If ibaDaVIS will be accessible via a public network, the system must be protected with a firewall as a minimum security requirement. As an additional layer, the use of a reverse proxy is recommended as this ensures that no direct communication takes place between the clients and ibaDaVIS. The corresponding port for the web interface (see Ports) of ibaDaVIS must be enabled in the firewall. By channeling the data traffic through the reverse proxy, additional protective measures can be implemented. These may include virus scanners or packet filters. If the reverse proxy is also used to encrypt the data traffic using an SSL certificate, this reduces the CPU load on the ibaDaVIS web server.

Fig. Operation with firewall and reverse proxy