External Web Tier Configuration in DMZ - Security Concerns
Hi,
We're following note ID - 380490.1 for doing the DMZ configuration. We're following up Option 2.2: Using Separate Oracle E-Business Suite Release 12 Web Tiers as described in figure 4. Please refer the attached document.
The client has following concerns:
1. The external web tier will talk to DB directly? Does this mean a known security threat to the application? Of course this is certified by Oracle. However, we would like to know what kind of exposure the DB would have since it's talking to external web server directly.
2. If we have to follow Option 2.4: Using Reverse Proxy with no External Web Tier (Figure 9), would it require any additional software or license? Kindly advise.