Skip to content

File Relay vs. Encryption

When a Front-end server in the DMZ relays file requests to a Front-end server on the internal network, the traffic between the Base Agent and the servers stays protected all the way.

In this example, Base Agent 2 communicates with Frontend server 2 in the DMZ. Frontend server 2 has no access to a management server, so it relays all file requests to Frontend server 1 on the inside of the DMZ. See Relaying files.

Diagram: Base Agent 2 connects to Frontend server 2 in the DMZ, which relays file requests through the internal firewall to Frontend server 1 on the internal network

  • Every request from the Base Agent is authenticated by the Front-end server that handles it. A request can’t be reused.
  • When Frontend server 2 relays a file request, Frontend server 1 authenticates the request again, as if it came directly from the Base Agent.
  • File contents are encrypted between the Base Agent and Frontend server 1. Frontend server 2 passes the data on without decrypting it.