Symantec preps Linux firewall for IBM iSeries

Hardened, seasoned, thickened


ComputerWire: IT Industry Intelligence

Symantec will announce this week that it is working with IBM to deliver a hardened firewall which will run within an iSeries Linux partition and provide protection for the iSeries or other connected servers on corporate networks,

Timothy Prickett Morgan writes

.

The firewall is a tweaked version of Symantec's Enterprise Firewall for Windows and Solaris servers, and it is expected to be available in the second half of 2002.

OS/400 V5R2 is expected to start shipping at around the same time--notwithstanding recent rumors about IBM's moving up the next-generation iSeries announcements (an announcement is not the same thing as a delivery date, remember). Sources at Symantec say that they are keen on moving into the OS/400 server space, but that there are some significant issues involved with support the open-source Linux operating system.

Because Linux is open source, anybody can, in theory, as well as in practice, go into the very guts of the Linux operating system--its kernel--and make substantial changes. This self-reliance is one of the benefits of using Linux over other operating systems. When it comes to security, however, this is a serious detriment. The reason security programs like Symantec's Enterprise Firewall work is that only Symantec and the operating system vendor have the ability to make changes to the operating system and the way it interacts with the firewall.

This is why Symantec does not support its firewalls on Linux and why it only sells an appliance server version of the Enterprise Firewall to customers who want to run it on Linux. Symantec uses a version of Red Hat Linux 7.1 that runs on an Intel-based server.

Symantec takes the Red Hat Linux, weaves its firewall into it, and "hardens" it. Hardening a piece of software means closing up potential security gaps, applying specific settings that cannot be changed, and restricting how other programs interact with that piece of software. Symantec controls the hardware, software, and firewall, so it can say confidently that it will be secure.

Having done this for its Enterprise Firewall appliance, called VelociRaptor, Symantec is now taking the same approach as it moves into the iSeries market. Rather than just deliver a Linux-version of its firewall that can load into an iSeries Linux partition,

Symantec will ship a hardened version of Red Hat plus its firewall and effectively turn a single iSeries Linux partition into an appliance server, or, in IBM lingo, a Dedicated Firewall Partition (I made that name up). No other application will be allowed in the iSeries Linux partition where the Symantec firewall runs, and customers will load the Red Hat and firewall programs as a single entity. Pricing has not been set for the firewall, and Symantec is not a liberty to say when the Enterprise Firewall for iSeries will be ready. But the company is looking for beta testers for the new iSeries program. You can contact Symantec at www.symantec.com for more information.

© Midrange Server, Inc. All Rights Reserved.


Other stories you might like

  • VMware claims ‘bare-metal’ performance from virtualized Nvidia GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual datacenter product updates across CPU, GPU, and DPU
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Now Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading

Biting the hand that feeds IT © 1998–2022