> For the complete documentation index, see [llms.txt](https://docs.parallels.com/landing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.parallels.com/landing/ras-reference-architecture/v19/deployment-scenarios/parallels-ras-deployment-scenarios/high-availability-with-single-hop-or-double-hop-dmz/single-hop-dmz-two-firewalls.md).

# Single-hop DMZ (two firewalls)

In a single-hop DMZ scenario, the firewall system must be capable of routing connections properly from RAS Secure Gateways to RAS Connection Brokers. The firewall system is also responsible for connections from the Internet to the virtual IP address of a HALB Virtual Server (HALB VS) representing HALB virtual appliance(s) or other generic protocol load balancing scenarios. Note that in this case two HALB Virtual Servers are used for internal and external traffic load balancing to internal Secure Gateways.

<figure><img src="https://1694883226-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkldliYhYd3ruhOnSCITd%2Fuploads%2FrlGkNz72CmClMsPiC5lC%2Fsolutionsguide12.png?alt=media&amp;token=d4a12864-0059-4141-be23-916f1232689a" alt=""><figcaption></figcaption></figure>

To differentiate traffic between internal and external network, you can use public and private Secure Gateways (both are equal from the RAS perspective):

<figure><img src="https://1694883226-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FkldliYhYd3ruhOnSCITd%2Fuploads%2FxiA04PDdnkIBrLm2wO8i%2Fsingle-hopdmz(twofirewalls)2.png?alt=media&amp;token=d29751bf-af87-498f-9a23-43a3ec5e9828" alt=""><figcaption></figcaption></figure>

In a configuration of this type, HALB appliances installed in front of RAS Secure Gateways in the internal perimeter network (DMZ). The WAN users connect to the IP address of external HALBS VS, while LAN users use IP address of the internal HALB VS, which use HALB appliances installed in front of the Secure Gateways located in internal network. The Parallels Client settings can be configured either centrally (via Client Policy in the Parallels RAS console) or locally on a device where Parallels Client is running. To add high availability for HALB VS, the second appliance can be deployed for external internal and HALB VS.

## **Installation Notes**

RAS Connection Broker is installed using the Parallels RAS installer (standard installation).

HALB is installed as a ready-to-use virtual appliance and configured in HALB VS properties.

All other components are push-installed from the RAS console.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.parallels.com/landing/ras-reference-architecture/v19/deployment-scenarios/parallels-ras-deployment-scenarios/high-availability-with-single-hop-or-double-hop-dmz/single-hop-dmz-two-firewalls.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
