ObjectSecurity Home Services News+Events Customers+Partners Industries Contact
OpenPMF 2.0 Model Driven Security Management
Products  ObjectWall - IIOP domain boundary protection : Technical features
OpenPMF 2.0Secure CORBA & CCMSimulateWorld 4DSINS middleware

ObjectWall IIOP firewall comes in two different editions: The stand-alone Professional Edition and the OpenPMF-enabled Enterprise Edition.

ObjectWall Enterprise Edition supports more advanced access control features, and uses the OpenPMF policy management framework, which supports the flexible enforcement of access control on the firewall based on a unified policy (stored in a central repository together with policies for other systems).

ObjectWall Professional Edition is a stand-alone edition that does not require advanced setup or any services except interface repository.

Both editions include the following features:

Full IIOP firewall traversal: ObjectWall supports firewall traversal by rewriting passed object references. It uses the interface repository to be able to traverse complex CORBA types passed as request parameters. In this way, ObjectWall “compresses” an entire CORBA application behind the firewall into one or a few TCPIP (or TLS) entry points to the application.

Application Integration: ObjectWall is transparent to the applications, so no changes are required to the application logic except a small addition to the initial service bootstrap. The proxy fully supports call-backs and call reverse processing.

Vendor independence: ObjectWall is built on the MICO open source CORBA 2.3 implementation, which was branded "CORBA-compliant" by the OpenGroup. Hence the proxy itself uses the CORBA-compliant GIOP/IIOP engine which ensures seamless interoperability with other IIOP-based products.

Multi-home support: ObjectWall supports multi-home firewall machines and makes sure that the rewritten object reference is accessible on all outer or inner network interfaces (for call-backs by clients).

TLS transport layer support: ObjectWall supports TLS/SSLIOP protocol outside the perimeter from the client to the outer interface(s), internally between target(s) and inner interface(s), or for the entire system communication.

NAT support: ObjectWall supports NAT, an important requirement for many network topologies.

Built-in Interface Repository (IR): The interface repository is normally required by the proxy to run. However, to also support the setup without the interface repository and improve performance, the proxy itself might be started with the built-in interface repository enabled.

O(1) object scalability: Only one CORBA object is created on the proxy server for all traversed objects of the same type, which results in excellent scalability and low memory requirements when traversing/serving many CORBA objects.



      

Copyright (c) 2000-2008 ObjectSecurity - all rights reserved - copyright & terms of use - site map overview - webmaster