× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Mark,

I've put off the SSL till after this weekend as they are going to V5R1M0 then.

I will let you know how it goes when get back to it.

Roger Vicker, CCP

Mark Villa wrote:

> ~~~Hello,
> ~~~
> ~~~I am getting ready to open the SSL ports of a firewall and issue
> ~~~certificates for remote CAE users. What I want to make sure
> ~~~of is that
> ~~~the users inside the firewall can continue without SSL while those
> ~~~outside must use SSL because those are the only ports open on the
> ~~~firewall. Correct?
>
> Roger,
>
> We could not get that to work without timeouts using a particular nat
> configuration. We had a 192.168 and a 10.10 network that was trusted. We
> needed explicit opening of non-SSL ports (at least for telnet). We do not
> think it had anything to do with our lack of port ID knowledge of intended
> use within CAE or the signon server. It was something to do with a Cisco
> setting or the way Cisco handled nat'ting, we think.
>
> We added an iSeries filter using ops Navigator to the iSeries IP card to do
> exactly what you said above. Actually I like this better because it becomes
> integrated with the asset we are protecting in our case. We agreed that
> double protection would have been better.
>
> In the meanwhile we learned a lot about PTF's for this area, depending on
> release.
>
> Fortunately, the iSeries filter works in sequential order, so you are able
> to come up with some flexible rules. Based on this, I could make it work
> anywhere no matter what the case given enough time.
>
> Would be very interested in response here to your final method of choice and
> why.
>
> Mark Villa in Charleston SC
>
> _______________________________________________

--
*** Vicker Programming and Service *** Have bits will byte *** www.vicker.com
***
EXPERT: called in at the last minute to share the blame.






As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.