Documente Academic
Documente Profesional
Documente Cultură
Service Description
SRX VPN Boxes
This document describes the features and functions of Alliance Connect Bronze and the roles and responsibilities of the
parties that implement this product when implemented with SRX VPN boxes. This document is for customers that require
information about Alliance Connect Bronze.
01 August 2018
Alliance Connect Bronze Table of Contents
Service Description
Table of Contents
Preface............................................................................................................................................................... 3
1 Introduction..............................................................................................................................................4
3 Service Availability................................................................................................................................ 10
4 Ordering................................................................................................................................................. 11
4.1 Ordering.................................................................................................................................................11
4.2 Subscription to Alliance Connect Bronze.............................................................................................. 11
4.3 Export Restrictions................................................................................................................................ 11
4.4 Import Restrictions................................................................................................................................ 12
5 Support...................................................................................................................................................13
7 Contractual Framework.........................................................................................................................19
8 SWIFT Training...................................................................................................................................... 20
Legal Notices................................................................................................................................................... 21
01 August 2018 2
Alliance Connect Bronze Preface
Service Description
Preface
About this document
This service description describes the features and functions of Alliance Connect Bronze, when
implemented with the new model of SRX VPN boxes, and the roles and responsibilities of the
parties that implement this product.
Note This service description, together with the SWIFT General Terms and Conditions, the
VPN Box Terms and Conditions, and other relevant Contractual Documentation, is an
integral part of the contractual arrangements between SWIFT and its customers for
the provision and the use of the Alliance Connect Bronze product.
Intended audience
This document is for customers that require information about the features and functions of the
Alliance Connect Bronze product and about the related roles and responsibilities.
First edition
This is the first edition of the document.
SWIFT-defined terms
In the context of SWIFT documentation, certain terms have a specific meaning. These terms are
called SWIFT-defined terms (for example, customer, user, or SWIFT services and products). The
definitions of SWIFT-defined terms appear in the SWIFT Glossary .
Related documentation
• Alliance Connect Bronze Implementation Guide - SRX VPN Boxes
• Alliance Connect Bronze Quick Installation Guide - Two SRX VPN Boxes
• Alliance Connect Bronze Quick Installation Guide - One SRX VPN Box
• VPN Interface Configuration for Alliance Connect Bronze Release Letter
• Alliance Connect Bronze VPN Box Resilience Testing Scenarios - SRX VPN Boxes - Dual VPN
Solution
• Alliance Connect Bronze Connectivity Test Tool User Guide
• VPN Box Terms and Conditions
• Network Access Control Guide
• Network Configuration Tables Guide
• Resilience Guide
• SWIFT General Terms and Conditions
• SWIFT Corporate Rules
• SWIFT Customer Testing Policy
• SWIFT By-laws
• SWIFT Personal Data Protection Policy
01 August 2018 3
Alliance Connect Bronze Introduction
Service Description
1 Introduction
Alliance Connect portfolio
SWIFT has developed three different Alliance Connect products. Each product addresses specific
needs in terms of infrastructure and connectivity requirements.
01 August 2018 4
Alliance Connect Bronze Introduction
Service Description
Customers can re-use an existing internet connection or order a new one with a preferred local
ISP. SWIFT provides the necessary elements to establish a secure connection to multi- vendor
secure IP network.
• Security
The same trusted security mechanisms are in place as for any other connectivity method for
connecting to the multi-vendor secure IP network, including SWIFT-managed VPN boxes.
The built-in IPsec encryption ensures the complete confidentiality of exchanged data.
• Resilience
Alliance Connect Bronze with two active SRX VPN boxes and two ISP connections configuration
protects against failure of the ISP router, the ISP connection, and the SRX VPN box through
automatic failover to the secondary SRX VPN box or the secondary ISP connection, depending
on the failure type, that is, VPN or ISP connection failure.
• Support
SWIFT offers world-class customer support services, which are available 24 hours a day, 7 days
a week, worldwide.
Features overview
Alliance Connect Bronze has the following key features:
• Internet-based connectivity
Alliance Connect Bronze enables customers to establish a secure channel to SWIFTNet, both
for the primary and secondary (with two active VPN solution) connections. These can be
provided by the Internet Service Provider (ISP) of the customer's choice.
• Cluster of two VPN boxes in an active/standby mode providing built-in resilience
The Alliance Connect Bronze with two active SRX VPN boxes set-up has built-in resilience in
case of failure of one of the VPN boxes, due to the active/standby cluster of VPN boxes. The
VPN boxes appear as one to the hosts. If the primary VPN box fails, then the standby VPN box
automatically initiates a failover. After restoration of the primary VPN box, the failed over traffic
flow is restored automatically to the primary VPN box.
