Previous Table of Contents Next


As a final topic on network security, let’s consider the use of a firewall. A firewall is another system outside the AS/400 used to secure the communications gateway to the Internet. With such a configuration, the AS/400, and perhaps other systems within the business, are never directly connected to the Internet. Instead, all accesses from the network first come into the firewall system. Firewalls protect private networks from outsiders (internal and external). Based upon the security policy for the business, the firewall system allows or denies access to the secured systems within the business. It gets its name because it keeps the fire (unsecured network) from reaching the secured internal network.

In most businesses, firewalls are typically implemented as either PCs or Unix systems. Because the use of firewalls introduces a new system for an AS/400 customer to manage, at V4R1 we introduced an under-the-covers firewall system. We use the Integrated PC Server (IPCS) to provide this secured network gateway. We discuss the uses of the IPCS and other under-the-covers application engines in Chapter 11; but for security purposes, the IPCS makes a great firewall because it reduces the management overhead of another system. This firewall is in the same box (physically), without being in the same box (logically).

Conclusions

Security is one of the most important functions in any multiuser system. With so many systems being connected to the Internet, the need to guarantee a secure system will only increase. OS/400’s security component and SLIC’s object-based authorization component provide a mechanism that satisfies today’s requirements yet is flexible enough to provide for future expansion. As requirements for even higher levels of security evolve, such security can be added in a nondisruptive way to the AS/400.

In addition to the overall system security of an AS/400, we have described in this chapter the ways a user’s authority is commonly managed. These include

•  Menu access
•  Adopted authority
•  Group authority
•  Private authority

As a part of pointer resolution, the authority search algorithm described earlier is performed. But the authority to an object is not much good if you can’t address it. In the next chapter, we look at addressing and the management of the single-level store. Though not usually considered a part of security, the single-level store on the AS/400 plays a major role in protecting users and user data.


Previous Table of Contents Next

Copyright © NEWS/400 Books