SWIFTNet Online Operations Manager

Similar documents
Connectivity. SWIFTNet Link 7.0. Functional Overview

Acronis Backup & Recovery 11.5 Quick Start Guide

Connectivity. Alliance 7.0. Alliance Interfaces. FileAct support in SWIFTNet Release 7.0

Service Description. 3SKey. Connectivity

SWIFTReady for Corporates Cash Management

Contents Overview of RD Web Access What is RD Web Access?... 2 What are the benefits of RD Web Access versus thin client?...

novdocx (en) 11 December 2007 XIII XIIIMonitor


F-SECURE MESSAGING SECURITY GATEWAY

Virtual Appliance Setup Guide

F-Secure Messaging Security Gateway. Deployment Guide

Cyberoam Virtual Security Appliance - Installation Guide for XenServer. Version 10

Using SolarWinds Orion for Cisco Assessments

Connectivity. Alliance Access 7.0. Database Recovery. Information Paper

Connectivity. Alliance Access 7.0. Database Recovery. Information Paper

Personal Token Software Installation Guide

RSA Authentication Manager 7.1 Basic Exercises

EMC Data Domain Management Center

SWIFT Certified Application Payments

SWIFT Certified Specialist - Consultancy for Trade and Supply Chain Finance Track Criteria

How to configure the TopCloudXL WHMCS plugin (version 2+) Update: Version: 2.2

Installation Guide. Version 1.5. May 2015 Edition ICS Learning Group

Hillstone StoneOS User Manual Hillstone Unified Intelligence Firewall Installation Manual

VMUnify EC2 Gateway Guide

Pass Through Proxy. How-to. Overview:..1 Why PTP?...1

Installation Guide. SafeNet Authentication Service

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

Customer Testing Policy

SMART Vantage. Installation guide

Connection Broker The Leader in Managing Hosted Desktop Infrastructures and Virtual Desktop Infrastructures (HDI and VDI) DNS Setup Guide

DameWare Server. Administrator Guide

WhatsUp Gold v16.3 Installation and Configuration Guide

Alliance Access Integration Automated File Transfer

Alliance Access Integration SOAP Host Adaptor

F-Secure Internet Gatekeeper Virtual Appliance

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Setting Up a Unisphere Management Station for the VNX Series P/N Revision A01 January 5, 2010

Test Case 3 Active Directory Integration

How to Configure Active Directory based User Authentication

Connection Broker Managing User Connections to Workstations, Blades, VDI, and More. Quick Start with Microsoft Hyper-V

WhatsUp Gold v16.2 Installation and Configuration Guide


Multimedia Contact Center Setup and Operation Guide. BCM 4.0 Business Communications Manager

CA Nimsoft Monitor. Probe Guide for URL Endpoint Response Monitoring. url_response v4.1 series

Installation and Deployment

Interworks. Interworks Cloud Platform Installation Guide

Quick Start Guide: Iridium GO! Advanced Portal

Installing and Configuring vcloud Connector

NSi Mobile Installation Guide. Version 6.2

Web Application Firewall

User Guide & Implementation Guidelines for using the Transaction Delivery Agent (TDA) 3.0

Name Services (DNS): This is Quick rule will enable the Domain Name Services on the firewall.

Electronic Bank Account Management - EBAM

CA arcserve Unified Data Protection Agent for Linux

WebSpy Vantage Ultimate 2.2 Web Module Administrators Guide

Application Notes for Multi-Tech FaxFinder IP with Avaya IP Office Issue 1.0

Setting Up Scan to SMB on TaskALFA series MFP s.

Nimsoft Monitor. dns_response Guide. v1.6 series

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

Web Security Firewall Setup. Administrator Guide

WatchDox for Windows User Guide. Version 3.9.0

Virtual Web Appliance Setup Guide

3M Command Center. Installation and Upgrade Guide

Copyright 2012 Trend Micro Incorporated. All rights reserved.

Cloud Authentication. Getting Started Guide. Version

Installation Guide For Choic Enterprise Edition

Alliance Access Integration MQ Host Adaptor

Administering the Web Server (IIS) Role of Windows Server


WHMCS LUXCLOUD MODULE

Active Directory Self-Service FAQ

Server Installation Guide ZENworks Patch Management 6.4 SP2

Lab - Observing DNS Resolution

How to Secure a Groove Manager Web Site

ArcMail Technology Defender Mail Server Configuration Guide for Microsoft Exchange Server 2003 / 2000

RSA Authentication Manager 8.1 Virtual Appliance Getting Started

Cisco Collaboration with Microsoft Interoperability

WhatsUp Gold v16.1 Installation and Configuration Guide

Cisco UCS Director Payment Gateway Integration Guide, Release 4.1

Salesforce Integration

Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice.

