« Phishing looks to FTP to distribute malware | Main | Updates to Email Factory for .NET and Secure iNet Factory »

March 28, 2008

DMZ File Transfer Streaming

With regulations such as PCI DSS, Sarbanes-Oxley and HIPAA in effect many companies are now required to put measures in place to ensure that no sensitive data is stored in the DMZ (de-militarized zone).  However, for those businesses who need to provide outside users access to this data, whether it be employees working remotely or trading partners, this poses an interesting problem.  How do you make data available in the DMZ without storing that data in the DMZ?  The answer is DMZ file transfer streaming.

DMZ file transfer streaming is accomplished by using a feature in JSCAPE Secure FTP Server known as a Resource. A Resource provides a way to create a virtual directory at the user or group level and map it to the account of a remote FTP/S, SFTP or WebDAV server.   

In order to setup DMZ streaming an instance of JSCAPE Secure FTP Server is installed in the DMZ.  A Resource is then created in JSCAPE Secure FTP Server that is mapped to an account on any FTP/S, SFTP or WebDAV server located behind the firewall.  A virtual directory is then created at the user or group level that maps to the Resource created earlier.

DMZ File Transfer Streaming

When a user uploads a file it is streamed from client to server in DMZ to server behind firewall.  Similarly when a client attempts to download a file it is streamed from server behind firewall to server in DMZ to client.  This process is completely transparent to the user.  Using DMZ streaming ensures that no data is stored in the DMZ allowing companies to meet compliance requirements while still providing external users access to data.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/2925084/27547748

Listed below are links to weblogs that reference DMZ File Transfer Streaming:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Can you explain the licensing requirements for this setup?

Re: Can you explain the licensing requirements for this setup?

Yes. This depends on whether the Resource target is also an JSCAPE Secure FTP Server service, or is a service run by some other file transfer server. In the event that target Resource is a JSCAPE Secure FTP Server service then a minimum of 2 licenses would be needed, 1 for the JSCAPE Secure FTP Server running in DMZ and a 2nd for the JSCAPE Secure FTP Server running behind firewall. If Resource target is not a JSCAPE Secure FTP Server service then only 1 license would be needed.

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In