Configuring Firewall

To configure Firewall, select 81. System Configuration from the Firewall Main Menu (STRFW). The iSecurity (part I) Global Parameters screen appears:

                     ​ iSecurity (part I) Global Parameters​   ​ 05/12/24​ 10:30:50​ 
          ​
                                   ​                                   
 Firewall​  *FYI*​                          ​ SIEM Support                     ​    
  1. General Definitions​                  ​ 70. Main Control----->​ Active        
  2. Additional Settings           ​       ​ 71. SIEM 1:​ MONITOR   ​  ​ Y​           
  3. User Settings                 ​       ​ 72. SIEM 2:​ Victor    ​  ​ N​           
  4. Transaction Post Processing   ​       ​ 73. SIEM 3:​           ​  ​ N​           
  5.​ Intrusion Detection System​           ​ 74. JSON   ​             ​ N​           
  6. Product Exit Programs         ​                                             
  7. Enable ACTION (CL Script + more)​     ​ 79. Setting Severity for Servers    ​ 
  9. Log Retention                   ​                                           
                                                                                
                                                                                
 Other Products Definitions​ Active        ​ General​                              
 11. Command              ​    N  ​         ​ 81. iSecurity/Base Configuration​     
 21. Screen               ​   ​ Y​           ​ 91. Language Support               ​  
 31. Password             ​   ​ N​           ​ 99. Copyright Notice               ​  
 41. Use MFA for TCP servers​  N​                                                 
                                                                                
 Selection ===>​                                                                 
 Release ID . . . . . . . . . . . . . .​  19.06 24-11-03 ​   #​###  ##​ ###​#####   #
 Authorization code . . . . . . . . . .​  #########​###              ​ #  ​ #####   
 F3=Exit    F22=Enter authority code       ​                                     
                                                                                

To set general definitions for Firewall, including triggering emergency override or FYI simulation modes and determining the order in which logs and queries are displayed, select 1. General Definitions. The Firewall General Definitions screen appears, as shown in Setting General Definitions for Firewall.

To set additional definitions, including aspects of SQL handling and whether to inherit certain in-product authorities, select 2. Additional Settings. The Firewall Additional Settings screen appears, as shown in Setting Additional Definitions for Firewall.

To set rules on libraries or IFS objects based on user name, select 3. User Settings. The User Settings screen appears, as shown in User Settings for Firewall.

To set the data queues used to bind Firewall with external products when transactions are accepted or rejected, select 4. Transaction Post Processing. The Firewall Transaction Post Processing Data Queues screen appears, as shown in Setting Data Queues for Post-Processing of Firewall Transactions.

To set how Firewall reacts to intrusions, select 5. Intrusion Detection System. The Firewall Intrusion Detection System screen appears, as shown in Setting Up a Firewall Intrusion Detection System.

To set additional exit programs, select 6. Product Exit Programs. The Firewall User Exit Programs screen appears, as shown in Setting Product Exit Programs.

To enable or disable iSecurity Action for Firewall, select 7. Enable Action (CL Script + more). The Enable Real-Time Detection screen appears, as shown in Enabling Action for Firewall.

To set how long logs are retained and how they are backed up, select 9. Log Retention. The Log & Journal Retention screen appears, as shown in Setting Log Retention and Backup for Firewall.

To enter your authorization code for Firewall, press the F22 (Shift+F10) key. Type the code in the Authorization code field, then press Enter. Alternatively, you can set Authorization codes using the SETISAUT command provided by your distributor (SETISAUT.html).