3 of 3 people found this helpful
my recommendation from OSIsoft Systems Engineering point of view:
This is quite a common Scenario. We have many customers who use this kind of system architecture.
The PI Server (and also PI AF) should reside in Level 2 (aka DMZ with its own domain, ideally trusted with the AD from the corporate network).
Applications like Coresight should reside on corporate network layer because of security reasons. Since IIS and intra-/Internet offers quite often a surface for attacks. Putting that on the DMZ could mean that somebody could theoretically intrude the PI Server.
Interfaces/Connectors should always reside on process network level.
Just let me know if you need more details.
that was exactly what I needed to know. Thanks for your help!
This is somewhat old thread, but it is the most relevant I found for my doubt.
In this scenario, if you had only one SQL server for both AF an Vision, where would you place it?
I would guess place it in the corporate network and move AF along.
What is the main reason for keeping AF in the DMZ?