> For the complete documentation index, see [llms.txt](https://docs.parallels.com/landing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.parallels.com/landing/ras-reference-architecture/deployment-scenarios/parallels-ras-deployment-scenarios/high-availability-with-single-hop-or-double-hop-dmz/double-hop-dmz-three-firewalls.md).

# Double-hop DMZ (three firewalls)

In a double-hop DMZ scenario, settings are simpler and the protection from external malicious agents is higher. Double-hop DMZ requires Forwarding RAS Secure Gateways installed in the perimeter network to pass client connections to RAS Secure Gateways residing in the internal second perimeter network (the second hop).

In such configuration, the HALB VS with a HALB pair (primary and secondary) is installed in front of Forwarding RAS Secure Gateways in DMZ. WAN users connect to Parallels RAS using the IP address of the HALB VS, while LAN users use IP address of the internal HALB VS, which use HALB appliance installed in front of the gateways located in internal network. Parallels RAS connection properties can be configured either centrally (using Client Policy in the RAS Console) or manually in Parallels Client.

Forwarding RAS Secure Gateways forward network traffic using the **Forward requests to next RAS Secure Gateway in chain** option in the **Advanced** tab of the **Forwarding RAS Secure Gateway** properties.

<figure><img src="https://content.gitbook.com/content/jRndoUJVjRrmCN0WR7H6/blobs/uwGqHEG3mALxsrOcJPKq/securesetupwithdouble-hopdmzandsecond-levelauthentication.png" alt=""><figcaption></figcaption></figure>

Parallels recommends using Forwarding RAS Secure Gateways in double hop DMZ deployments only.

To differentiate traffic between internal and external network, you can use public and private gateways (both are equal from the RAS perspective):

<figure><img src="https://content.gitbook.com/content/jRndoUJVjRrmCN0WR7H6/blobs/1uQk4kMZGEmby2lIguAI/double-hopdmz(threefirewalls)2.png" alt=""><figcaption></figcaption></figure>

## **Installation Notes**

RAS Connection Broker is installed using the Parallels RAS installer (standard installation).

HALB is installed as a ready-to-use virtual appliance and configured in HALB VS properties.

All other components are push-installed from the RAS console.

If the Forwarding RAS Secure Gateway cannot be push-installed for any reason, you can run the Parallels RAS installer on the target server. When doing so, select **Custom** installation type and then choose the **RAS Secure Gateway** component.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.parallels.com/landing/ras-reference-architecture/deployment-scenarios/parallels-ras-deployment-scenarios/high-availability-with-single-hop-or-double-hop-dmz/double-hop-dmz-three-firewalls.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
