IBM Iseries Universal Connection for Electronic Support and Services
Total Page:16
File Type:pdf, Size:1020Kb
IBM iSeries Universal Connection for Electronic Support and Services Explains the supported functions with Universal Connection Shows how to install, tailor, and configure Universal Connection Helps you determine communications problems Masahiko Hamada Michael S Alexander Makoto Kikuchi ibm.com/redbooks International Technical Support Organization SG24-6224-00 iSeries Universal Connection for Electronic Support and Services August 2001 Take Note! Before using this information and the product it supports, be sure to read the general information in Appendix A, “Special notices” on page 209. First Edition (August 2001) This edition applies to Version 5 Release 1 of OS/400. Comments may be addressed to: IBM Corporation, International Technical Support Organization Dept. JLU Building 107-2 3605 Highway 52N Rochester, Minnesota 55901-7829 When you send information to IBM, you grant IBM a non-exclusive right to use or distribute the information in any way it believes appropriate without incurring any obligation to you. © Copyright International Business Machines Corporation 2001. All rights reserved. Note to U.S Government Users - Documentation related to restricted rights - Use, duplication or disclosure is subject to restrictions set forth in GSA ADP Schedule Contract with IBM Corp. Contents Preface . vii The team that wrote this redbook . vii Comments welcome . viii Chapter 1. Extreme Support Personalized (ESP) . .1 1.1 Introduction to ESP . .1 1.1.1 Customer Care Advantage . .1 1.1.2 ESP approach. .3 1.1.3 Benefits for customers. .4 1.2 Available applications in electronic support . .5 1.2.1 Electronic Customer Support (ECS) connection . .5 1.2.2 Service Agent . .6 1.2.3 Consolidated inventory collection using Management Central . .6 1.2.4 Electronic Services for iSeries and AS/400 servers . .6 1.2.5 Performance Management/400e . .8 1.3 Connectivity options . .9 1.4 Connectivity tools for iSeries. .11 1.4.1 Extreme Support configuration wizard . .11 1.4.2 Universal Connection Wizard (UVC) . .12 1.4.3 Dial-up connection wizards . .12 Chapter 2. Network security concepts and overview . .15 2.1 Designing network security . .15 2.1.1 Goals of network security . .15 2.1.2 Threats against network security. .17 2.1.3 Evaluating the threats . .18 2.1.4 Creating a security policy . .18 2.1.5 Security plan . .19 2.1.6 Anatomy of a security policy . .19 2.2 Security characteristics of popular protocols and services. .23 2.2.1 Internet Protocol (IP) security characteristics . .23 2.2.2 Internet Control Message Protocol (ICMP) security characteristics . .24 2.2.3 Transmission Control Protocol (TCP) security characteristics . .25 2.2.4 Simple Mail Transfer Protocol (SMTP) security characteristics . .26 2.2.5 Domain Name System (DNS) security. .27 2.2.6 Passive attacks . .27 2.2.7 Denial of Service (DoS) attacks. .28 2.2.8 Unauthorized access. .28 2.2.9 Impersonation or masquerade. .29 2.3 Network security technologies. .30 2.3.1 IP packet filters . .30 2.3.2 Network address translation (NAT) . .31 2.3.3 Virtual private network (VPN) and IPSec . .31 2.3.4 Proxy server . .32 2.3.5 SOCKS server. .33 2.3.6 Secure Sockets Layer (SSL) and Transport Layer Security (TLS) . .33 2.3.7 Domain Name Server (DNS) . .34 2.3.8 Comparing network security functions . .35 2.4 Monitoring: Auditing and logging . .35 2.5 Universal Connection security. .36 © Copyright IBM Corp. 2001 iii Chapter 3. Point-to-Point Protocol (PPP) connection examples . 37 3.1 Universal Connection Wizard. 37 3.2 PPP dial-up to AGNS. 38 3.2.1 Prerequisites . 38 3.2.2 Planning worksheet for PPP dial-up to AGNS . 39 3.2.3 Configuring a PPP connection using AGNS . 40 3.2.4 Objects created by the wizard for AGNS connections . 49 3.2.5 Using Universal Connection. 54 3.2.6 Security over an AGNS connection . 58 3.3 PPP dial-up to any ISP . 59 3.3.1 Prerequisites . 60 3.3.2 Planning worksheet for PPP dial-up to any ISP . 60 3.3.3 Configuring a PPP dial-up to any ISP connection. 62 3.3.4 The definitions created in the Universal Connection Wizard. 73 3.4 PPP dedicated FT1/T1 configuration . 79 3.4.1 Planning worksheet for the dedicated FT1/T1 configuration . 80 3.4.2 Configuring a PPP dedicated FT1/T1 on AS026. 83 3.4.3 The definitions created in the wizard . 95 3.5 Security over a PPP dial-up to any ISP connection . 102 3.5.1 IBM Electronic Support connection using VPN. 102 3.5.2 IP packet filtering . 103 Chapter 4. Direct connection examples . 107 4.1 Direct connection support . 107 4.1.1 Prerequisites . 108 4.2 Frame relay configuration . 108 4.2.1 Planning worksheet for a direct frame relay configuration . 109 4.2.2 Configuring a direct frame relay connection on AS026. 110 4.2.3 The definitions created in the Universal Connection Wizard. 123 4.3 Using a cable modem or DSL modem . 126 4.3.1 Planning worksheet for a cable modem configuration . 126 4.3.2 Configuring a direct cable modem on AS026 . 128 4.3.3 Definitions created in the Universal Connection Wizard . 133 4.4 Router isolated access configuration . 137 4.4.1 Planning worksheet for a router isolated access configuration . 137 4.4.2 Configuring router isolated access on AS026. 139 4.4.3 The definitions created in the wizard . 145 4.5 Security over a direct connection. 149 4.5.1 IBM Electronic Support connection using VPN. 149 4.5.2 IP packet filtering . 149 Chapter 5. Multi-hop scenario . 151 5.1 What is multi-hop?. 151 5.2 Multi-hop network configurations . 152 5.2.1 Extreme router merged with a VPN secure gateway connection . 152 5.2.2 Interior router merged with VPN secure gateway connection . 153 5.2.3 Interior/exterior router with a VPN secure gateway connection . 154 5.2.4 Standalone VPN secure gateway behind a firewall . 154 5.2.5 Standalone VPN secure gateway as a bastion host on DMZ . 155 5.3 Prerequisites . 157 5.4 Completing the planning worksheet for multi-hop. 158 5.5 Requirements for the packet filter router configuration. 159 5.6 Configuring a multi-hop connection . 162 iv iSeries Universal Connection for Electronic Support and Services 5.7 Definitions created by the wizard for a multi-hop connection . .168 5.7.1 QTOCL2TP profile. .169 5.8 Security over a multi-hop connection . .171 Chapter 6. Troubleshooting tips. .173 6.1 Considerations for using the Universal Connection Wizard . .173 6.2 PC troubleshooting . .174 6.3 iSeries server troubleshooting. .176 6.3.1 Dial-up AT&T Global Network Service. .176 6.3.2 ISP connection case troubleshooting. .185 6.3.3 Multi-hop troubleshooting . ..