Home > Ask the AS/400 Experts > iSeries Systems Management Questions & Answers > Configure the iSeries v5r4 to open the HTTPS port for incoming connections
Ask The iSeries 400 Expert: Questions & Answers
EMAIL THIS

Configure the iSeries v5r4 to open the HTTPS port for incoming connections

Scott Ingvaldson EXPERT RESPONSE FROM: Scott Ingvaldson

Pose a Question
Other iSeries 400 Categories
Meet all iSeries 400 Experts
Become an Expert for this site


iSeries news and advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 20 November 2008
Our iSeries v5r4 is running on WAS 6.0 and is connected to the internet via L2TP connection without IPSec.

The problem is that the HTTPS 443 port is not accessible from interned, but it is open within the local network. Nmap ports 25, 80, 110 and 10322 (WAS administration console) have state open on the internet IP address.

The HTTPS 443 port has state filtered.

No packet filters are active. My goal is to open the HTTPS 443 port, and close the 10322 ports in internet. However, I'm not sure where or how to configure this.

Activating the following filtering rules causes port 80 to open, and ports 443 and 10322 to be filtered.


# -----------------------------------------------

# Statements to permit inbound HTTP over STATICIP # -----------------------------------------------

FILTER SET HTTP_INBOUND   ACTION = PERMIT   DIRECTION = OUTBOUND   SRCADDR = *   DSTADDR = *   SERVICE = HTTP_80_FS   JRN = OFF

FILTER SET HTTP_INBOUND   ACTION = PERMIT   DIRECTION = INBOUND   SRCADDR = *   DSTADDR = *   SERVICE = HTTP_80_FC   JRN = OFF

FILTER SET HTTP_INBOUND   ACTION = PERMIT   DIRECTION = OUTBOUND   SRCADDR = *   DSTADDR = *   SERVICE = HTTP_443_FS   JRN = OFF

FILTER SET HTTP_INBOUND   ACTION = PERMIT   DIRECTION = INBOUND   SRCADDR = *   DSTADDR = *   SERVICE = HTTP_443_FC   JRN = OFF

FILTER_INTERFACE   INTERFACE = STATICIP   SET = HTTP_INBOUND

# -----------------------------------------------
How can I open the HTTPS port for incoming connections?

>
Packet rules are fairly complicated. My systems have about three pages of rules each, and there is no way I can tell what is going on without seeing the whole file.

That said, since you say that "HTTPS 443 port is not accessible from interned, but it is open within the local network," I suspect that this is a network firewall issue rather than an iSeries problem.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
iSeries Systems Management
Transfer files from one environment to another without closing all other AS/400 sessions
Send a *LMSG successfully on AS/400 using the SNDDST command
Extend storage capacity on an IBM i without negatively effecting system performance
Changing system CCSID
Changing user password expiration
Detecting system changes made by outside IP address
HIPER PTF installation and cover letters for SF99097
Library QUSRSYS not completely installed
SQL statement history storage
Setting up an automatic reply in the system reply list

Physical connections to iSeries
"Time" saving programming tips for iSeries
PC/Windows connectivity: Top 10 expert Q&As
Run command on a PC
Working with ODBC and dates
Why is my job taking twice as long?
Problems with new server and PC
Take control of your iSeries network security -- Part 2
The iSeries and MS Office make good partners
Microsoft computing: Integrating the iSeries and Microsoft Office
i5/OS and Microsoft Office Integration Handbook, Third Edition -- Chapter 3
Physical connections to iSeries Research

TCP/IP
PC/Windows connectivity: Top 10 expert Q&As
How to use NETSTAT to troubleshoot your iSeries network connections
Is there a way to continue output after logging off server?
Encrypt communication between iSeries and desktops
Use the i5/OS Networking Quality of Service monitor to look at your system's bandwidth usage
Vendor IT Briefing EDI- Has the need outpaced the translators?
Hot programming tips
The Lazy Coder: Fun with TCP/IP
Dealing with TCP/IP "hiccups"
User profile on remote machine needed for TCP/IP

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



iSeries Networking - Printing, Remote Access, TCP/IP
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts