SecureWay Firewall V4.2 for Windows NT and AIX Offers More Secure, Cost-Effective Connectivity

Similar documents
General Parallel File System V1R4 Now Supported on Clusters of RS/6000 Workstations and Servers Running HACMP

IBM WebSphere Application Server V3.5, Advanced Edition Expands Platform Support and Leverages the Performance of the Java 2 Software Development Kit

IBM WebSphere Application Server V3.5, Advanced Edition for Linux Extends Support to Red Hat, Caldera, SuSE, and TurboLinux

IBM Payment Gateway for AIX, Version 2 Adds Major Functions to Financial Institutions Processing Transactions for Internet Commerce

National Language Support for Windows NT and AIX Now Available with IBM WebSphere Application Server V3.0.1, Standard Edition

IBM DirectTalk Speech Recognition for Windows with ViaVoice Technology Delivers Large Vocabulary Speech Recognition in the Telephony Environment

IBM NetVista Thin Client Manager V2R1 Simplified Ordering

IBM WebSphere Site Analyzer, V3.5 Adds Build to Order Support for AIX Users

DB2 for IBM iseries Platform Extended with Enhanced Tools

IBM ViaVoice for Windows, Release 8 Family of Products, Spanish Language Version, Delivers Improved ViaVoice Performance

DFS 3.1 for Gateway Environments

IBM QMF for Windows for IBM iseries, V7.2 Business Intelligence Starts Here!

IBM MQSeries Integrator Agent for CICS Transaction Server Enables MDp Customers to Move to Business Integration

Tivoli Remote Control V3.7.1 Delivers Enhanced Function for Enterprise Networks

IBM WebSphere Commerce Suite, Start Edition for Linux, Version 4.1: The Complete e-commerce Solution for Your Web Site

IBM WebSphere Data Interchange for Multiplatforms V3.1 Extends Coverage to AIX and Windows 2000 Platforms

IBM Netfinity Director with UM Services v2.12 Leading PC/Server Management Software for Windows 2000

IBM CICS Online Transmission Time Optimizer for z/os V1.1 Improves User Productivity and 3270 Network Utilization

IBM Workstation APL2 for Multiplatforms V2 Includes Productivity Enhancements and Linux Support

Software Announcement March 6, 2001

Tivoli Inventory 4.0 Provides A Cross-Platform Automated Solution For Inventory Management

IBM MQSeries Version 5.1 for Compaq Tru64 UNIX and MQSeries link for R/3 for Compaq Tru64 UNIX, V1.2 New Platform Support in the MQSeries Family

IBM Net.Commerce Version 3.2: The Complete E-commerce Solution for Your Growing Business

Tivoli SecureWay Security Manager V3.7.1 Delivers Increased Functionality for UNIX Environments

IBM Infoprint Server for iseries V5.2 Transforms Your Output into an e-business Advantage

IBM Tivoli Risk Manager Provides Protection for the Enterprise through Intrusion and Protection Management

Solution Developer Marketing: AS/400 Introduction CBT Self-Study Courseware from Course Technology, Inc.

IBM QMF for Windows for AS/400 Business Intelligence Starts Here

IBM Program Restart Facility for IMS Facilitates Automated Restarts

Novell Network Services for OS/390 Release 1

Tivoli NetView Performance Monitor Version 2 Release 5

IBM AIXlink/X.25 V2.1 offers enhancements for migration from X.25 specific adapters that allow APIs to remain the same

IBM Communications Server for AIX, Version 6.1 Supports the IBM AIX 5L Version 5.1 Operating System

IBM 4690 Operating System Now Supports Telxon Wireless Adapters

IBM QMF for Windows for AS/400 V7 For All Your Operational and Warehouse Query Needs

IBM GPFS for Linux V1.3 Extends Your Configuration Options

Manage Your Software Budget with IBM Software Subscription for AIX

Software Announcement December 17, 2002

IBM COBOL for OS/390 & VM V2R2

IBM MQSeries for VSE/ESA

IBM WebSphere Business Integration Adapter for DTS Protocol extends legacy mainframe integration

Software Announcement October 14, 2003

Software Announcement October 26, 1999

IBM Content Manager OnDemand for z/os and OS/390, Version 7.1 Your Key to Enterprise Report Management

IBM Debug Tool Utilities and Advanced Functions V3.1 Helps Maximize Availability of z/os and OS/390 Applications

Selected IBM Informix Products Now Available through Passport Advantage

Tivoli Smart Handheld Device Manager Enables Remote Management of Mobile Devices

RS/6000 Clustered Server Attachment Features Connect Servers and Control Workstations

IBM Content Manager OnDemand for Multiplatforms V2.2 Enhanced

IBM Object REXX Now Runs on Windows NT and Windows 95

VisualAge COBOL for Windows NT, Version 3.0 Simplifies Use and Improves Productivity

IBM QMF for Windows for DB2 Workstation Databases, V7.2 Business Intelligence Starts Here!

