Axway
Axway
Transfer
Insights & Best
Practices
David Butcher, PMP CSDP
Sr. Systems Engineer
Agenda
Axway/Tumbleweed Snapshot
File Transfer Overview
Evolution
Challenges & Drivers
What is Managed File Transfer?
Best Practices
Q&A
Early Connectivity
Dial-up connections – Async, Bisync
Dedicated links – FrameRelay
Value Added Networks - VANs
Enter the Internet
FTP becomes the de facto standard for file transfer
Available on every platform, easy to code into scripts
The tool of choice for application-to-application connectivity
Evolving Solutions
Variety of enhanced secure file transfer products
Open standards / open protocols
FTP, HTTP, SSL/TLS, SSH, PGP, S/MIME, EDIINT AS2 and AS3.
Managed File Transfer Solutions
Exterior Interior
Users Pick-up
Firewall Firewall
Files Staged in
the DMZ DMZ Have to Stage
files to the DMZ
DMZ FTP FTP server
User Credentials
Users Drop-off Have to Retrieve
Data Files
Files in the DMZ the files from the
DMZ FTP server
FTP/S
FTP over SSL/TLS
SSH – Secure Shell
SFTP – SSH File Transfer Protocol or Secure FTP
SCP – SSH protected remote copy
Leverages SSH Protocol
Encryption and Authentication
AS2
AS2 - Applicability Statement 2
HTTP Based, Can Use SSL
Encryption, Data Integrity, Signatures, Receipts
Server initiates all connections
Associated With EDIINT – Can Send Any Data
Outgrown/Limited
Existing Systems
© 2008 Axway Inc.
File Transfer Drivers
Data Protection & Security
HIPAA
GLBA SEC 17a-4 &
NASD 3010
FDA 21 CFR
Part 11
Payment Card
Industry (PCI) Data
USA Patriot Act Security Standard
© 2008 Axway Inc.
File Transfer Drivers
Outgrown Existing/Limited Systems
Internal Partners
Increasing scrutiny from Partners and customers
Chief Security Officer require electronic
(CSO) transfers
Facilitates need to SLA enforcement
prove data exchange
activity/ security with Did our partner/vendor
reporting, logging and deliver the data on
auditing schedule?
Physical medium file 67% of CIOs surveyed
transfers are gone reported more than
20% of their file
Corporate reputation – transfers are tied to
remember TJX SLAs – SC Magazine
Enforcement of (Jan. 2008)
corporate policies
Each business unit
deploying point solutions
Efficiency – savings
achieved through
automation &
consolidation
© 2008 Axway Inc.
Managed File Transfer ( MFT )
According to Gartner
Back end automation – getting the data to the systems that are
consuming it and from the systems that produce it
File moves and copies
File level encryption
PGP during transport
Encrypted file system during storage
Email notifications on successful transfers and failures
Framework for custom transforms – event drive
Send Email
File Dropped off Notification of Encrypt file and
PGP Decrypt File
At the Server File Arriving Store to Disk
Successfully
File
Notifications Repository
External Enterprise
Partners
DMZ
`
Internal User
FTP Server
HTTP(S), FTP(S)
SFTP, SCP, AS2
MFT Server
`
Application
User Servers
External Enterprise
Partners
DMZ `
Internal User
FTP
Server HTTP(S), FTP(S)
SFTP, SCP, AS2
MFT MFT
` Proxy Server
Application
User
Servers
Internal
MFT User
Proxy MFT
DMZ ` Server
External
`
User
Shared
File
HTTP(S), FTP(S) Storage
SFTP, SCP, AS2
Load Load
Balancer Balancer MFT
Remote Server
MFT
File Proxy
Transfer Application
Server Enterprise Servers
Authentication
Single factor
Passwords
Certificates
Multi factor
Authentication database local to solution
Integrating with existing authentication databases
(LDAP/AD/SSO)
X.509 Certificate
MFT
SSH Key
Client Server
` User ID / Password
Client
Two Factor
`
Logging
Granular
All file transfers recorded – who, what and
when
All access recorded
Integrity
Protected from outsiders – out of the DMZ
Protected from insiders – digitally signed
Access
Log
`
MFT MFT
Audit
Proxy Server Log
www.tumbleweed.com
www.axway.com
[email protected]
877 282-7390