Virtual Appliance Setup Guide

Job Management Partner 1/IT Desktop Management 2 - Asset Console Description

Hyper-V Server 2008 Setup and Configuration Tool Guide

PineApp Surf-SeCure Quick

WatchDox for Windows. User Guide. Version 3.9.5

Configuring PPP And SIP

EMC Data Protection Search

Ocularis Media Server Installation & Administration Guide

Quick Start Guide. for Installing vnios Software on. VMware Platforms

A Guide to New Features in Propalms OneGate 4.0

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

Introduction to Mobile Access Gateway Installation

AusCERT Remote Monitoring Service (ARMS) User Guide for AusCERT Members

Technical Notes. EMC NetWorker Performing Backup and Recovery of SharePoint Server by using NetWorker Module for Microsoft SQL VDI Solution

Abila MIP Mobile. System Requirements

IP Office - Job Aid Remote Access

Acronis Backup & Recovery 11

1 You will need the following items to get started:

SuperLumin Nemesis. Administration Guide. February 2011

Transcription:

Messaging SWIFTNet 7.0 SWIFTNet Online Operations Manager Quick Overview December 2010

Table of Contents Preface... 3 1 Introduction... 4 1.1 Background... 4 1.2 SWIFTNet Online Operations Manager... 4 2 Functionality overview... 5 3 How to get access... 7 3.1 Available to all customers... 7 3.2 Specifying the URL... 7 3.3 Netwk configuration... 7 3.4 Netwk setup checks... 7 3.5 Browser settings... 8 3.6 System requirements... 8 4 Access control... 9 5 User Guide... 11 Legal Notices... 12 SWIFTNet Online Operations Manager Quick Overview 2

Preface Purpose of this document This document provides an overview of the SWIFTNet Online Operations Manager functionality, including infmation on how to access the service and the required netwk setup. Intended audience This document is intended f security officers, SWIFTNet project managers and customers responsible f operating the SWIFTNet environment. Related documentation SWIFTNet 7.0 Release Overview SWIFTNet Messaging Service Description SWIFTNet Messaging Operations Guide SWIFTNet Online Operations Manager Quick Overview 3

1 Introduction 1.1 Background SWIFT provides the ability f customers to manage their SWIFTNet security and routing online. Befe SWIFTNet 7.0, customers required an application such as the Alliance WebStation to administer their certificates, roles and routing rules. 1.2 SWIFTNet Online Operations Manager SWIFTNet 7.0 introduced the SWIFTNet Online Operations Manager. This service allows customers to administer their security and routing through a new SWIFT-managed service available over Browse. This service offers access to the same functionality as the GUI on the Alliance WebStation. In addition, this new service will also enable various new security features (See the SWIFTNet 7.0 Release Overview, sections 5.14 through 5.23, the SWIFTNet Service Description and SWIFTNet Operations Guide) Note that most of this new functionality is only available by accessing the new Browse service. The existing Users and Routing module of Alliance WebStation are no longer available in Alliance WebStation 7.0. As f any other Browse service, customers require the Alliance WebStation the Web Platfm to access the SWIFTNet Online Operations Manager. However customers do not need to upgrade their Alliance WebStation (release 6.x) Web Platfm (release 6.x) in der to be able to use this new Browse service (and thus the new functionality). This means that customers can start using this functionality at any time. SWIFTNet Online Operations Manager Quick Overview 4

