Home > AS/400 Tips > iSeries administrator tips > Where to put a firewall when using partitions
iSeries 400 Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ISERIES ADMINISTRATOR TIPS

Where to put a firewall when using partitions


Yessong Johng
11.27.2002
Rating: -4.20- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Symantec Enterprise Firewall (SEF) for iSeries running Linux V7.0.3 will be available in the near future. You can install this product in a Linux LPAR partition within an iSeries server. This way, you can have a Web server, Web application server, database server and firewall all together in a single iSeries server. To get you thinking about how you would deploy a firewall product within an iSeries partition, this tip suggests some scenarios with comparison of pros and cons of each option.

Topology 1: The firewall on Linux for iSeries with an intranet
The first topology shown in Figure 1 is designed to protect an iSeries server from an intranet. The firewall has one iSeries Ethernet adapter assigned to it, and the Ethernet adapter connects to an intranet. The firewall also has two virtual Ethernet LAN adapters to access each OS/400 logical partition. All traffic from the intranet must pass through the firewall partition before reaching any OS/400 logical partition. This topology allows firewall administrators to control access to the iSeries from an intranet.

Figure 1: The firewall on Linux for iSeries with an intranet.

 

Advantages of Topology 1:

  • Simple configuration
  • Protects iSeries server from unauthorized access from intranet
  • Controls iSeries access to intranet and Internet
  • Controls access between OS/400 partitions
  • Uses high-speed virtual LAN

Disadvantages of Topology 1:

  • No direct access to iSeries partition if intranet is trusted
  • No control of intranet access to Internet
  • Cannot protect intranet from Internet attacks

Topology 2: The firewall with an intranet and with a virtual LAN perimeter network
The topology shown in Figure 2 protects the iSeries server from the Internet and the intranet. The topology provides a virtual LAN perimeter network. A perimeter network provides separation from a front-end application and a back-end database to provide additional security. For example, the perimeter network may contain an Apache HTTP server on Linux, IBM HTTP server for iSeries or WebSphere Application Server that communicates with a database on the LPAR1 partition. This topology does not trust the intranet and can control access from the intranet to the iSeries server.

Figure 2: The firewall with an intranet and with a virtual LAN perimeter network.

 

Advantages of Topology 2:

  • Provides perimeter network for increased security
  • Protects iSeries server and the intranet from Internet attacks
  • Controls access from the intranet to the perimeter network and to the Internet
  • Uses high-speed virtual LAN

Disadvantages Topology 2:

  • No physical perimeter network for hosts that are not on the virtual LAN
  • Complex configuration

Topology 3: The firewall with an intranet and a perimeter network
The topology shown in Figure 3 protects the iSeries server from the Internet and the intranet, and it provides a real perimeter network. This topology is important if the hosts in the perimeter network are not OS/400 logical partitions and cannot be a part of the virtual LAN perimeter network. This topology does not trust the intranet and can control access from the intranet to the iSeries server.

Figure 3: The firewall with an intranet and with a perimeter network.

 

Advantages Topology 3:

  • Provides perimeter network for increased security
  • Provides real perimeter network for hosts not on the virtual LAN
  • Protects iSeries server, the intranet and the perimeter network from Internet attacks
  • Controls access from the intranet to the iSeries server, the perimeter network and the Internet

Disadvantages of Topology 3:

  • Complex configuration
  • Does not use high-speed virtual LAN for external hosts in the perimeter network

----------------------------
About the author: Yessong Johng is an IBM Certified IT Specialist at the IBM International Technical Support Organization, Rochester Center. His major responsibilities are WebSphere and Domino implementation on iSeries focusing on their integration. His new responsibilities include Linux and its solutions on iSeries. Yessong can be contacted by e-mail at yessong@us.ibm.com.


Rate this Tip
To rate tips, you must be a member of Search400.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
iSeries administrator tips
Translating Linux for IBM i admins: Using GUI to make it easy
Translating Linux for IBM i admins: Working with jobs and networking
OpenOffice: What to know before making the transition from Microsoft Office
OpenOffice: An enterprise open source solution
Database performance comparisons on IBM i
Translating Linux for IBM i admins: User profile commands
Modern System i reports using Client Access
Tips for installing Lotus Domino server on a System i partition
The iSeries Blog has a new home on IT Knowledge Exchange
Virtualization for IBM i: Backups

Performance
Will overloaded discs impact iSeries performance?
Extend storage capacity on an IBM i without negatively effecting system performance
Database drivers on the i: MySQL vs. IBM Toolbox
Performance tuning for IBM i: The basics and beyond
IBM releases new Power products for the midrange
Top System i admin tips for 2006
Catholic Charities keeps track of homeless with iSeries
i5 error messages: What you need to know
IBM races for clock speed
System shutting down after cleanup

iSeries system performance and monitoring
Translating Linux for IBM i admins: Working with jobs and networking
Database performance comparisons on IBM i
How to: Monitoring job activity on the AS/400
Performance tuning for IBM i: The basics and beyond
How to: Reduce the percentage of ASP used on the AS/400
Detecting system changes made by outside IP address
AS/400 system values quiz
Checking on System i disk space requires creating a new command: XRTVSYSSTS
Drive space management commands
Viewing netstat information

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CIW  (Search400.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



iSeries Security - Security Tools, Physical Security and System Security
HomeNewsTopicsITKnowledge ExchangeTipsBlogsAsk the ExpertsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts