Quantcast
Channel: HelpSystems - Technical Alerts
Viewing all 23 articles
Browse latest View live

Installing or Updating Network Security 7 (v7.4)

$
0
0

Before You Begin

Note: For information on installation and setup in an HA environment, contact PowerTech Support.

Licensing

Network Security requires that you enter a valid license key in order to protect your servers. Contact keys@helpsystems.com if you need to request a new license key.

System Values

It is PowerTech’s goal not to change system values on customer systems because we recognize that security-conscious organizations have rigorous change control processes in place for even small changes to system values. Therefore, we ask you to make any system value changes that are needed. However, the Network Security installation process could change a system value to allow the install to proceed if a system value is not set as specified below. If the Installation Wizard changes a system value during install, it changes it back to its original value when the install completes.
To install PowerTech Network Security on your system, the following system values that control object restores must be configured as shown.

  • Set QALWOBJRST to *ALWPGMADP (at a minimum) to allow the system to restore programs that adopt authority. Many PowerTech Network Security programs adopt the authority of the product owner, rather than forcing you to give authority directly to administrators and end users. (Note: For some system configurations, *ALL is required temporarily.) 
  • QALWUSRDMN controls which libraries on the system can contain certain types of user domain objects. You should set the system value to *ALL or include the name of the Network Security product library (PTNSLIB and QTEMP as a minimum) for the product to function properly.
  • Set QVFYOBJRST to 1, 2, or 3. This allows Network Security to restore all objects regardless of their signature. (Note: If you normally check signatures, remember to check this system value after the Network Security install process completes.)
  • Set QFRCCVNRST (Force conversion on restore) to 0, 'Do not convert anything.'
  • Set QALWJOBITP (Allow jobs to be interrupted) to 1. This allows jobs to be interrupted to run user-defined exit programs. All new jobs that become active will default to be uninterruptible.

QAUDJRN

If you are installing or updating Network Security on a new system that does not yet include IBM's QAUDJRN audit journal, run the command CHGSECAUD to create one automatically. This is the default journal used to record Network Security’s transaction auditing data.  

System Requirements

Network Security requires the following:

  • IBM i (i5/OS, OS/400) version V7R1 or higher
  • 256 MB of disk space 
  • PASE (Portable Applications Solutions Environment), option 33
  • CCA Cryptographic Service Provider, option 35
  • Current IBM-supported PTF level

ShowCase version 9.1.0.3 or greater is required to use Network Security's ShowCase exit points.  

Installation

  1. Download the PowerTech Network Security installer (setupNetworkSecurity7.exe) from Your Account page on our website. Double-click it to start it.

  2. On the Choose Components panel, select which components you want to install. You can choose to install the Manuals and the Software for IBM i. Click Next.

  3. If you’re only installing the Manuals, the process completes and the installer closes. The Manuals have been installed. You can skip the rest of these steps.

    Note: The manuals are installed to the following location:

    • C:\Program Files\PowerTech\Network Security\manuals

    If you’re loading the Software for IBM i, continue to step 4.

  4. On the Choose a Destination IBM i panel:

    1. Select or enter the IBM i where you want to load Network Security.

    2. Enter a user profile and password that’s a member of the user class *SECOFR and has at least the following special authorities: *ALLOBJ, *SECADM, *JOBCTL, and *IOSYSCFG. The user profile should have Limit capabilities set to *NO. This profile will be used to restore and copy objects, and for product maintenance on the IBM i.

    3. (Optional) In the Advanced Settings section:

      • Enter a port number or use the arrows if you want to change the FTP port number to something other than the default of 21.

      • Select Secure File Transfer if you want to use FTPS (FTP over SSL) during the file transfer. The default FTPS secure port is 990, but it can be changed to the required secure port for your environment.

      • In the Timeout (seconds) field, enter the number of seconds the session should be kept active during an FTP transfer. You can choose anywhere between 25 and 1800 seconds (30 minutes).

        Note: If the transfer takes longer than the amount of time specified, the session will expire.

    4. Click Next.

  5. You have two options on the Product Load Options panel:

    1. Click Immediate Load if you’d like to load the product on the IBM i now.

      Note: If you're doing an update, this ends Network Security until the product load completes. After you are done, we’ll restart the product.

    2. Click Staged Load if you’d like to transfer the objects now and load them on the IBM i at a later time.

      Note: See “Loading Staged Objects on the IBM i” below for instructions on how to load the staged objects on your selected IBM i system.

  6. The Product Load Progress panel for Network Security launches. When the processing is complete, you have two choices:

    • If this is the only installation or update of Network Security that you're doing, click Finish.

    • If you have installs or updates to do on other IBM i systems, click Restart. Then, return to step 4.

    Note: If the Product Load Progress panel ends with an overall Failed message, the product upload could not complete properly. To find the reason the upload failed, click View Logs and review your logs. You can also use Download at the top of the logs to save the information for future review.

Use the WRKSPLF command to display the job log for complete information on the Network Security install. (The job log file name is JLOGn, where "n" equals a six digit number, e.g. JLOG144620).

To verify that Network Security installed successfully, enter the following command to display the PowerTech Network Security window, which shows the release and modification level of the product:

PTNSLIB/LPRDVRM

Network Security installs the following product libraries, profiles, authorization lists, commands,objects, and exit points on your system.