IBM XML Toolkit for z/os and OS/390, V1.5 Supports XML Open Standards for Java and C++ Parsers and Java XSLT Processor

Software Announcement January 28, 2003

IBM WebSphere Application Server Version 4.0, Advanced Single Server Edition for iseries

IBM Cluster Systems Management for Linux Now Available on IBM Cluster 1300 Running Linux OS

IBM Tivoli Access Manager for Operating Systems V3.8 Manages and Extends Access Control to UNIX and Linux Systems

IBM Software Subscription for IBM iseries Offering Saves Time and Improves Your IT Budgeting

IBM VisualAge Smalltalk Enterprise V6.0 The Comprehensive Smalltalk Development Tool for e-business on Demand

IBM Lotus Instant Messaging and Web Conferencing (Sametime) V6.5.1 provides instant, anytime access to people and information

IBM Tivoli NetView for TCP/IP Performance V1.4 Maximizes z/os System and Network Performance

IBM VisualAge C++ Professional for AIX, V6.0 Now Supports Symmetric Multiprocessing with OpenMP

IBM XL Fortran Advanced Edition V8.1 for Mac OS X A new platform supported in the IBM XL Fortran family

IBM General Parallel File System for Linux helps simplify file system management across clusters

IBM CICS VSAM Recovery V3R1 Automates the Recovery of Your Lost or Damaged VSAM Files

IBM WebSphere Everyplace Connection Manager V4.2 Enables You to Extend Applications to Wireless Devices Over Multiple Networks

IBM WebSphere Voice Application Access, V4.1 Speech Enables Your e-business Portal Environment to Improve Information Access

IBM Secure Perspective bridges the gap between data security policy and practice

IBM WebSphere MQ V5.3 Changes to Processor-Based Pricing and Adds Extended Transactional Clients

IBM 4690 Operating System V4, engineered exclusively for the retail industry, provides enhanced security and greater support

Tivoli Manager for OS/390 Monitors and Controls Your Systems Management Activities

IBM X.25 over TCP/IP for Communication Controller for Linux lets you use X.25 in the CCL environment

IBM COBOL for Windows, V7.6 provides a costeffective compiler and runtime environment for customizing third-party applications on Windows servers

IBM i operating system Value Pack offers software and vouchers for IBM Power 570 and 595 servers

IBM Lotus Domino Unified Communication V1.2.2 adds National Language Support and AIX for Cisco

IBM Lotus Messaging and WebSphere Portal CEO bundle includes messaging, collaborative applications, and full portal capabilities

IBM XL C/C++ Advanced Edition V7.0.1 for Linux and XL Fortran Advanced Edition V9.1.1 for Linux enhanced to include new Linux support

Airline Control System V2.3 delivers a new base for exploiting 64-bit addressing

IBM HACMP Version Enhances High-Availability Processing for Mission-Critical Applications

IBM Scale Out Network Attached Storage Software

IBM pseries 610 Models 6C1 and 6E1 Value Increased with POWER3-II 333 MHz Processor Option and Internal SCSI RAID Support

IBM Infoprint XML Extender for z/os Connects e-business Applications with Advanced Function Presentation

IBM Content Manager VideoCharger for Multiplatforms V7.1 Delivers High-Impact Video and Audio Content Via the Internet and Intranet

Software Announcement September 23, 2003

IBM SecureWay On-Demand Server Version 2.0

IBM Virtual I/O Server helps maximize physical

IBM 7329 Model 308 SLR100 Tape Autoloader Enhances Data Storage

ENOVIA Web-Based Learning Solutions V5.9 Optimizes User Performance

IBM InfoSphere Master Content for InfoSphere Master Data Management Server delivers enterprise content to single view of customer applications

IBM WebSphere MQ Hypervisor Edition accelerates deployment of private cloud messaging

IBM 3494 Peer-to-Peer Virtual Tape Server Enhances Data Availability and Recovery

