June 5, 2026 | IBM i

The IBM i Firewall Checklist

image

Create a programmable IBM i-based firewall with exit point management 

 

This post provides a checklist for enabling cyberthreat protection controls on IBM i systems. It provides a framework for building a programmable IBM i firewall for advanced user access security, monitoring, and reporting capabilities.  

 

IBM i cyberthreat protection, exit point management, and firewalls 

IBM i Cyberthreat Protection uses exit points and exit programs to control access to system services. 

 

Exit points are hooks built into IBM i system interfaces that allow custom programming (exit programs) to intercept, allow, deny, modifyor restrict access to IBM i services, such as FTP, ODBC/JDBC, SQL, and DDM/DRDA. 

 

Exit point management allows security professionals to build an IBM I firewall using exit programming, where advanced security, monitoring, and reporting controls are built directly into operating system functionality. 

 

Related: The IBM i Cybersecurity Protection Checklist 

 

The IBM iFirewall Checklist  

An IBM i firewall consists of the accumulated cyberthreat protection controls enabled through exit point management. Exit point managers provide administrative interfaces, dashboards, access rule templatesfilters, and other mechanisms to regulate i firewall access through the exit programming process. Organizations can implement an IBM i firewall by reviewing these checklist items for exit point management. 

 

  1. Understanding how IBM i exit point management works 
  2. Creating an IBM i firewall framework for exit point management 
  3. Implementing IBM i firewall protections for common remote access scenarios 
  4. Continually monitoring, reporting, and expanding firewall protections 

 

Understand how IBM i exit point management works 

Exit point management is a foundational component in building an IBM i firewallExit points are a simple mechanism that does the following when an IBM i function is called. 

 

  1. A user or an application initiates a request for IBM i access, such as an FTP logon request. 
  2. The request is intercepted and hooked into an exit point associated with the transaction. For FTP logons, the exit point name is QIBM_QTMF_SVR_LOGON.  
  3. All relevant request details are passed to any exit programs associated with the exit point. Exit programs are custom-written code created internally by the organization or produced externally by vendors, consultants, or included with vendor-supplied applications. 
  4. Exit programs provide access rules that allow, deny, modify, or provide additional functionality when IBM i operating system requests are being processed. 

Related: Using Exit Point Programming to Control IBM i Access. 

 

 

Creating an IBM i Firewall Framework for Exit Point Management

Many organizations use DIY programming and IBM i commands such as the Work with Registration Information (WRKREGINF) command to attach exit programs to exit points. You can use DIY exit programming to create an IBM i firewall one exit point at a time within your existing application infrastructure. However, DIY exit programming can be intensive and prone to a number of risks including disabling system access, creating system vulnerabilities, ransomware & virus exposure, and allowing cyberattacks on your system. It can also be time-consuming and slow-to-deploy as new program functionality must be created from scratch for every exit point function you want to provide advanced capabilities for. 

 

A better, more efficient way to provide IBM i firewall functionality is to use an exit point management solution such as iSecurity Firewall. Exit point managers provide administrative interfaces, dashboards, access rule templatesfilters, and other mechanisms to regulate i server access. Exit point managers abstract exit programming providing out-of-the-box IBM i security, intrusion protection, and firewall capabilities that can be easily managed by security professionals instead of application developers. Exit point managers can also provide monitoring, alerting, and reporting capabilities for detecting and documenting unauthorized access, security violations, and cyberattacks. 

 

To build an IBM i firewall, SEA recommends using a vendor-supplied exit point management solution like iSecurity Firewalinstead of using DIY programming. Vendor-supplied exit point management capabilities are pre-tested, hardened, and easier to deploy than creating your own DIY solutions. 

 

Table 1 Select an Exit Point Management approach for creating your IBM i firewall 

 

Related reading: Building an IBM i Firewall using Exit Points. 

 

Implementing IBM i firewall protections for common remote access controls 

Once an IBM i exit point management framework is in place, organizations can start creating i server firewall capabilities. Start with implementing exit point controls for the most common and vulnerable remote access scenarios and add more controls as needed. Common exit point controls for firewall-like security include the items listed in Table 2Note: This table lists exit point management found in iSecurity Firewall as a proxy for the controls provided by third-party exit point management programs. 

 

When using DIY exit programming, custom-written programs must be attached to exit points. When using exit point management solutions for your IBM i firewall, look for and configure the exit point manager configurations listed here to control access. 

 

Table 2: Starter options for implementing IBM i firewall controls 

 

Continually monitoringreporting, and expanding firewall protections 

Whether you use DIY exit programming or an exit point management solution such as iSecurity Firewall, your firewall solution must contain options for creating and viewing queries, reports, and logs. These items are central not only for firewall evaluation and security monitoring; they are necessary for regulatory and auditor stakeholder compliance reporting. Consider the following items as you implement your IBM i firewall framework. 

 

 

Learn more about IBM i Cybersecurity and Firewalls 

Use this IBM ifirewall checklist to better understand and improve your cyberthreat attack posture. If you’d like to learn more about IBM i cybersecurity in enterprise environments, please contact us at SEA. We’ll be glad to discuss your IBM i cybersecurity needs and how to safely satisfy your data and compliance requirements.