Design Pattern for external access Version 2

1
External Access Management F5 Big-IP Internal Virtual Server Linux Oracle OHS Reverse Proxy Web Server Access Policy Central Login F5 Big-IP External Virtual Server Internal DNS/VIP Oracle Access Manager DMZ Subnet Application Identity Data Store Role Based Access Control Person Federation Service (Oracle Webgate) Session Policy 15 minutes idle limit External DNS/VIP External Facing Firewall Protected Access Point SSO SSO If login is required Internal Facing Firewall Person Internal Subnet Protected Access Point Internal Access Token External Access Token Internal Facing Firewall Authorization Process If token present then allow SSO or send to IdP Login

Transcript of Design Pattern for external access Version 2

Page 1: Design Pattern for external access Version 2

External Access ManagementF5 Big-IP Internal Virtual Server

Linux Oracle OHS Reverse Proxy

Web ServerAccess Policy

Central Login

F5 Big-IP External Virtual Server

Internal DNS/VIP

Oracle Access

Manager

DMZ Subnet

ApplicationIdentity Data Store

Role Based Access Control

Person

Federation Service (Oracle Webgate)

Session Policy15 minutes idle limit

External DNS/VIP External Facing

Firewall

Protected Access Point

SSO

SSO

If login is required

Internal Facing

Firewall

Person

Internal Subnet

Protected Access Point

Internal Access Token

External Access Token

Internal Facing

Firewall

Authorization Process

If token present then allow SSO or send to IdP Login