2 Functionality overview The SWIFTNet Online Operations Manager provides the same functionality f certificate management, role management and routing management that was available in the WebStation's "Users" and "Routing" modules. In addition, it provides some new functions as well. Here is a brief overview of the main new functionality (f me infmation, see the online help the User Guide): (items indicated with * become available during the course of December 2010) Certificate Management ability to recover SNL certificates online addition of certificate expiry date in the node details screen ability to get the details of multiple nodes at the same time search capability on node name to easily find an entry in the tree ability to limit the scope of a Security Officer to a branch in the tree ability to delete nodes from the tree print the naming tree node details part of the screen ability to add a free-fmat description f any user * availability of an advanced search based on certificate parameters on user's roles * Role Management ability to get the details of multiple nodes at the same time search capability on node name to easily find an entry in the tree ability to limit the scope of a Security Officer to a branch in the tree ability to manage a group of nodes at once (group grant, group ungrant, role copy) quick view of all roles that a user has (and print this screen) print the naming tree node details part of the screen availability of an advanced search based on certificate parameters on user's roles * 4eyes authisations When the second Security Officer receives the 4eyes token from the first Security Officer, the application will present the changes made by the first Security Officer and the second can approve. Routing management ability to select individual routing rules (f reroute enable/disable operation) print routing rules ability to save selection parameters f later use * Repts certificate rept: allows to generate an up-to-date list of all certificates of your institution including their details (name, type, status, expiry date). certificate rept: option to list all certificates that will expire soon * role rept: allows to generate an up-to-date list of all users and the roles they have, across all services. Lists each time the relevant details (such as qualifier infmation). activity log: allows to generate a rept that lists all changes perfmed with regards to certificate, role routing management, as well as login and logouts to the SWIFTNet Online Operations Manager. all repts allow to save rept parameters f later use * ability to schedule automatic repts, f delivery via e-mail FileAct * SWIFTNet Online Operations Manager Quick Overview 5

Administration e-mail management: define e-mail addresses that can be used when scheduling automated repts * General ability to avoid inadvertent changes by giving appropriate read-only access * SWIFTNet Online Operations Manager Quick Overview 6

3 How to get access 3.1 Available to all customers All SWIFT customers can access the SWIFTNet Online Operations Manager, no specific subscription is required. To access the SWIFTNet Online Operations Manager, ensure that: you have the ability to access a Browse service (this means either through the Browse module of Alliance WebStation through the use of Alliance WebPlatfm) you know the URL of the service your netwk allows access to the service. The above points will allow you to access the Browse service. In addition, you need one me roles that allow you to access the functionality, that this, the menu options of the application. See the section "Access Control" below f me infmation. The current functionality (mainly certificate and role management) is available at no extra charge. The usage of these functions is included in the SWIFTNet PKI charges. 3.2 Specifying the URL The URL f the Browse service SWIFTNet Online Operations Manager on the production environment is as follows: https://www.o2m.swiftnet.sipn.swift.com. Developers who have access to the Integration TestBed (ITB) need to use the following URL: https://www.o2m-itb.swiftnet.sipn.swift.com. 3.3 Netwk configuration Like f any Browse service, customers need to ensure that their netwk setup (typically firewalls) allows to reach the web server. Customers that configure their netwk infrastructure to allow outgoing TCP sessions to the subnet range 149.134.0.0 /17 on destination TCP pt 443 (HTTPS), do not need any specific setting. Indeed, this range includes, amongst others, the IP addresses of SWIFT-operated Browse services. Customers using stringent security policies may require to configure a list of specific IP addresses. In this case, the filtering policy of the Browse customer's firewall must allow the following routes: Source Destination Host Pt Host Pt Client > 1023/tcp 149.134.126.33 443/tcp Client > 1023/tcp 149.134.127.33 443/tcp F me infmation on netwk configuration, and f details related to the Integration Testbed (ITB) environment, please refer to the Netwk Configuration Tables Guide. 3.4 Netwk setup checks You can check if your netwk setup is crect as follows: 1) check the DNS (Domain Naming Service) You can run the nslookup command on your local machine: - click "Start", "Run...", type cmd (a window opens) - type nslookup command as follows: nslookup www.o2m.swiftnet.sipn.swift.com Server: <DNS server name> Address: <DNS server IP address> SWIFTNet Online Operations Manager Quick Overview 7

