Unconfigured Ad Widget

Collapse

Announcement

Collapse
No announcement yet.

AS/400 Outside Firewall

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • AS/400 Outside Firewall

    There are several things that you should be aware of....and this is only a partial list... 1) make sure all of the IBM default user ID's (QSECOFR, QPGMR, QSYSOPR, etc.) have the passwords changed to a non-trivial one, or set to *NONE so they cannot signon. 2) secure the root of the IFS so there is no public rights to it. 3) be careful about having FTP or Telnet activated to your production box, if it is necessary, I would recommend some sort of exit program software to monitor for someone using these. 4) check out whether devices are being autoconfigured, both remote devices and virtual devices. I would configure the minimun number of devices needed (if any) and then set these values off. 5) secure your program and data libraries with authority lists or object authority, making the programs *use only for *PUBLIC and the minimun necessary for the data. 6) check to find out what programs have adopted authority (there is a menu option from the menu SECTOOLS that will create a report of these items). Verify it these programs really need adopted authority. 7) Only start the TCP servers that are required for your web hosting, turn the others off. 8) restrict access to qsys.lib from the ifs. anyway...these were some of the key issues raised when I had a security audit last year. They are mostly general AS/400 security things that should be done anyway. Hope this helps Ron

  • #2
    AS/400 Outside Firewall

    All: We are moving an AS/400 outside the fire wall for a B2B solution. The machine is not a production box, however, it will be used to showcase some of our new Web Enabled AS/400 screens. Currently our machine is at Security Level 20, but since running the AS/400 Security Advisor, we will be changing this to Security Level 40 as well as making several other security changes. Are there any really major holes in security that should be patched prior to establishing the AS/400 outside the fire wall? As you might be able to see, I'm not well versed in AS/400 security, but I seem to be the only one concerned about this box being outside our fire wall. I Thank You In Advance For You Suggestions.

    Comment


    • #3
      AS/400 Outside Firewall

      I appreciate your advice. Thanks so much. Regards, Jamey.

      Comment

      Working...
      X