PeSIT Proxy configuration
Secure Proxy acts as an application proxy between IBM® Sterling Connect:Express and PeSIT nodes. It provides a high level of data protection between external PeSIT connections and your internal network. Define an inbound node definition for each trading partner connection from outside the company and outbound node definition for every company server to which Secure Proxy will connect.
Secure Proxy provides reverse proxy services for Sterling Connect:Express servers when the trading partners initiate sessions to Sterling Connect:Express servers in the trusted zone. Secure Proxy provides forward proxy services for Sterling Connect:Express servers when the node in the trusted zone initiates a session to a server at a remote trading partner.
Secure Proxy provides these services for Sterling Connect:Express and PeSIT nodes in a manner similar to the way it provides these services for other protocols.
The PeSIT configuration scenarios describe how to configure PeSIT protocol connections to and from the Secure Proxy engine using Configuration Manager.
Supported PeSIT Software
- Sterling Connect:Express for z/OS version 4.2.2 or later
- Sterling Connect:Express for UNIX version 1.4.4 or later
- Sterling Connect:Express for Microsoft Windows version 3.0.5 or later
Organization of the PeSIT Configuration Scenarios
The first scenario instructs you how to do a basic setup. Each successive scenario adds an additional security feature to the basic configuration. After you go through each scenario, test the connection to ensure that it is correctly configured. You determine your security needs and configure the security features applicable to your environment.
- Create a basic PeSIT configuration
- Add SSL/TLS support
- Configure PNODE-based routing
- Add local Logon ID authentication
- Provide outbound credentials using the netmap
- Authenticate an inbound certificate or user using Sterling External Authentication Server
- Configure logon ID mapping to the SNODE using Sterling External Authentication Server
- Configure certificate-based routing
- Define alternate nodes for failover support
- Enable action based on protocol errors
- Block a PeSIT command from a PNODE