Name: NLCBSL-GUA.swiftnet.sipn.swift.com ( USCBSL-GUA.swiftnet.sipn.swift.com) Address: 149.134.127.33 ( 149.134.126.33) Aliases: www.o2m.swiftnet.sipn.swift.com 2) check the DNS and the ability to reach the Browse server : Run the checkip command, the results should be similar to the following output: checkip www.o2m.swiftnet.sipn.swift.com 443 ------------------------------------------------------------------------------ Results of tests will be available in "C:\Users\SNLOwner\AppData\Local\Temp\2\checkip_1274881604_4976.out" ------------------------------------------------------------------------------ Execution Started : Wed May 26 09:46:44 2010 Hostname : <hostname> - [www.o2m.swiftnet.sipn.swift.com 443 TCP] : FULL_SUCCESS ============================================================================ Host IP : 149.134.127.33 ( 149.134.126.33) Result : FULL_SUCCESS Total Time : 32 ms ============================================================================ 3.5 Browser settings Because the SWIFTNet Online Operations Manager is a Browse service on SWIFTNet, you need to ensure your browser settings are crectly set. Please refer to the Browse Implementation Guide f the details, especially chapters 4 and 5. 3.6 System requirements Make sure your system satisfies the minimum system requirements f the interface software you are using (Alliance WebStation Alliance WebPlatfm). Also, the desktop where your run the browser that accesses the SWIFTNet Online Operations Manager should at least be "Intel Ce Duo CPU" based ( equivalent) and have sufficient memy to ensure good perfmance, preferably 3GB me. If you run on the same system other applications at the same time, then ensure that the total amount of memy is sufficient to also run these other applications. SWIFTNet Online Operations Manager Quick Overview 8

4 Access control Customers need (RBAC) roles to be able to access specific functionality provided through the SWIFTNet Online Operations Manager. If a customer has no roles to access the service, an err message will be displayed. If a customer has one me roles, then the cresponding menu options will become available. Menu options f which the customer does not have the necessary role, will be greyed out. The following is a summary of the menu options and the roles needed (f full details, see the User Guide): Menu option Certificate Management - User Certificate Management - SNL Certificate Management - Web Role Management 4eyes Authisation Routing Rules Management Certificate rept Role rept Role(s) needed SWIFT.LRA//CertificateAdministration SWIFT.LRA//CertificateAdministration4eyes SWIFT.LRA//LiteCertificateAdministration SWIFT.LRA//Viewer SWIFT.LRA//SnlCertificateAdmin SWIFT.LRA//SnlCertificateAdmin4eyes SWIFT.LRA//Viewer SWIFT.LRA//CertificateAdministration SWIFT.LRA//CertificateAdministration4eyes SWIFT.LRA//Viewer SWIFT.RBAC//Nmal User SWIFT.RBAC//Viewer SWIFT.RBAC//Delegat SWIFT.RBAC//Delegat4eyes SWIFT.RBAC//DelegatPilot SWIFT.LRA//CertificateAdministration SWIFT.LRA//CertificateAdministration4eyes SWIFT.LRA//SnlCertificateAdmin SWIFT.LRA//SnlCertificateAdmin4eyes SWIFT.RBAC//Delegat SWIFT.RBAC//Delegat4eyes SWIFT.RUG//SiteManager SWIFT.RUG//PilotSiteManager SWIFT.RUG//LiveSiteManager SWIFT.RUG//Viewer SWIFT.LRA//CertificateAdministration SWIFT.LRA//CertificateAdministration4eyes SWIFT.LRA//SnlCertificateAdmin SWIFT.LRA//SnlCertificateAdmin4eyes SWIFT.LRA//LiteCertificateAdministration SWIFT.LRA//Viewer SWIFT.RBAC//Viewer SWIFTNet Online Operations Manager Quick Overview 9

Activity log SWIFT.RBAC//Delegat SWIFT.RBAC//Delegat4eyes SWIFT.RBAC//DelegatPilot SWIFT.RBAC//Audit SWIFT.LRA//Audit SWIFT.RUG//Audit SWIFTNet Online Operations Manager Quick Overview 10

5 User Guide SWIFT provides both an on-line help as well as a User Guide f the SWIFTNet Online Operations Manager. The on-line help can be accessed through a link at the top right cner of the screen. The SWIFTNet Online Operations Manager User Guide is part of the User Handbook that customers can access through swift.com SWIFTNet Online Operations Manager Quick Overview 11

Legal Notices Copyright SWIFT 2010. All rights reserved. You may copy this publication within your ganisation. Any such copy must include these legal notices. Confidentiality This publication contains SWIFT third-party confidential infmation. Do not disclose this publication outside your ganisation without the pri written consent of SWIFT. Disclaimer The infmation in this publication may change from time to time. You must always refer to the latest available version on www.swift.com. Translations The English version of SWIFT documentation is the only official and binding version. Trademarks SWIFT is the trade name of S.W.I.F.T. SCRL. The following are registered trademarks of SWIFT: SWIFT, the SWIFT logo, Sibos, SWIFTNet, SWIFTReady, and Accd. Other product, service, company names in this publication are trade names, trademarks, registered trademarks of their respective owners. SWIFTNet Online Operations Manager Quick Overview 12