 

Installed on SystemDescription

Libraries

  • PTNSLIB 
  • PTWRKMGT (unless already installed by another product)
  • PTPLLIB (unless already installed by another product)

Profiles

  • PTWRKMGTOW (unless already created by another product)
  • PTADMIN (unless already installed by another product), which has special authorities *ALLOBJ, *AUDIT, *IOSYSCFG, *JOBCTL, *SAVSYS, *SECADM, *SERVICE, and *SPLCTL 
  • PTUSER (unless already installed by another product), which has no special authorities

(All these profiles are set to Password = *NONE so that they can’t be used to sign on to the system.)

Authorization List

  • PTADMIN (unless already installed by another product): PowerTech Network Security Administrators

Commands

  • WRKPTNS
  • POWERLOCK
  • PLNSREPORT
  • POWERTECH

Note: The Network Security installation program places these commands in the PTNSLIB/PTNSLIB07 library. They are copied to QGPL when you activate Network Security.

PowerTech-created
Exit Points

  • POWERLOCK_SS
  • POWERLOCK_NS
  • POWERLOCK_WRKMGT (unless already created by another product)
  • POWERLOCK_PL (unless already created by another product)

Loading Staged Objects on the IBM i

If you chose to stage your objects during step 5b of the installation or update process, do the following to manually load them on the IBM i you identified above.

  1. On the IBM i, execute the following command to display the Work with Loads panel:

    HSLOADMGR/HSWRKLOAD

  2. Enter option 1, Load, next to the Load Name for Network Security and press Enter.

    The installation program installs Network Security, the RBTSYSLIB library (as needed), and three user profiles (RBTADMIN, RBTUSER, and RBTNETPT). It adds RBTSYSLIB to the system portion of your library list, if required.

  3. Review the information on the Install Network Security Host panel and make any necessary changes and additions. Select *NEW for the installation, then press Enter.

HelpSystem's Insite Web User Interface

The Network Security 7 web server has been discontinued in favor of the HelpSystems Insite web server and browser interface, which offers simultaneous viewing of rules across all systems on your network and support for other HelpSystems products including Robot SCHEDULE and Robot NETWORK. Insite is not installed during Network Security's installation procedure. To download HelpSystem's Insite, visit the Your Account page on the HelpSystems website. 

The following commands have been removed from Network Security in favor of the HelpSystem's Insite Web UI:

  • PTNSINSWEB (to install the old web server)
  • PTNSSTRWEB (to start the old web server)
  • PTNSENDWEB (to stop the old web server)
  • PTNSCFGWEB (to configure web server ports in the old web server)
  • PTNSRMVWEB (to remove the old web server)

Also, the profile PTWEB, used for the old web server, is no longer installed.

The HelpSystem's Insite Web Browser Interface allows security administrators to work with rules and most other Network Security features directly from a browser. The following browser versions (or later) are required to use Network Security's WUI:

Hardware TypeMinimum Browser and/or OS Requirements

Desktop/Laptop

Firefox 11 or higher

Chrome 21 or higher

Internet Explorer 11

Safari 6.1 or higher

Microsoft Edge

Mobile Device

iOS: Browsers on iOS 8 or higher

Android: OS4.4 or higher using Chrome

Windows: OS 10 using Edge

IBM i

V7R1 or higher operating system

Dashboard Showing Transaction Counts

A feature of HelpSystem's Insite for Network Security is the Dashboard.

The Dashboard displays a count of all transactions monitored or controlled by Network Security. The Dashboard displays the totals for the servers based upon the criteria selected by the user (today's totals, yesterday's totals, last 7 days or last 30 days). You can also select to see the individual server's counts for the past 24 hours. To activate this feature, start the Dashboard Data Summarization job.

To start/end the Dashboard Data Summarization job, use the following commands:

Start - PNSSTRDASH

End - PNSENDDASH

Execution of the Dashboard Data Summarization job can be controlled with the following commands:

PNSHLDDASH - Use this command, Hold Dashboard Collection, to set the system in a state such that data collection to support the web interface Dashboard will not run.

PNSRLSDASH - Use this command, Release Dashboard Collection, to release the Hold Dashboard Collection command, allowing data collection to occur. 

After You Are Done

After you install Network Security, see Activating PowerTech Network Security in the Administrator's Guide for instructions on how to activate Network Security.

See also the Network Security 7 Administrator's Guide.

Brand PowerTech Platform WindowsLinuxIBM i: System i, iSeries, AS/400 Solution Security & ComplianceIntrusion DetectionNetwork Access ControlSecurity Event MonitoringSecurity & ComplianceSecurity & ComplianceSecurity & Compliance Customers Only 0 Resource Topic Procedures Products PowerTech | Network Security

Technical Alerts

$
0
0

There are currently no SEQUEL Software related alerts.

 

Product Line: 
Sequel
Products: 
Esend
Sequel Data Access
Sequel Viewpoint
Sequel Web Interface
Abstract
Anydate
Resource Topic: 

Scheduling Reports

$
0
0

With Compliance Center, you can run and distribute reports automatically. Watch our short video to learn how to create and edit a schedule, define email parameters, and distribute a report in PDF format.

Products: 
Compliance Center
Video Embed: 
Transcript: 

Transcript not available at this time.

Viewing all 23 articles
Browse latest View live