IBM System Storage ProtecTIER Entry Edition V2.5 supports Symantec NetBackup OpenStorage API

Software Announcement June 24, 2003

IBM VisualAge Smalltalk Server for OS/390 and z/os, V6.0 The Deployment Environment for VisualAge Smalltalk

IBM Tivoli Storage Productivity Center for Disk Midrange Edition V4.1 and IBM Tivoli Monitoring for Virtual Servers V6.2

IBM Power Systems Software: Ordering and pricing structure enhancements

VMware vsphere subscription upgrades available

IBM DB2 Intelligent Miner Scoring V7R1 Delivers Mining Analytics to Operational Applications

IBM DB2 High Performance Unload for Multiplatforms and Workgroups add additional language support

IBM Content Manager for iseries V5R1 Provides Best-of-Breed Content Management and Workflow Technology

Transcription:

Software Announcement June 20, 2000 SecureWay Firewall V4.2 for Windows NT and AIX Offers More Secure, Cost-Effective Connectivity Overview IBM s SecureWay Firewall products can help protect your network by: Only admitting authorized traffic through the firewall Hiding the IP addresses and configuration of the internal network from the untrusted network Authenticating users and traffic while controlling access Hardening of the Firewall system so that there is less chance for hackers to get into or through the firewall Allowing you to log all traffic through the firewall and use it to generate user activity reports What s New in Firewall V4.2 for both Windows NT and AIX Platforms Administrators may now perform basic administration functions on the Firewall from a downloadable SecureWay Tivoli Plus Module (English). The WTE V2.0 (HTTP proxy), which shipped with Firewall 4.1, has been upgraded to WTE V3.0. A new Connection Wizard makes it easier for you to configure and activate some of the typical filter rules to allow traffic through the Firewall. Function from SecureWay Boundary Server has been integrated to enable you to authenticate users in the Lightweight Directory Access Protocol (LDAP) database using Tivoli SecureWay Policy Director. The AIX platform is further enhanced with the addition of: Firewall V4.2, which allows you to use the AIX 4.3.3 Internet Key Exchange (IKE) plus the latest AIX services. An IKE compliant Virtual Private Network (VPN) Client, which allows remote users to establish a VPN tunnel with the Firewall. Dynamic filters for the FTP PASV command, which allow you to define a connection for FTP sessions. Filter rules permitting the data connection are dynamically allocated and removed based upon ports in use by the server. Key Prerequisites Windows NT installations require Windows NT Server V4. AIX installations require AIX V4.3.3. Planned Availability Date July 7, 2000 At a Glance Protect your valuable business assets, provide a virtual private network, and offer easy-to-use administration with comprehensive network security! Firewall 4.2 for AIX extends V4.1 with new features: AIX IKE support IKE VPN Client Dynamic filter for FTP PASV Firewall 4.2 offers the following new features for AIX and Windows NT: Firewall administration from Tivoli managed systems Web Traffic Express (WTE3) upgrade Connection Wizard LDAP user authentication For ordering, contact: Your IBM representative, an IBM Business Partner, or IBM Americas Call Centers at 800-IBM-CALL Reference: YE001 This announcement is provided for your information only. For additional information, contact your IBM representative, call 800-IBM-4YOU, or visit the IBM home page at: http://www.ibm.com. IBM United States IBM is a registered trademark of International Business Machines Corporation. 200-181

