Dear all, We have the following problem. There is an Appian infrastru

Dear all,

We have the following problem. There is an Appian infrastructure that is already installed and users of an organization have access to (green). In this infrastructure we already have some Appian applications deployed (green). We want to develop a new Appian Application (orange), and give access to that application to external (and internal) users. One solution we thought would be to setup a new infrastructure (red) that includes an HTTP server and an Appian AS (running tempo) and to put this in different zones in our network configuration. This will ensure that we will only open up Tempo to external users.
Using access right configuration on Tempo we can make sure that the new external users will be able to only access the new application we will develop. The problem is that (in this way) we also allow internal users to access this application (and other applications) externally. If the internal users use their internal credentials to ac...

OriginalPostID-172560

OriginalPostID-172560

  Discussion posts and replies are publicly visible

Parents
  • We have implemented the following – there is an Appian application server in DMZ and one internal and one external web servers. Appian is configured to use SSO authentication when users come from the internal network. In this case internal users can’t login to applications if they access Appian externally (they have to go via remote desktop). We have also implemented URL filtering so no one, even administrators, can access designer or admin functionality from the external network.
Reply
  • We have implemented the following – there is an Appian application server in DMZ and one internal and one external web servers. Appian is configured to use SSO authentication when users come from the internal network. In this case internal users can’t login to applications if they access Appian externally (they have to go via remote desktop). We have also implemented URL filtering so no one, even administrators, can access designer or admin functionality from the external network.
Children
No Data