TMS zl Module Planning and Implementation Guide 2009-08

Table Of Contents
Page 27
7.2.3 VPN Gateway
The TMS zl Module is shown in Figure 8 performing as a site-to-site VPN
Gateway for a strategic business partner, providing an additional layer of
security to an extranet connection. The perimeter firewall is simply a pass-
through point in the VPN tunnel’s path. Any NAT performed by the perimeter
firewall is dealt with through the use of the standard NAT Traversal (NAT-T)
option.
Note: Terminating the tunnel directly in the data center reduces the
partner’s access to the remainder of the enterprise network and also
protects the traffic from potential eavesdropping in the remainder of the
enterprise network, e.g. highly sensitive research and development
activities, activities potentially subject to industrial espionage, etc.
Figure 8: Data Center Security Control Point Extranet VPN
Figure 9 below illustrates another common data center VPN scenario :
Figure 9: Data Center Security Control Point Internal VPN