Creating a Connect:Direct netmap

You define connection information for every Connect:Direct® node that communicates by using Secure Proxy. These values are stored in a netmap. The netmap is associated with a policy and an adapter.

About this task

Before you begin this procedure, create a policy to associate with the netmap.

To create a netmap and define Connect:Direct nodes:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Netmaps, then in the Connect:Direct Netmap tile, click View Netmaps to display the list of created Connect:Direct Netmaps.
  3. Click Add New +.
  4. Type a Netmap Name.
  5. To define a Connect:Direct node definition, click Add Netmap Node +.
  6. Specify the following values:
    • Node Name
    • Connect:Direct Server Address or hostname
    • Connect:Direct Server Port (listening port)
    • Policy
      Attention: If you did not define a policy, click the green plus sign to define one.
  7. Repeat steps 3 through 5 for each node you want to define. Define at least one PNODE and at least one SNODE to establish a connection between two Connect:Direct nodes.
  8. Click Save.

What to do next

You can limit which SNodes that specific PNodes can communicate with by creating an Access Control List (ACL) for each PNode. Complete the following steps to create an ACL:
  1. Check Enable Access Control for Outbound connections.
  2. Select a node from the list of nodes.
  3. Click Edit.
  4. Click the Outbound ACL tab.
  5. From the Available Outbound Nodes: list, select the nodes that you want the PNode to communicate with.
  6. Click to move the selected nodes to Authorized Outbound Nodes.
  7. Repeat steps 2 through 6 to create more ACLs.
  8. Click Save.
    Attention: If you check Enable Access Control for Outbound connections and do not configure any ACLs, a warning message is displayed when you click Save. The netmap is successfully saved.
    Attention: If you do not check Enable Access Control for Outbound connections and configure one or more ACLs, Secure Proxy does not enforce the ACLs.
    Important: If you use standard routing to connect to Connect:Direct in the secure zone, you identify a primary server to connect to in the adapter. You can also identify up to three alternate outbound nodes for situations when the primary Connect:Direct server is not available. Two methods of configuring alternate server routing are available:
    • Select a previously defined outbound node from the netmap–you must include this alternate outbound node in the ACL or the connection fails.
    • Enter an IP address and port–the ACL is not applied to this alternate outbound node and the connection does not fail because of the ACL.
    • If the ACL check fails on the primary outbound node, the Connect:Direct proxy adapter does not attempt connections with any of the specified alternate nodes.
    • If the ACL check fails on any specified alternate node, the Connect:Direct proxy adapter attempts connections with the remaining alternate nodes.