• Proven IPsec security mechanism
Alliance Connect Bronze uses the proven security mechanism that the SRX VPN box cluster
provides to create a secure channel over the Internet. This channel uses the IPsec technology,
which preserves the security of the data that users exchange on a public infrastructure such as
the Internet.
• Single or dual internet topology
For Alliance Connect Bronze with two active SRX VPN boxes, primary and secondary ISP
connections are needed thus improving resiliency.
For Alliance Connect Bronze with one active SRX VPN box, it is highly recommended to have a
Disaster Recovery site ready to take over the traffic in case of VPN failure or Internet connection
failure. Alternatively, if faulty VPN, it can be replaced by the mandatory spare VPN box.
• Simple set-up and installation of the VPN box cluster
The implementation and set up is straightforward: the customer can install the VPN box(es) and
set up the secure connection thanks to the Alliance Connect Bronze Quick Installation Guide -
SRX VPN Boxes that is provided with the VPN boxes.
01 August 2018 5
Alliance Connect Bronze Features and Functions
Service Description
Internet connection
Depending on the configuration (one or two active SRX VPN boxes), customers need one or two
broadband internet connections and routers, or modem(s) provided by their preferred Internet
Service Provider (ISP) that the customer has selected. Customers can use an existing internet
connection for this purpose.
The implementation and the set-up of the VPN boxes is straightforward. Customers can find more
information about the installation of the VPN boxes and the set-up of the secure connection in the
Alliance Connect Bronze Implementation Guide - SRX VPN Boxes.
Note The internet connection must not be restricted to sending or receiving SWIFT traffic. It
can be shared with other internet services.
01 August 2018 6
Alliance Connect Bronze Features and Functions
Service Description
Failover mechanism of the VPN box cluster for two active SRX VPN boxes
The SRX VPN boxes are co-located and interconnected by three dedicated cables. The VPN boxes
appear as one to the host. If the primary VPN box, router, or connection fails, then the standby VPN
box automatically initiates a failover to activate the secondary connection. After restoration of the
primary VPN box, the failed over traffic flow is restored automatically to the primary VPN box.
The active/standby cluster of VPN boxes offers built-in resilience for the standard Alliance Connect
Bronze set-up in case of failure of one of the VPN boxes or internet connection. An Alliance
Connect Bronze with two active VPN boxes is a configuration of two VPN boxes in active/standby
mode, in which each VPN box is connected to an internet connection. By default only one internet
connection is active at any time in case of no load sharing. The VPN boxes are co-located and
interconnected by three dedicated cables. The VPN boxes appear as one to the host.
If the primary VPN box fails, then the secondary VPN box automatically initiates a takeover so
traffic flows over this VPN box, existing connections continue to be used as this VPN connects to
both connections. After restoration of the primary VPN box, the failed over traffic flow is restored
automatically to the primary VPN box.
01 August 2018 7
Alliance Connect Bronze Features and Functions
Service Description
On the other hand, if the primary connection fails, then the cluster uses the secondary connection
to transmit the traffic. After restoration of the primary connection, the failed over traffic flow is
restored automatically to the primary connection.
Alliance Connect Bronze SRX topology with two active VPN boxes
Failover mechanism of the VPN box in case of one active SRX VPN box
Important It is highly recommended to have a Disaster Recovery site ready to take over the
traffic in case of VPN failure or Internet connection failure. Alternatively, if the VPN is
faulty, it can be replaced by the mandatory spare VPN box.
This configuration does not protect against a failure of the internet connection, in
which case all connectivity is lost.
01 August 2018 8
Alliance Connect Bronze Features and Functions
Service Description
An Alliance Connect Bronze based on a single SRX VPN box set-up is a configuration of one
internet access.
Alliance Connect Bronze SRX topology with one active VPN box
01 August 2018 9
Alliance Connect Bronze Service Availability
Service Description
3 Service Availability
Operational status
SWIFT displays the operational status of SWIFT's systems and messaging services on the SWIFT
Operational Status.
In case of problems, it is the customer's responsibility to first consult any notifications about the
operational status of SWIFT's systems and messaging services. To do so, the customer must
subscribe to operational status notifications.
Important Alliance Connect Bronze is an internet-based product. SWIFT has no control over the
capacity or the availability of the internet connection. SWIFT is not responsible for and
cannot guarantee the bandwidth nor the service availability of the internet connection.
