IBM Sterling Ecosystem

IBM Sterling Secure Proxy Services

Perimeter and DMZ security for partner connectivity into IBM Sterling B2B Integrator — architecture, configuration, modernization, and support.

Where it fits

The perimeter layer

IBM Sterling Secure Proxy sits in the DMZ and terminates inbound partner connections before they reach the internal network. Session break, protocol inspection, and credential handling happen at the perimeter, so IBM Sterling B2B Integrator and Sterling File Gateway are never directly exposed to partner traffic.

It is a security control rather than an integration engine. Its configuration follows from decisions made about the IBM Sterling B2B Integrator environment behind it: which protocols partners use, how credentials are stored, and what the inbound and outbound paths look like.

Services

Secure Proxy work is architecture-led and change-controlled.

Secure architecture

DMZ topology, engine and configuration manager placement, firewall rule design, and inbound and outbound flow definition.

Configuration

Adapter definitions, netmap and policy configuration, protocol termination for SFTP, FTPS, HTTPS, and Connect:Direct, and certificate handling.

Modernization

Version upgrades, migration away from unsupported releases, and alignment with current TLS and key-exchange requirements.

Operational support

Connection failure analysis, certificate operations, partner troubleshooting, and release support.

Authentication integration

Integration with Sterling External Authentication Server for certificate validation and extended authentication.

Monitoring

Visibility into perimeter connection health through IBM Control Center Monitor.

Common failure patterns we resolve

Perimeter issues are rarely reported as perimeter issues.

  • Partner connections failing after a certificate or cipher change at either end
  • Netmap and policy definitions that drifted from the internal environment after a migration
  • Credential handling that blocks key rotation without partner downtime
  • Upgrades deferred so long that a supported path requires an intermediate step
  • DMZ rules that permit more than the exchange actually requires

Review Your Perimeter Design

A short review usually identifies configuration drift and unsupported versions quickly.