12.07.2015 Views

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

eTrust CA-Top Secret Security for z/OS and OS ... - SupportConnect

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Using FTPIP Address ProtectionSecuring an IP address using <strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> (or any external securityproduct) requires that the TCP/IP product installed pass the IP address packet.Not all TCP/IP vendor products pass this in<strong>for</strong>mation. IBM’s TCP/IP productdoes pass the IP address.IP address protection is not available if your TCP/IP product does not pass theIP address packet.The IP packet passed is generated from the user's originating IP address. Thus,these IP packets often have no resemblance to st<strong>and</strong>ard LU names. Each node ofthe IP address is translated into a character representation of the hex value of thenode. For example, the IP address 141.202.201.56 would appear as terminal8D<strong>CA</strong>C938. The hex value of 141 is 8D, the hex value of 202 is <strong>CA</strong>, <strong>and</strong> so on.<strong>eTrust</strong> <strong>CA</strong>-<strong>Top</strong> <strong>Secret</strong> allows you two mechanisms to implement security of an IPaddress. Dotted IP is converted to hex pairs. If you want to restrict a particularuser to enter the system only through a given IP address, you would use sourcerestriction. For example:TSS ADD(aicd) SOURCE(8D<strong>CA</strong>C938) equivalent to 141.202.201.56If you want to protect an IP address or range from use, you would useTERMINAL restriction. For example, to restrict use of all IP addresses starting141.202 <strong>for</strong> all users:TSS ADD(dept) TERMINAL(8D<strong>CA</strong>)To permit userid2 to use IP addresses starting 141.202:TSS PERMIT(userid2) TERMINAL(8D<strong>CA</strong>)To permit userid3 to use IP addresses starting 141.202.201:TSS PERMIT(userid3) TERMINAL(8D<strong>CA</strong>C9)Using FTPFTP is a feature of TCP/IP that allows users to transfer files to <strong>and</strong> from themainframe. In addition, remote users can submit jobs to MVS. Users are requiredto identify themselves when using FTP.FTP runs as an MVS or UNIX System Services application. <strong>Security</strong> configurationis similar <strong>for</strong> both.1–32 Cookbook

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!