With the advent of the Perpetual Participant Licenses, the need to install and configure Directory Server WebSTS in the DMZ is a necessity to allow External Participant Users to be able to login to Forms.
The issue that I have observed and hoping that others have too and can provide a resolution is that with a setup where you have two forms instances (internal and DMZ) sharing a Single Database, when you set the Directory Server STS URL to either internal/DMZ WebSTS address, it changes it for both.
One of the consequences of this depending on the DMZ setup is that at only one group of users can login. Meaning either Internal or External users can login to Forms. If the URL is set to the WebSTS of the DMZ Server, only external users can access Forms and if set to the Internal Server's WebSTS, only Internal Users can log in.
How do you achieve both since the setting for one overwrites the other? I have encountered this behavior with at least a couple of Clients already.
Any ideas on this or working example configs will be highly appreciated.
With one particular Client, internal Users are unable to hit the DMZ server's Public address internally but external users can.