VPN, in plain English
A VPN is a private tunnel across the public internet.
Think of the internet as a busy high street. Without a VPN, your staff walk that street carrying the company keys. Anyone standing nearby can watch. With a VPN they go through a locked corridor. Same destination. Far fewer strangers.
That is all a VPN is: prove who you are, then send the traffic through an encrypted pipe so hotel Wi-Fi, home broadband and the public internet cannot read it.
How you will use it
You are moving a physical IBM i system into a cloud Power environment. The programs can stay as they are. The box will no longer sit in your own room.
Staff will still need to sign on, run the green screen, look at files and use the same tools they use today. They should not do that by typing a public address into the internet. The cloud system should stay private, like the old locked rack.
So the working day looks like this:
- The person starts the company VPN (from a laptop, or the office network does it for them).
- The laptop is now on your private road.
- They open the usual IBM i tools and work as before.
Office staff can have a permanent link from the building. Home and travelling staff connect when they need to. When someone leaves, you switch their VPN access off.
What it does not do
A VPN is not antivirus. It does not replace passwords, backups, or good IBM i user control. It is the front gate. You still lock the filing cabinets inside.
“Free VPN” apps from a phone store are for hiding a laptop on cafe Wi-Fi. They are not the design for payroll. You want a proper business VPN with named users, a second factor at login, and someone to call if the tunnel fails on a Thursday.
The one sentence version
Staff connect to the company tunnel first. Then they use IBM i. The system never sits on the open/insecure internet.
That is how you keep the move to the cloud from becoming a new way to leave the door open.
Do I need to use VPN? If so, which one? Is it Free? And other questions…
If you are moving a physical Power System to a cloud IBM i partition, someone will eventually say “we can just use a free VPN for connection” That sentence mixes up two different products. One is a consumer app for hiding a laptop on public Wi-Fi. The other is the private road your payroll system will travel on. This is the short version for people who sign the cheque.
What a VPN actually is
VPN means virtual private network. In plain English: an encrypted tunnel across a network you do not own, usually the public internet.
Without a tunnel, a laptop in a hotel talks to your IBM i addresses in the open. With a tunnel, that laptop (or the office firewall) first proves who it is, then all the IBM i traffic rides inside an encrypted pipe to a private network. Access Client Solutions, 5250, SQL and IFS then see private addresses, as if the LPAR was still in your computer room.
That last point matters on IBM i. Green screen, Navigator, Run SQL Scripts and IFS are not one website on port 443. They open a set of host server ports. A VPN is how you avoid publishing that whole set to the world.
A VPN is not antivirus, not a backup, and not a replacement for IBM i user security. It is the fence around the field.
Two things people call “VPN”
Consumer VPN.
An app on a phone or laptop that sends your traffic through someone else’s server so coffee-shop Wi-Fi is less ugly. Fine for a sales director on a train. Useless as the design for production IBM i.
Business VPN.
A site-to-site or client-to-site service that joins your office and your approved laptops to your cloud network (for example IBM Cloud VPC, then into Power Virtual Server). Users connect, then ACS points at a private IP. This is the one that belongs in the migration design.
If the proposal is “download a free app and type the public IP of the LPAR,” that is not a design. That is hope.
Free versus commercial
| Free / DIY | Commercial / enterprise | |
|---|---|---|
| What you get | A consumer app, or software such as OpenVPN or WireGuard that your team builds | A supported service: IBM Cloud VPN, a firewall vendor, or a managed SASE product |
| Who it is for | Individuals, labs, a proof of concept | Production IBM i, auditors, home workers, suppliers |
| Cost | Licence looks free. Staff time, outages and incidents are not | Subscription or appliance plus support. Predictable |
| SLA and support | None you can put in a contract | Named support, uptime targets, someone to ring at 2 a.m. |
| Identity | Shared password if you are lucky | MFA, SSO, named users, revoke a leaver in one place |
| Audit | Little or no usable log | Connection logs you can show an auditor |
| IBM i fit | Rarely speaks site-to-site into PowerVS the way IBM documents it | Site-to-site for the office, client VPN for laptops, routing into the Power workspace |
| Risk | Free consumer VPNs have a long history of logging, selling data, or simply vanishing. DIY means you own every certificate and every CIDR typo | You pay for a grown-up boundary. You still own IBM i profiles and *PUBLIC authorities |
Open source tools are excellent components. They are not a free operations department. If you have network engineers who already run strongSwan or WireGuard properly, that can be a commercial-grade answer with a free licence. Most IBM i shops do not have that spare capacity. They have a cutover date.
What I tell the client in the room
Use a commercial path that IBM already documents for Power Virtual Server: VPN into VPC, then into the Power workspace. Client VPN for people with ACS on a sofa. Site-to-site for the office that needs the LPAR all day. MFA on the VPN login. Keep the IBM i partition off the public internet.
If someone offers a free consumer VPN as the production design, smile, thank them, and ask who is on the hook when the tunnel dies on payroll Thursday.
The applications can stay on IBM i. The rack can go to the cloud. The path in should not be the cheapest app in the store.
Until next time, keep those IBM i systems humming. And keep port 23 off the internet.
