We are looking at deploying NetBrain and managing multiple customer networks from it.
My question is, for optimum separation from a security standpoint, must there be a separate front server per customer (tenant)?
Or can each front server service multiple tenants whilst maintaining separation?
The biggest risk we are concerned with is that if a vulnerability exists in the front server, could an attacker on one customer network leverage a front server to gain access to another customer network?
It would be a simple matter to have a separate front server for each tenant, but costly where we have lots of customers with small networks.