File Relay vs. Encryption
When a Front-end server in the DMZ relays file requests to a Front-end server on the internal network, the traffic between the Base Agent and the servers stays protected all the way.
In this example, Base Agent 2 communicates with Frontend server 2 in the DMZ. Frontend server 2 has no access to a management server, so it relays all file requests to Frontend server 1 on the inside of the DMZ. See Relaying files.

How relayed requests are protected
Section titled “How relayed requests are protected”- Every request from the Base Agent is authenticated by the Front-end server that handles it. A request can’t be reused.
- When Frontend server 2 relays a file request, Frontend server 1 authenticates the request again, as if it came directly from the Base Agent.
- File contents are encrypted between the Base Agent and Frontend server 1. Frontend server 2 passes the data on without decrypting it.
Recommendations
Section titled “Recommendations”- Use HTTPS URLs for the Front-end servers, especially for the public URL. See Use HTTPS in Backend, Frontend & OS Deployment Service.
- Make sure the redirect in the internal firewall points to the public port of Frontend server 1, not to its internal port, as described in Relaying files.