2.5

Table Of Contents
VMware, Inc. 23
Chapter 2 Planning an ACE Management Server Deployment
ACEManagementServercanbedeployedwiththefollowingHTTPSproxysolutions:
ApacheProxyUsingmod_proxy
ZeusTechnologyLoadBalancerAcommerciallyavailableloadbalancerand
trafficmanagementsolution
AvoidthefollowingproblemswhenyouuseaproxyfortrafficintoanACE
ManagementServer:
SSLTerminationIfyourHTTPSproxyterminatestheSSLconnection,youmust
usethesameSSLkeyandcertificateontheHTTPSproxyserverandACE
ManagementServer.Or,usetheACEManagementServercertificatechainto
embedtheHTTPSproxycertificateverificationchainintheACEpackage.
Anexample
ofaproxyserverthatterminatesSSLconnectionsisApacheProxy.
TheZeusloadbalancingproductssupportSSLpassthrough,whichmeansthatthe
SSLconnectionisterminatedatACEManagementServer.
MultipleACEManagementServerSSLcertificatesIfyouaredeploying
multipleACEManagementServerinstancesbehindaloadbalancingsolution,all
ACEManagementServerinstancesmustusethesameSSLkeyandcertificatepair.
YoucanalsousetheACEManagementServercertificatechainfeaturetoembed
everySSLcertificate
verificationchainintotheACEpackage.
DNSresolutionWhenyoucreateanACEenabledvirtualmachine,youmust
specifyahostnameforACEManagementServer.Thishostnamemustresolveto
theappropriateIPaddressforbothinternalandexternalclients.Internally,itcan
resolvetoACEManagementServeritself.Externally,itcanresolveto
theHTTPS
proxyserver.
BecausethetrafficcomingintoACEManagementServerisplainHTTPStrafficandthe
serverisstateless,youcandeploymanyotherconfigurationstoprovideexternalaccess
toanACEManagementServer.Whenyoudesignyourdeployment,thinkofACE
ManagementServerasaWebserverwith
securetraffic.