Description SecureWay Plus Module for Tivoli Firewall users can now perform remote administration from a Tivoli console using the Plus module. The module lets you perform the following tasks: Manage distribution and installation of the IBM Firewall Manage subscription lists for clients and servers Monitor key processes and services Monitor IBM Firewall clients from the console Start and stop processes or services from the Tivoli desktop For instructions on downloading the Plus module visit: http://www-4.ibm.com/software/security/firewall This module is in the English language only. Web Traffic Express (WTE) Upgrade The SecureWay Firewall V4.2 provides a full-featured HTTP proxy implementation based upon a new, upgraded version of the WTE3 product. The HTTP proxy efficiently handles browser requests through the IBM Firewall, eliminating the need for a socks server for Web browsing. Connection Wizard The Connection Wizard is designed to simplify configuration of common Firewall connections. The wizard is a fast mechanism for building connections while reducing human error. It is provided as an option to users who are inexperienced with filter configuration or who are interested in fast set-up of some of the more typical kinds of filter connections. It can be useful for configuring DMZ Firewalls (or any Firewall with more than two adapters). Lightweight Directory Access Protocol (LDAP) User Authentication The Firewall accesses SecureWay Directory LDAP is used to authenticate the following proxy users: FTP Telnet HTTP Socks The Tivoli SecureWay Policy Director (5698-PDD or 5698-PDI) is not included with Firewall and must be purchased separately. If you do not use the SecureWay Directory, the Firewall uses the local database to authenticate users. To configure the Firewall for LDAP authentication, use the LDAP wizard, which is accessible from the Help menu in the Firewall configuration client GUI. Dynamic Filter for File Transfer Protocol PASV Command (FTP PASV) With PASV FTP data transfers, the client sends a PASV command, and the server performs a passive TCP-open on a random port. The server then informs the client of the port number, and the client does an active-open to establish the connection. IBM Firewall V4.2 supports PASV FTP transfers by monitoring and identifying PASV FTP control connections. Once a control connection has been identified, a dynamic filter rule is defined. The filter rule is removed once transfer ends. AIX Internet Key Exchange (IKE) Support Firewall V4.2 supports IKE tunnels in AIX V4.3.3. IKE is a protocol for automatically and securely exchanging a VPN tunnel s encryption keys. Therefore, it substantially simplifies the configuration and maintenance of VPN tunnels. IKE VPN Client IBM will make available the Ashley Laurent corporation s VPN Client (VPCom Client) for your use. This VPN Client can be installed on Windows 95, Windows 98, and Windows NT Workstations. It can be used to establish an IKE tunnel between the Client and another host running an IKE implementation, such as AIX V4.3.3. Firewall V4.2 running on AIX V4.3.3 supports IKE tunnels configured with this VPN Client. Capabilities No Longer Supported in Firewall V4.2 The limited license Security Dynamics Ace/Server package Triple DES with Key Recovery has been dropped since U.S. export regulations no longer require this capability for Triple DES products with retail export status. Year 2000 This product is Year 2000 ready. When used in accordance with its associated documentation, it is capable of correctly processing, providing, and/or receiving date data within and between the twentieth and twenty-first centuries, provided that all products (for example, hardware, software, and firmware) used with the product properly exchange accurate date data with it. The service end date for this Year 2000 ready product is June 30, 2002. Euro Currency This program is not impacted by euro currency. Reference Information Refer to Software Announcement 299-295, dated September 28, 1999 Trademarks SecureWay is a trademark of International Business Machines Corporation in the United States or other countries or both. AIX is a registered trademark of International Business Machines Corporation in the United States or other countries or both. Windows NT and Windows are trademarks of Microsoft Corporation. Tivoli is a registered trademark of Tivoli Systems, Inc. in the United States or other countries or both. In Denmark, Tivoli is a trademark licensed from Kjobenhavns Sommer -- Tivoli A/S. Other company, product, and service names may be trademarks or service marks of others. 200-181 -2-

