JSCAPE
  • Products
    • Managed File Transfer
    • JSCAPE SaaS
    • MFT Gateway
    • MFT Monitor
    • All Products
  • Solutions
    • All Solutions
    • Secure File Transfer
    • AS2 Server Software
    • File Synchronization
    • Reverse Proxy
    • Compliance
    • DMZ Streaming
  • Pricing
  • Company
    • Blog
    • Company
    • Contact Us
    • Clients
    • Case Studies
    • Testimonials
    • Certifications
  • Support
    • Help Desk
    • Documentation
    • Customer Downloads
Get a demo

Providing network services from an internal network while prohibiting inbound connections

Words by

John Carl Villanueva

Overview Some organizations that deal with exceptionally sensitive information need to employ very stringent access restrictions to their internal networks. While a DMZ consisting of firewalls and reverse proxies can, in most cases, meet such requirements, providing network services from the internal network to external clients while also prohibiting inbound connections can be quite challenging.…

Published in:

Blog

/

JSCAPE MFT, Reverse Proxy, Secure File Transfer

Overview

Some organizations that deal with exceptionally sensitive information need to employ very stringent access restrictions to their internal networks. While a DMZ consisting of firewalls and reverse proxies can, in most cases, meet such requirements, providing network services from the internal network to external clients while also prohibiting inbound connections can be quite challenging. This little reverse proxy enhancement can simplify things.

providing_network_services_from_an_internal_networ-1.png

A reverse proxy like JSCAPE MFT Gateway deployed in the DMZ offers a secure way of providing network services (FTP, SFTP, FTPS, HTTP, HTTPS, etc) from internal networks to external clients. With this configuration, it’s possible to just stream data straight from the internal network, through the DMZ, and right to the requesting client. No data will need to be stored in the DMZ.

DMZStreamingReverseProxy.png

Coupled with a well-planned DMZ firewall policy, this configuration will allow you to:

  1. Create a single point of access to your internal servers;
  2. Simplify access control tasks;
  3. Move user credentials to a more secure zone;
  4. Reduce risks to sensitive data;
  5. Help achieve regulatory compliance;
  6. Bring down capital and operational expenses; and
  7. Allow transparent maintenance of backend servers

For more information about these benefits, read the article Top 8 Benefits of a Reverse Proxy.

A reverse proxy like JSCAPE MFT Gateway typically listens on a public-facing network interface for incoming connections. When a valid incoming connection is received from an external client, this reverse proxy will promptly connect to the appropriate internal-network-based server in behalf of the client and then facilitate secure data exchanges between the two.

Notice that, in this configuration, the reverse proxy will still have to make an inbound connection to the internal server. To make this happen, you’ll need to open some ports on your DMZ firewall. The problem is, open ports can be exploited. You can mitigate the risks by employing complex firewall configurations but you can’t totally eliminate the vulnerability.

Achieving zero inbound connections

But is it really possible to fully restrict inbound connections while still offering network services from within? The answer is yes. One way to do this is by employing MFT Gateway Agents. First introduced in JSCAPE MFT Gateway 3.0, an MFT Gateway Agent is an optional component that you install on one or more servers within your internal network.

Its primary purpose is to perform network requests on behalf of JSCAPE MFT Gateway Server. Upon startup, an agent establishes an outbound connection to JSCAPE MFT Gateway Server via a control channel. This connection is maintained while both MFT Gateway and the agent is running. At no instance will there be an inbound connection from the reverse proxy to the agent.

mft_gateway_agent.png

When a client application connects to MFT Gateway, the reverse proxy forwards a request to the agent and instructs the agent to establish a connection between the target internal server. Once the connection is established, the agent then creates a tunnel between the internal server, the agent, MFT Gateway, and the external client. It is through this tunnel that data exchanges will be made.

mft_gateway_agent_tunnel.png

If you’re interested in trying this out, you may download a free, fully-functional evaluation edition of JSCAPE MFT Gateway and follow the installation instructions in the documentation.

Download Now

Easy To Deploy, Easy To Administer, Easy To Manage

Ready to see how JSCAPE makes managed file transfer so much simpler? Schedule your demo now.

Request a demo

Popular Articles

View more by

JSCAPE
  •  
    1–2 minutes
    23/09/2025

    JSCAPE by Redwood, version 2025.3: New UI continues to make a splash

    Dive back into JSCAPE by Redwood with version 2025.3, bringing more modern UI updates to make using and navigating JSCAPE more intuitive. 

    Read article

  •  
    1–2 minutes
    19/08/2025

    Weathering the economic storm: Expert support is your enterprise file transfer system’s lifeline

    The global economic landscape can be described by one word: “uncertain”. Lingering effects from the 2020 pandemic, combined with new waves of international tariffs throughout 2025, have…

    Read article

  •  
    1–2 minutes
    30/07/2025

    Escape the grip: Why flexible MFT is key to enterprise agility

    Break free from costly vendor lock-in Let’s be blunt: some MFT vendors have built product suites that are less about true partnership and more about proprietary siloing.…

    Read article

  •  
    1–2 minutes
    23/07/2025

    Avoid downtime and threat actors: Getting the best of both worlds in MFT

    For enterprise organizations relying on managed file transfer (MFT) solutions, cybersecurity often feels like an arms race. The need to patch MFT software vulnerabilities to prevent breaches…

    Read article

Related Content

Read more about

JSCAPE MFT
  •  
    1–2 minutes
    30/07/2025

    Escape the grip: Why flexible MFT is key to enterprise agility

    Break free from costly vendor lock-in Let’s be blunt: some MFT vendors have built product suites that are less about true partnership and more about proprietary siloing.…

    Read article

  •  
    1–2 minutes
    03/07/2025

    Consolidate, deploy and thrive: JSCAPE’s formula for MFT success in uncertain times

    Global enterprises today are navigating a landscape marked by significant economic volatility. Fluctuating markets, shifting trade policies and persistent economic uncertainty are compelling enterprise organizations to reevaluate…

    Read article

  •  
    1–2 minutes
    31/03/2025

    SFTP vs. FTPS: Which file transfer software is best for business use?

    What is SFTP? SFTP is a file transfer protocol that’s normally packaged with Secure Shell (SSH), the network protocol most IT administrators use to access and manage…

    Read article

  •  
    1–2 minutes
    25/03/2025

    EDI integration with trading partners: 6 best practices

    Many large companies with high-volume transactions, especially those involved in e-commerce, manufacturing and retail supply chains, have long migrated from manual processes to Electronic Data Interchange (EDI).…

    Read article

Company

  • About Us
  • Contact Us
  • Clients
  • Case Studies
  • Testimonials
  • Privacy Policy
  • Certifications

Resources

  • Managed File Transfer
  • Secure File Transfer
  • Secure FTP Server
  • AS2 Server
  • Reverse Proxy
  • File Upload Processing
  • What Is An AS2 Server?

Support

  • Help Desk
  • Documentation
  • Customer Downloads
JSCAPE

Copyright © 2025 JSCAPE

  • Privacy Policy
  • Cookie Settings