IBM BS029ML Self Help Guide - Page 186

Security Considerations, Local: Install ISA on the WebSphere Portal Server machine.

Page 186 highlights

Figure A-1 ISA Download page Security Considerations: As with any software application, ISA's security greatly depends on the overall security architecture in place on the machine itself. ISA runs as a Web application on a small application server. At startup, the default behavior for the application server is to dynamically pick an open port. The port will usually be different each time ISA starts, but it is possible for a user to configure the application server to use a static port for increased security and control. As for access, the default configuration for ISA V3 is to only allow access from localhost. Therefore, if the machine itself is secure from the outside, then ISA does nothing to undermine that security. Before choosing the install code and beginning the download, there a couple thing to consider. First, you have two options on how to use ISA in your WebSphere Portal Server environment: Local: Install ISA on the WebSphere Portal Server machine. Remote: Install ISA on a designated ISA administration machine. Note that this is not suggesting that this machine only be used for ISA; rather, its simply an administration machine that is remote from the WebSphere Portal Server environment. Note: The remote option may be desired when the WebSphere Portal Server is running in production and you do not want to place any further resource requirements on the machine that may impact performance, or because of business rules, you are not allowed to install any additional software onto the machine. 172 IBM WebSphere Portal V6 Self Help Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242

172
IBM WebSphere Portal V6 Self Help Guide
Figure A-1
ISA Download page
Before choosing the install code and beginning the download, there a couple thing to
consider.
First, you have two options on how to use ISA in your WebSphere Portal Server environment:
±
Local: Install ISA on the WebSphere Portal Server machine.
±
Remote: Install ISA on a designated ISA administration machine. Note that this is not
suggesting that this machine
only
be used for ISA; rather, its simply an administration
machine that is remote from the WebSphere Portal Server environment.
Security Considerations:
As with any software application, ISA’s security greatly
depends on the overall security architecture in place on the machine itself. ISA runs as a
Web application on a small application server. At startup, the default behavior for the
application server is to dynamically pick an open port. The port will usually be different
each time ISA starts, but it is possible for a user to configure the application server to use a
static port for increased security and control.
As for access, the default configuration for ISA V3 is to only allow access from localhost.
Therefore, if the machine itself is secure from the outside, then ISA does nothing to
undermine that security.
Note:
The remote option may be desired when the WebSphere Portal Server is running
in production and you do not want to place any further resource requirements on the
machine that may impact performance, or because of business rules, you are not
allowed to install any additional software onto the machine.