IBM US Announcement Supplemental Information June 20, 2000 Offering Information Product information will be available on day of announcement through Offering Information (OITOOL) at: http://www.ibm.com/wwoi Publications No hardcopy publications are shipped with this program. The following publications can be ordered after availability. To order, contact an IBM/Tivoli representative. Title IBM SecureWay Firewall User s Guide for Windows NT IBM SecureWay Firewall Reference for Windows NT IBM SecureWay Firewall User s Guide for AIX IBM SecureWay Firewall Reference for AIX Order GC31-8658 SC31-8659 GC31-8419 SC31-8418 In addition, to download, view, and print the Firewall publications in Portable Document Format (PDF), you can use the IBM Internet Firewall Web site at: http://www.ibm.com/software/security/firewall For printing PDF files, you will need the Adobe Acrobat Reader, which is available through: http://www.adobe.com/prodindex/acrobat/ Displayable Softcopy Publications: The following English and translated publications are offered in softcopy form. The displayable manuals are part of the basic machine-readable material at no additional charge. The files are shipped on the same media type as the basic machine-readable material (CD-ROM). These displayable manuals can be used with the PDF, in conjunction with the ADOBE Acrobat Reader licensed programs, in any of the supported environments to create unmodified printed copies of the manuals. Terms and conditions for use of the machine-readable files are shipped with the files. The following publications are provided, including the translated editions of: IBM SecureWay Firewall User s Guide for Windows NT IBM SecureWay Firewall Reference for Windows NT IBM SecureWay Firewall Setup and Installation for Windows NT IBM SecureWay Firewall User s Guide for AIX IBM SecureWay Firewall Reference for AIX IBM SecureWay Firewall Setup and Installation for AIX The following publications for AIX Firewall are provided in English only: A Secure Way to Protect Your Network: IBM SecureWay Firewall for AIX V4.1 Highly Available IBM enetwork Firewall using HACMP or enetwork Dispatcher A Comprehensive Guide to Virtual Private Networks, Volume 1: IBM Firewall, Servers and Client Solutions The IBM SecureWay Firewall Problem Determination Guide (English only) is available at the following: http://www.software.ibm.com/security/firewall/ A number of additional Redbooks that pertain to the Firewall may be found at the following: http://www.redbooks.ibm.com/ Technical Information Specified Operating Environment Hardware Requirements For Firewall on Windows NT A single, dual, or four-processor Intel Pentium 266 MHz or faster machine. For Firewall on AIX An RS/6000 including the Power Series Family including Symmetric Multiprocessing (SMP) Models. Firewall for both Windows NT and AIX require: A minimum of 64 MB of memory on Windows NT and 128 MB of memory on AIX Approximately 180 MB of free disk space for the following: 90 MB for the base Firewall, Netscape Communicator, Report Utilities, and AIX or Windows NT patches 50 MB for log files Depending on how you configure your Firewall, your storage needs for logs will vary. For example, if you record little data in the log file, you might need as little a 1 MB of log storage per day. However, if you implement a full Socks Firewall, you could need as much as 30 MB per day for log files. Assuming you want to keep seven days worth of logs, this is 210 MB Disk space for logs. A CD-ROM drive for product installation This announcement is provided for your information only. For additional information, contact your IBM representative, call 800-IBM-4YOU, or visit the IBM home page at: http://www.ibm.com. IBM United States IBM is a registered trademark of International Business Machines Corporation. 200-181

Peripheral devices: Mouse, trackball, TrackPoint, or pen. Not all GUI functions can be performed with the keyboard; a pointing device is required. At least two network adapters One adapter connects the secure, internal network that the firewall protects The other network adapter connects the non-secure, outside network or Internet Adapters -- All adapters supported by NDIS including Token Ring and Ethernet (Windows NT only) -- X.25, ATM, FDDI, Token Ring and Ethernet or S/390 (AIX Only) -- These adapters must be supported by the TCP/IP protocol stack IBM modem or Hayes compatible for pager support Supported pager (TAP protocol) Communication hardware interface supported by TCP/IP protocol Software Requirements To install and use the IBM Firewall Version 4.2 for AIX, you must have: AIX/6000 Version 4.3.3.10 or later is recommended and required for VPN functions. Other Firewall functions are supported on AIX/6000 Version 4.3.2.5, or later. Netscape Communicator Version 4.0.7 or later. To install and use IBM Firewall Version 4.2 for Windows NT, you must have the following programs installed: Windows NT Server Version 4.0 Windows NT Service Pack 4, 5, or 6A If using Service Pack 3, then the following Microsoft Corrective service hotfixes should be installed: For ndis_fix, q156655 (required for SMP support) For dns_fix, q169461 (required for DNS support) simptcp_fix, q154460 (improved security) teardrop2_fix, q179129 (improved security) These fixes should be installed in the listed sequence. The English versions of these hotfixes are currently available from Microsoft, Inc. Some hotfixes may not be available for select language versions of Windows NT V4.0. Availability of hotfixes from Microsoft, Inc. may impact Firewall function and security for national language versions of Windows NT. For additional information on Microsoft hotfixes, refer to: http://www.microsoft.com/support Compatibility Security Authentication Devices: You can use IBM Firewall V4.2 with the following security devices to provide remote authentication of your users: Security Dynamics SecurID card Model SD200 PINPAD Packaging Planning Information Both the IBM Firewall V4.2 for Windows NT and the Firewall V4.2 for AIX package includes: One CD-ROM containing: IBM Firewall product Report Utilities Configuration Client English Netscape Communicator The following softcopy publications in all supported languages: -- IBM SecureWay Firewall User s Guide -- IBM SecureWay Firewall Reference -- IBM SecureWay Firewall Setup and Installation The following softcopy publications are in English: -- Guarding the Gates Using the IBM enetwork Firewall for Windows NT -- A Secure Way to Protect Your Network: IBM SecureWay Firewall for AIX V4.1 -- Highly Available IBM enetwork Firewall using HACMP or enetwork Dispatcher -- A Comprehensive Guide to Virtual Private Networks, Volume 1: IBM Firewall, Servers and Client Solution AIX Only: One CD-ROM containing Ashley-Laurent VPN Client code. Note: This code may be delayed awaiting export approval to all industries from the U.S. Department of Commerce, which is expected no later than July 1, 2000. If delayed, a memorandum to customers with instructions for acquiring the code will be included. Proof of License Program License Agreement AIX Only: License Information Booklet Read This First Card Customer Service and Support Page IBM Year 2000 Service Reminder Booklet This program when downloaded from a Web site, contains the applicable IBM license agreement, and License Information (LI), if appropriate, and will be presented for acceptance at the time of installation of the program. The license and LI will be stored in a directory for future reference. Security, Auditability, and Control The security and auditability features of the Firewall V4.2 for Windows NT and AIX include the following: User identification/authentication Secured network Intrusion alarm Error log tracking Report utilities Secured passwords Virtual Private Networks 200-181 -2-

