If you search in the community you can find all the documentations.
After all, usually the most frequently configuration is a LB before UI machines and later the task and db servers with SSL activated.
Better if you dont have any FW between UI,Task & DB.