Currently Jira sits on the corporate LAN behind the firewall. Internal users access it via the corporate LAN, but can also access it outside the office using VPN. Moreover, the base url "http://jira-xx:8080" only works when you are logged on to the corporate LAN.
Now we are adding Service Desk for external customers. We have had to change the Jira base url to one which anyone on the internet can use (https://...) because it has to be the same as the Service Desk url (surely this is a defect in the design of Service Desk?). As a result, anyone on the internet can get to our Jira's login page. They still need to have a valid login and password to get in the normal route, but the mere fact that they can get to the login page is a security risk since Service Desk and Jira are so closely connected.
Has anyone had this problem and is aware of a resolution?
For example, can we separate Service Desk (with or without it's own Jira project) from Jira, place it in a DMZ and connect it with Jira via the firewall thereby keeping Jira inside the corporate LAN?
Adam