The security and auditability feature unique to Firewall V4.2 for Windows NT and AIX is configuration file checksum monitor. The customer is responsible for evaluation, selection, and implementation of security features, administrative procedures, and appropriate controls in application systems and communication facilities. Ordering Information IBM SecureWay Firewall V4.2 for Windows NT and AIX has a Gateway Install CD-ROM and a per User authorization. A User is an IP Address that sends IP packets through the firewall from the secure side of the Firewall. Customers requiring 500 or more users should order the Unrestricted Users rather than multiple 1 User units. The Firewall units are also available as upgrades for customers licensed for prior IBM Firewall installations, Internet Connection Secure Network Gateway V2 (ICSNG) installations, or non-ibm Firewall installations. The Gateway install program packages and upgrade packages contain CD-ROMs authorized for one user and one install. Customers requiring greater capacity must also order the appropriate number of user installs authorization. Upgrade Entitlements Table from Previous Versions and Non-IBM Firewalls Firewall (FW) FW V4.2 for NT FW V4.2 for NT AIX, V4.2 DES/CDMF Upgrade for NT or AIX, 1 User Unrestricted Upgrade From: or AIX PP Upgrade Upgrade Version 4.1 1 of 4.1 users Version 3 Entry 1 and 24 users Small 1 and 49 users Medium 1 and 249 users Unrestricted 1 and 1 Unres Version 2 1 and 1 Unres Non-IBM Firewalls 1 and 1 Unres Unres = Unrestricted Triple DES will be available as a no charge upgrade to the DES/CDMF program packages. Customers wishing to receive Triple DES upgrades can download the upgrades from the IBM Web site at: http://www.ibm.com/download Part Ordering Information Program Name/Description Firewall V4.2 DES/CDMF for NT Program Package, 1 Gateway Install and 1 user Firewall V4.2 for NT, 1 Gateway Install Firewall V4.2 for NT, 1 User Firewall V4.2 NT Unrestricted Users per Gateway Install Firewall V4.2 DES/CDMF for AIX Program Package, 1 Gateway Install and 1 User Firewall V4.2 for AIX, 1 Gateway Install Firewall V4.2 for AIX, 1 User Firewall V4.2 AIX Unrestricted Users per Gateway Install Firewall V4.2 DES/CDMF for NT, Electronic Software (SW) Distribution Part 11K7929 11K7931 11K7932 11K7933 11K7919 11K7921 11K7922 11K7923 11K5782 Program Name/Description Firewall V4.2 DES/CDMF for AIX, Electronic SW Distribution Firewall V4.2 DES/CDMF for NT Upgrade from V4, V3, V2, or non-ibm Firewalls, Electronic SW Distribution Firewall V4.2 DES/CDMF for AIX Upgrade from V4, V3, V2, or non-ibm Firewalls, Electronic SW Distribution Upgrades Firewall V4.2 DES/CDMF for NT Program Package Upgrade from V4, V3, V2, or non-ibm Firewalls, 1 Gateway Install and 1 User Firewall V4.2 for NT, 1 Gateway Install Upgrade Firewall V4.2, NT User Upgrade Firewall V4.2 for NT Unrestricted Users per Gateway Install Upgrade Firewall V4.2 DES/CDMF for AIX Program Package Upgrade from V4, V3, V2, or non-ibm Firewalls, 1 Gateway Install and 1 User Part 11K5780 11K5783 11K5781 11K7930 11K7934 11K7935 11K7936 11K7920-3- 200-181

