance allows eHealth to transparently reach into the DMZ over a single encrypted TCP Port. ICMP and SNMP into the DMZ are sent over one port and SNMP traps to Live eHealth are sent over this same encrypted connection. This allows for one eHealth server to monitor internal and external (DMZ) devices. There are no additional servers in the DMZ to administer (operating system maintenance) or ftp data transfers to rollup. All data is collected in real-time to one central eHealth database. Device discovery is done from the main eHealth console and the discovery results easily modified for the appropriate MIB variables. Information from multiple ZoneRangers can be forwarded to a single eHealth server or multiple servers. |
|
How does ZoneRanger fit into your network?What others are saying..."Tavve has developed the ZoneRanger product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols." Tavve: ZoneRanger Subraya Mallya PrudentCloud.com "Without a more secure approach to managing the protocols and tools that manage the network - including the 'trusted' internal network - enterprises may be exposing themselves to more risk than they realize."
Scott Crawford, CISSP, ISSAP, ISSMP Senior Analyst, Enterprise Management Associates
"ZoneRanger effectively extends the reach of management applications to devices located beyond firewalls, eliminating the need for complicated firewall configurations, extensive agent deployments, or expensive application replication. ZoneRanger also provides security, acting as an application layer proxy firewall, inspecting and validating the traffic relayed between applications and devices."
Jim Doble, CISSP CTO, Tavve
|