Firewall support
Tivoli Management Services supports most common firewall configurations, including those that use address translation (application proxy firewall is a notable exception). To enable this support, use the piped protocols, which open a single port on the firewall for communication by IBM® products. If your environment includes a firewall between any components that must communicate with each other, you must specify at least one piped protocol during configuration.
During startup, the monitoring server registers its services and the IP address of these services with a location broker. Clients such as monitoring agents send queries to the location broker to request address information for a service, and receive a list of protocols and IP addresses at which these services are available. The client then sends a specific server request to one of the addresses in the list received from the location broker. Service registration with the location broker assumes address continuity.
If the published address of the monitoring server is identical and reachable for either side of the firewall, then nothing further has to be done to achieve communications in this firewall environment. If the same address cannot be reached from either side of the barrier firewall, then either ephemeral pipe support or broker partitioning is required.
For more information about configuring firewall support, see the following publications:
- Instructions for enabling firewall support for the z/OS® components: Configure a Tivoli Enterprise Monitoring Server and the configuration documentation for each monitoring agent.
- Instructions for enabling firewall support for the distributed components: the "Firewalls" section in the IBM Tivoli Monitoring: Installation and Setup Guide.
- Conceptual information about IBM Tivoli Monitoring firewall support: IBM Tivoli Monitoring: Implementation and Performance Optimization for Large Scale Environments, SG24-7443, which you can find at the IBM Redbooks® website.