Program Name/Description Firewall V4.2 for AIX, 1 Gateway Install Upgrade Firewall V4.2 for AIX, 1 User Upgrade Firewall V4.2 for AIX, Unrestricted Users per Gateway Install Upgrade Media Packs Firewall V4.2 Media Pack AIX CD-ROM Firewall V4.2 Media Pack NT CD-ROM Part 11K7924 11K7925 11K7926 BE6JDML BE78MML Program Name: Firewall V4.2 DES/CDMF Gateway for AIX Program Package Machine Type/Model Ordering Information Current Licensees Current licensees of SecureWay Firewall V4, V3, V2 for AIX or non-ibm Firewalls may order the upgrade from IBM Software Delivery and Fulfillment by specifying the upgrade one-time charge (OTC) feature number and distribution medium feature number from the upgrade table below. New Licensees To order, specify type/model 5697-F48, feature number 9001 for asset registration, and the one-time charge and distribution medium feature numbers from the table below. OTC Medium Order Type Machine Feature Feature Description Type/Model Medium Firewall V4.2 DES/CDMF for 5697-F48 0001 5829 CD-ROM AIX Program Package, 1 Gateway Install and 1 User Firewall V4.2 for AIX 1 Gateway 0002 Install Firewall V4.2 for AIX, 1 User 0003 Firewall V4.2 for AIX 0004 Unrestricted Users Per Gateway Install Media Withdrawal from Marketing Effective January 31, 2001, medium feature number 5819 for Firewall V4.1 for AIX will be withdrawn from marketing of 5697-F48. Upgrades OTC Medium Order Type Machine Feature Feature Description Type/Model Medium Firewall V4.2 DES/CDMF for AIX 5697-F48 1000 5829 CD-ROM Program Package Upgrade from V4, V3, V2, or non-ibm Firewalls, 1 Gateway Install and 1 User Firewall V4.2 for AIX, 1001 1 Gateway Install Upgrade Firewall V4.2 for AIX, 1002 1 User Upgrade Firewall V4.2 for AIX 1003 Gateway Install Upgrade 200-181 -4-

Withdrawal of Previous Passport Advantage Part : The following Passport Advantage part number is being replaced or obsoleted by this announcement. The effective withdrawal date is October 7, 2000. Orders for this part number will not be accepted after the stated effective date of withdrawal, nor will normal marketing activities or educational support be available unless previous agreement exists between the customer and IBM. Program Name/Description Firewall V4.1 Media Pack NT CD-ROM and AIX CD-ROM Part BE6F3NA Select the appropriate feature numbers to customize your order with delivery options desired. These features can be specified on the initial or MES orders. Example: If publications are not desired for the initial order, specify feature number 3470 to ship media only. For future updates, specify feature number 3480 to ship media updates only. If, in the future, publication updates are required, order an MES to remove feature number 3480; then, the publications will ship with the next release of the program. Description Initial Shipments Feature Serial Only (suppresses shipment 3444 of media and documentation) Ship Media Only (suppresses initial 3470 shipment of documentation) Ship Documentation Only (suppresses 3471 initial shipment of media) Update Shipments Ship Media Updates Only (suppresses 3480 update shipment of documentation) Ship Documentation Only (suppresses 3481 update shipment of media) Suppress Updates (suppresses update 3482 shipment of media and documentation) Expedite Shipments Local IBM Office Expedite 3445 (for IBM use only) Customer Expedite Process Charge 3446 ($30 charge for each product) Expedite shipments will be processed to receive 72-hour delivery from the time IBM Software Delivery and Fulfillment (SDF) receives the order. SDF will then ship the order via overnight air transportation. Terms and Conditions Licensing: IBM International Program License Agreement. Proofs of Entitlement (PoE) are required for all authorized use. License Information Form : CT78SML Limited Warranty Applies: Yes Program Services: Available until June 30, 2002 Money-Back Guarantee: 30-day, money-back guarantee Copy and Use on Home/Portable Computer: No Volume Orders (IVO): Yes, contact your IBM representative. Passport Advantage Applies: Yes Passport Advantage Subscription Applies: Yes Upgrades: Customers can acquire upgrades up to the currently authorized level of use of the qualifying programs. Support Line: Yes AIX/UNIX Upgrade Protection Applies: No Entitled Upgrade for Current AIX/UNIX Upgrade Protection Licensees: No AS/400 Software Subscription Applies: No Variable Charges Apply: No Educational Allowance Available: Yes, 15% education allowance applies to qualified education institution customers. Charges Program Program Name/Description Charge Firewall V4.2 DES/CDMF for NT 11K7929 $ 2,079 Program Package, 1 Gateway Install and 1 User Firewall V4.2 for NT Gateway 11K7931 1,999 Install Firewall V4.2 for NT, 1 User 11K7932 32 Firewall V4.2 for NT 11K7933 15,999 Gateway Install Firewall V4.2 DES/CDMF for NT, 11K5782 2,031 1 Gateway Install and 1 User for Electronic SW Distribution Firewall V4.2 DES/CDMF for AIX 11K7919 2,079 Program Package, 1 Gateway Install and 1 User Firewall V4.2 for AIX, 11K7921 1,999 1 Gateway Install Firewall V4.2 for AIX User 11K7922 32 Firewall V4.2 for AIX 11K7923 15,999 Gateway Install -5-200-181

