IBM Support

IBM InfoSphere Guardium Platform Support, V8.0

Product Documentation


Abstract

This page summarizes major specifications for the IBM InfoSphere Guardium V8.0 solution, including supported databases, operating systems, and enterprise applications for which out-of-the-box support for end-user identification is provided.

Content

These are the Guardium products related to the specifications: Database Activity Monitor; Advanced Compliance Workflow Automation; Enterprise Integrator; Vulnerability Assessment, Entitlement Reports, Data-Level Access Control; and Central Manager and Aggregator.

Cross-Platform Security

Guardium’s cross-platform solution is ideal for heterogeneous environments because it supports all major DBMS platforms and protocols running on all major operating systems.

This table shows all V8.0 supported platforms and versions.

Supported PlatformSupported Versions
Oracle8i, 9i, 10g (r1, r2), 11g, 11gR2
Oracle (ASO, SSL)9i, 10g (r1, r2), 11g
Microsoft SQL Server2000, 2005, 2005 x64, 2005 IA64,
2008, 2008 x64, 2008 IA64
Microsoft SharePoint2007, 2010
IBM DB2 (Linux, Unix, Linux for System z)9.1, 9.5, 9.7
IBM DB2 (Windows)9.1, 9.5, 9.7
IBM DB2 Purescale9.8
IBM DB2 for z/OS8.1, 9.1, 10.1
IBM DB2 for iSeriesV5R2, V5R3, V5R4, V6R1
IBM Informix7, 9, 10, 11, 11.50
Sun MySQL and MySQL Cluster4.1, 5.0, 5.1
Sybase ASE12, 15, 15.5
Sybase IQ12.6, 12.7, 15
NetezzaNPS 4.5, 4.6, 5,0, 6.0
PostgreSQL8, 9
Teradata6.x, 12, 13, 13.10
FTP
Note: Bold type denotes versions added for V8.

Host-Based Monitoring

Unique in the industry, S-TAPs are lightweight software probes that monitor both network and local database protocols (shared memory, named pipes, etc.) at the OS level of the database server. S-TAPs minimize any affect on server performance by relaying all traffic to separate Guardium appliances for real-time analysis and reporting, rather than relying on the database itself to process and store log data. S-TAPs are often preferred because they eliminate the need for dedicated hardware appliances in remote locations or available SPAN ports in your data center.

This table shows all OS platforms and versions for which V8.0 S-TAPs are available.

OS TypeVersion32-Bit & 64-Bit
AIX5.2, 5.3Both
6.1, 7.164-Bit
HP-UX11.11, 11.23, 11.31Both
Red Hat Enterprise Linux3, 4, 5Both
Red Hat Enterprise Linux for System z5.4
SUSE Enterprise Linux9, 10, 11Both
SUSE Enterprise Linux for System z9, 10, 11
Solaris - SPARC8, 9, 10Both
Solaris - Intel/AMD10, 1110-Both, 11-64-Bit only
Tru645.1A, 5.1B64-Bit
Windows2000, 2003, 2008Both
iSeriesi5/OS*
* Supports network activity monitoring, local activity support via Enterprise Integrator
Note: Bold type denotes versions added for V8.

Flexible Deployment

Guardium is available as a hardware or software offering. As a hardware offering, the solution is delivered with licensed software fully loaded and tested on a physical appliance provided by IBM (hardware appliance), When delivered as a software offering, the solution is delivered as software images ready to be deployed on your own hardware (software appliance), either directly or as virtual appliances. While the software images can be installed on any VMware product, the VMware ESX server is the recommended platform for a virtual solution.

The following table summarizes major hardware requirements for software appliances. Unless specified otherwise, the requirements are for both the physical installation and the virtual installation. The Guardium solution is designed to work on Intel-based platforms with Xeon processors. Only platforms and hardware that are officially supported by RedHat Linux 5.5 can be used as Guardium platforms, however, not all officially supported RedHat Linux 5.5 platforms can be used. Platforms that require additional drivers or specialized post-install configuration are not supported at this time.

Recommended Resources per software/virtual appliance

ResourceRequired Range*Comment
Physical CPUs4-16 coresIntel XEON processors required
Virtual CPUsMinimum 4 vCPUs
RAM 8-16 GBFor virtual, initial value must be 8 GB. If virtual customers want to work outside the required range, consult with Guardium Technical Support.
Ports (NICs)

1 Gbit per second card recommended

1-4Each port can be an actual NIC, or a virtual switch that can be configured to use multiple NICs, optionally with failover IP teaming.

When using Inspection Engines (not S-TAPs), additional ports may be required.

Disk Size300 GB to 1 TBUsing Raid is recommended. Raid-0, Raid-1, Raid 0+1, Raid 1+0 are supported.

Note: Larger disks may hold more audit records for longer periods of time but are more likely to impact performance.

If customers want to work outside the required range, consult with Guardium Technical Support.

Disk Speed7200 RPM to 15,000 RPMWith 7200 RPM, scale back the sizing ratio by 70%
DVD Drive11

* Refer to IBM x2000 high end configuration table for physical ranges.


Application Monitoring

Guardium identifies potential fraud by tracking activities of end-users who access critical tables using multi-tier enterprise applications rather than by direct access to the database. This is required because enterprise applications typically use an optimization mechanism called connection pooling. In a pooled environment, all user traffic is aggregated within a few database connections that are identified only by a generic application account name, thereby masking the identity of end-users.

Guardium supports application monitoring for all major off-the-shelf enterprise applications. Support for other applications, including in-house applications, is provided by monitoring transactions at the application server level.

This table shows all enterprise applications for which out-of-the-box support is provided, as well as all application server platforms that are supported.

Supported Enterprise ApplicationsSupported Application Server Platforms
(for other enterprise & custom developed applications)
Oracle E-Business SuiteIBM WebSphere
PeopleSoftBEA WebLogic
SiebelOracle Application Server (AS)
SAPJBoss Enterprise Application Platform
Cognos+ Others based on customer demand
Business Objects Web Intelligence
+ Others based on customer demand

Original Publication Date

03 December 2010

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Guardium Database Activity Monitor","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"8.0","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 July 2018

UID

swg27019515