If SWIFT becomes aware of a problem with SWIFT's systems and messaging services, then it
initiates the relevant recovery or fallback operation, falling under SWIFT's responsibility that is
necessary to restore the service.
01 August 2018 10
Alliance Connect Bronze Ordering
Service Description
4 Ordering
4.1 Ordering
Order SWIFT services and products
To use SWIFT services and products, a customer must subscribe to, or order, the relevant services
and products.
Related information
For information about SWIFT's online ordering facility and how to order, see www.swift.com >
Ordering & Support > Ordering.
01 August 2018 11
Alliance Connect Bronze Ordering
Service Description
01 August 2018 12
Alliance Connect Bronze Support
Service Description
5 Support
Support for SWIFT customers
By default, SWIFT Support is the single point of contact to report all problems and queries that
relate to SWIFT services and products. Support is available to all SWIFT customers.
Individuals within a customer organisation must register on swift.com to use the Support service.
For more information about the different services that SWIFT offers as part of the support
packages and the procedure to order support, see Comparison of support packages on swift.com.
Related information
For more information about Support services, see the service description related to the applicable
support package:
Support documentation
01 August 2018 13
Alliance Connect Bronze Roles and Responsibilities
Service Description
01 August 2018 14
Alliance Connect Bronze Roles and Responsibilities
Service Description
01 August 2018 15
Alliance Connect Bronze Roles and Responsibilities
Service Description
• in case of one active VPN box, check that VPN box A is operational after the download of the
SWIFT configuration. The LED status should look like:
Customers can find more information about the provisioning in the Alliance Connect Bronze
Implementation Guide - SRX VPN Boxes.
01 August 2018 16
Alliance Connect Bronze Roles and Responsibilities
Service Description
Customer testing
Customers must not conduct any performance or vulnerability tests on or through SWIFT services
and products unless expressly permitted in the SWIFT Customer Testing Policy. If customers
believe they have identified a potential performance or vulnerability threat, they must immediately
inform SWIFT thereof and treat all related information, data or materials as SWIFT confidential
information.
Description
SWIFT is responsible for providing and managing the overall Alliance Connect Bronze
implementation except for the broadband internet connections.
01 August 2018 17
Alliance Connect Bronze Roles and Responsibilities
Service Description
01 August 2018 18
Alliance Connect Bronze Contractual Framework
Service Description
7 Contractual Framework
SWIFT General Terms and Conditions
Together with this service description, the SWIFT General Terms and Conditions and the VPN Box
Terms and Conditions govern the provision and the use of Alliance Connect Bronze.
For the latest available version of the SWIFT General Terms and Conditions and the VPN Box
Terms and Conditions, see www.swift.com > About Us > Legal > Terms & Conditions.
01 August 2018 19
Alliance Connect Bronze SWIFT Training
Service Description
8 SWIFT Training
SWIFT provides training about standards, products, and services to suit different needs. From
tailored training to self-paced e-learning modules on SWIFTSmart, a range of training options are
available for all SWIFT end users.
SWIFTSmart
SWIFTSmart is an interactive, cloud-based training service that offers a large variety of courses for
different levels of knowledge. The courses contain exercises and quizzes and are available in
multiple languages. The SWIFTSmart catalogue provides a list of courses that are organised into
these learning tracks:
• General knowledge
• Work with messages
• Deploy and manage SWIFT software solutions
• Security and audit
• Compliance and shared services
SWIFTSmart is accessible from the desktop or from a mobile device. No installation is required.
It is available to all connected SWIFT end users and registered SWIFT partners with a swift.com
account. For more information, see How to become a swift.com user.
Tailored training
A full range of tailored programmes are available to meet specific training needs. For more
information, visit the Training web page.
01 August 2018 20
Alliance Connect Bronze Legal Notices
Service Description
Legal Notices
Copyright
SWIFT © 2018. All rights reserved.
Restricted Distribution
Do not distribute this publication outside your organisation unless your subscription or order
expressly grants you that right, in which case ensure you comply with any other applicable
conditions.
Disclaimer
The information in this publication may change from time to time. You must always refer to the
latest available version.
Translations
The English version of SWIFT documentation is the only official and binding version.
Trademarks
SWIFT is the trade name of S.W.I.F.T. SCRL. The following are registered trademarks of SWIFT:
the SWIFT logo, SWIFT, SWIFTNet, Sibos, 3SKey, Innotribe, the Standards Forum logo,
MyStandards, and SWIFT Institute. Other product, service, or company names in this publication
are trade names, trademarks, or registered trademarks of their respective owners.
01 August 2018 21