PeSIT Proxy configuration

Secure Proxy acts as an application proxy between IBM® Sterling Connect:Express and PeSIT nodes. It provides a high level of data protection between external PeSIT connections and your internal network. Define an inbound node definition for each trading partner connection from outside the company and outbound node definition for every company server to which Secure Proxy will connect.

Secure Proxy provides reverse proxy services for Sterling Connect:Express servers when the trading partners initiate sessions to Sterling Connect:Express servers in the trusted zone. Secure Proxy provides forward proxy services for Sterling Connect:Express servers when the node in the trusted zone initiates a session to a server at a remote trading partner.

Secure Proxy provides these services for Sterling Connect:Express and PeSIT nodes in a manner similar to the way it provides these services for other protocols.

The PeSIT configuration scenarios describe how to configure PeSIT protocol connections to and from the Secure Proxy engine using Configuration Manager.

Supported PeSIT Software

The following software is supported for use with the Secure Proxy PeSIT Proxy Adapter:
  • Sterling Connect:Express for z/OS version 4.2.2 or later
  • Sterling Connect:Express for UNIX version 1.4.4 or later
  • Sterling Connect:Express for Microsoft Windows version 3.0.5 or later

Organization of the PeSIT Configuration Scenarios

The first scenario instructs you how to do a basic setup. Each successive scenario adds an additional security feature to the basic configuration. After you go through each scenario, test the connection to ensure that it is correctly configured. You determine your security needs and configure the security features applicable to your environment.

The scenarios include the following:
  • Create a basic PeSIT configuration
  • Add SSL/TLS support
  • Configure PNODE-based routing
  • Add local Logon ID authentication
  • Provide outbound credentials using the netmap
The remaining configuration scenarios require Sterling External Authentication Server, an optional security feature of Secure Proxy that must be configured independently of Secure Proxy. After Sterling External Authentication Server is configured, you can update your basic security definitions to enable Secure Proxy to connect to Sterling External Authentication Server to enforce the following advanced security features:
  • Authenticate an inbound certificate or user using Sterling External Authentication Server
  • Configure logon ID mapping to the SNODE using Sterling External Authentication Server
  • Configure certificate-based routing
Additional procedures are provided to instruct you how to configure the following features:
  • Define alternate nodes for failover support
  • Enable action based on protocol errors
  • Block a PeSIT command from a PNODE