Program Program Name/Description Charge FirewallV4.2 DES/CDMF for AIX, 11K5780 $2,031 Electronic SW Distribution Upgrades Firewall V4.2 DES/CDMF for NT 11K7930 625 Program Package Upgrade from V3, V2, or Non-IBM Firewalls, 1 Gateway Install and 1 User Firewall V4.2 for NT, 11K7934 599 1 Gateway Upgrade Firewall V4.2 for NT, 11K7935 10 1 User Install Upgrade Firewall V4.2 for NT 11K7936 4,799 Gateway Install Upgrade Firewall V4.2 DES/CDMF for NT 11K5783 625 Upgrade from V3, V2, or non-ibm Firewalls, 1 Gateway Install and 1 User for Electronic Software Distribution Firewall V4.2 DES/CDMF for AIX 11K7920 625 Program Package Upgrade from V3, V2, or Non-IBM Firewalls, 1 Gateway Install and 1 User Firewall V4.2 for AIX, 11K7924 599 1 Gateway Upgrade Firewall V4.2 for AIX, 11K7925 10 1 User Install Upgrade Firewall V4.2 for AIX 11K7926 4,799 Gateway Install Upgrade Firewall V4.2 DES/CDMF for AIX 11K5781 625 Upgrade from V3, V2, or non-ibm Firewalls, 1 Gateway Install and 1 User for Electronic Software Distribution Passport Advantage Note: For Passport Advantage charges, contact your IBM Lotus representative or authorized IBM Lotus Business Partner. Additional information is also available on the Passport Advantage: http://www.lotus.com/passportadvantage Order Now Use Priority/Reference Code: YE001 Phone: Fax: Internet: Mail: 800-IBM-CALL 800-2IBM-FAX ibm direct@us.ibm.com IBM Atlanta Sales Center Dept. YE001 P.O. Box 2690 Atlanta, GA 30301-2690 You can also contact your local IBM Business Partner or IBM representative. To identify them, call 800-IBM-4YOU. Note: Shipments will begin after the planned availability date. Trademarks SecureWay and enetwork are trademarks of International Business Machines Corporation in the United States or other countries or both. AIX, RS/6000, TrackPoint, S/390, AIX/6000, and AS/400 are registered trademarks of International Business Machines Corporation in the United States or other countries or both. Pentium is a trademark of Intel Corporation. Windows NT and Microsoft are trademarks of Microsoft Corporation. UNIX is a registered trademark in the United States and other countries exclusively through X/Open Company Limited. Tivoli is a registered trademark of Tivoli Systems, Inc. in the United States or other countries or both. In Denmark, Tivoli is a trademark licensed from Kjobenhavns Sommer -- Tivoli A/S. Lotus is a registered trademark of Lotus Development Corporation. Other company, product, and service names may be trademarks or service marks of others. Year 2000 Readiness Disclosure Statements made in this announcement regarding Year 2000 are Year 2000 Readiness Disclosures under the Year 2000 Information and Readiness Disclosure Act of 1998, a U.S. statute enacted on October 19, 1998. Customer Financing: IBM Global Financing offers attractive financing to credit-qualified commercial and government customers and Business Partners in more than 40 countries around the world. IBM Global Financing is provided by the IBM Credit Corporation in the United States. Offerings, rates, terms and availability may vary by country. Contact your local IBM Global Financing organization. Country organizations are listed on the Web at: http://www.financing.ibm.com 200-181 -6-