I am in the middle of helping a client lift a physical Power System out of the computer room and onto a cloud IBM i partition. Same workloads. Same legacy ERP system (RPG, CL and AS400 style physical files) that have paid the bills for years. The transition should be seamless to the end users. It’s just a Power System stored in a different building, on a different network, and a lot of very fair questions from people who have spent their careers walking up to a box they could point at.
The first question is never “which dashboard looks nicest.” It is this: if the machine is no longer on our floor, how do we reach it without hanging the family jewels on the public internet?
Security is the whole job when you move IBM i to the cloud. The applications can wait five minutes. A wide-open Telnet port cannot.
Before we get into tunnels and port numbers, here are the five questions that business almost always asks when they consider moving a legacy AS/400 style system onto a cloud Power System. Then we will spend the rest of this piece on the one that keeps people awake: how staff actually connect, safely.
The five questions every board asks
1. Will our systems still work, or do we have to rewrite everything?
If you land on real Power hardware in the cloud (IBM Power Virtual Server or an equivalent Power offering), you are not converting the application to something else. It is still IBM i. RPG, CL, DDS, SQL, job scheduler and Db2 for i come with you.
What does not automatically come with you is the wiring in the room: old tape, printers, IP addresses burned into CL, ISV licences tied to a serial number, and the PC that still thinks Client Access is a career. Plan those. Do not let a rewrite salesman turn a lift into a five-year programme unless you actually want that programme.
2. What will it really cost?
You swap hardware refresh, power and a computer room for monthly cores, memory, storage and network. That can be the right commercial move. It is not automatically cheaper on day one.
Get a three-year view that includes IBM i licensed cores, storage growth, VPN or Direct Link, migration tools, a second LPAR for HA or DR, and who takes the 2 a.m. call. The win is often cashflow and getting off ageing iron, not a magic discount.
3. Who owns security, and can we still pass an audit?
This is the question the rest of the article answers.
In the old room you owned the door, the switch and the partition. In the cloud the provider owns the building and the Power frame. You still own user profiles, *PUBLIC authorities, exit programs, backups, and how people sign on from a laptop.
4. How long will we be down, and how do we move the data?
Save and restore still works. BRMS and cloud storage still work. IBM i Migrate While Active can keep production running while a copy catches up. Downtime is a design choice, not a surprise, if you measure data size, change rate and bandwidth before you pick a weekend.
Also ask about fallback, parallel run, printers, EDI and bank files. A migration with no RPO or RTO is a hope.
5. Who runs it afterwards?
Cloud does not invent a spare IBM i operator. PTFs, journals, job queues, ISV keys and the next person who has never seen a green screen are still your problem, or your managed service partner’s problem. Decide that before go-live, not after the first invoice.
If you are planning the same move, or you have already landed in Power Virtual Server and you are staring at Access Client Solutions wondering which IP to type, read on. This is the practical version, not the brochure.

