1410
z/OS Communications Server Version 2 Release 3 IP Configuration Reference IBM SC27-3651-30

IP Configuration Reference...Summary of changes for IP Configuration Reference.....xxxix Changes made in z/OS Communications Server Version 2 Release 3.....xxxix Changes made in z/OS

  • Upload
    others

  • View
    21

  • Download
    0

Embed Size (px)

Citation preview

  • z/OS Communications ServerVersion 2 Release 3

    IP Configuration Reference

    IBM

    SC27-3651-30

  • Note:

    Before using this information and the product it supports, be sure to read the general information under“Notices” on page 1319.

    This edition applies to Version 2 Release 3 of z/OS® (5650-ZOS), and to subsequent releases and modifications untilotherwise indicated in new editions.

    Last updated: 2019-06-21© Copyright International Business Machines Corporation 2000, 2019.US Government Users Restricted Rights – Use, duplication or disclosure restricted by GSA ADP Schedule Contract withIBM Corp.

  • Contents

    Figures............................................................................................................... xix

    Tables...............................................................................................................xxiii

    About this document......................................................................................... xxixWho should read this document............................................................................................................. xxixHow this document is organized............................................................................................................. xxixHow to use this document.......................................................................................................................xxix

    How to contact IBM service............................................................................................................... xxixConventions and terminology that are used in this information............................................................. xxxHow to read a syntax diagram................................................................................................................. xxxiPrerequisite and related information.................................................................................................... xxxiv

    Summary of changes for IP Configuration Reference........................................ xxxixChanges made in z/OS Communications Server Version 2 Release 3................................................. xxxixChanges made in z/OS Communications Server Version 2 Release 2, as updated June 2017............... xliChanges made in z/OS Version 2 Release 2, as updated September 2016............................................ xliiChanges made in z/OS Version 2 Release 2, as updated March 2016.................................................... xliiChanges made in z/OS Version 2 Release 2............................................................................................. xliiChanges made in z/OS Version 2 Release 1, as updated February 2015...............................................xlivChanges made in z/OS Version 2 Release 1, as updated September 2014........................................... xlivChanges made in z/OS Version 2 Release 1, as updated December 2013..............................................xlvz/OS Version 2 Release 1 summary of changes....................................................................................... xlv

    Chapter 1. Configuration data sets and files........................................................... 1TCP/IP configuration data sets.................................................................................................................... 1

    Chapter 2. TCP/IP profile (PROFILE.TCPIP) and configuration statements............. 11Summary of TCP/IP address space configuration statements.................................................................11PROFILE.TCPIP search order.....................................................................................................................15Statement syntax for configuration statements....................................................................................... 15ARPAGE statement.................................................................................................................................... 16AUTOLOG statement..................................................................................................................................17BEGINROUTES statement......................................................................................................................... 20BSDROUTINGPARMS statement............................................................................................................... 28DEFADDRTABLE statement....................................................................................................................... 32DELETE statement..................................................................................................................................... 34Summary of DEVICE and LINK statements...............................................................................................36

    Overview of DEVICE and LINK statements..........................................................................................37Recovering from device failures...........................................................................................................38Missing interrupt handler factors.........................................................................................................38DEVICE and LINK statements relationship to VTAM configuration.................................................... 39Modifying DEVICE and LINK statements.............................................................................................39Monitoring network links (DEVICE and LINK statements)..................................................................40

    DEVICE and LINK - CTC devices statement.............................................................................................. 40DEVICE and LINK - LAN Channel Station and OSA devices statement....................................................43DEVICE and LINK - MPCIPA OSA-Express QDIO devices statement.......................................................47DEVICE and LINK - MPCIPA HiperSockets devices statement................................................................ 54DEVICE and LINK - MPCPTP devices statement.......................................................................................57

    iii

  • DEVICE and LINK - VIRTUAL devices statement......................................................................................60GLOBALCONFIG statement....................................................................................................................... 62HOME statement........................................................................................................................................83INCLUDE statement...................................................................................................................................87Summary of INTERFACE statements........................................................................................................ 87

    Restrictions on IPv6 addresses configured in the TCP/IP profile.......................................................90Steps for modifying INTERFACE statements.......................................................................................90Monitoring network interfaces (INTERFACE statements)...................................................................91

    INTERFACE - IPAQENET OSA-Express QDIO interfaces statement........................................................ 91INTERFACE - IPAQIDIO HiperSockets interfaces statement.................................................................102INTERFACE - VIRTUAL interfaces statement......................................................................................... 106INTERFACE - IPAQENET6 OSA-Express QDIO interfaces statement.................................................... 107INTERFACE - IPAQIDIO6 HiperSockets interfaces statement.............................................................. 121INTERFACE - LOOPBACK6 interface statement..................................................................................... 126INTERFACE - MPCPTP6 interfaces statement........................................................................................127INTERFACE - VIRTUAL6 interfaces statement....................................................................................... 130IPCONFIG statement...............................................................................................................................132IPCONFIG6 statement............................................................................................................................ 146IPSEC statement......................................................................................................................................156ITRACE statement................................................................................................................................... 169NETACCESS statement............................................................................................................................ 171NETMONITOR statement........................................................................................................................ 175OSAENTA statement................................................................................................................................182PKTTRACE statement.............................................................................................................................. 189PORT statement.......................................................................................................................................196PORTRANGE statement...........................................................................................................................205PRIMARYINTERFACE statement.............................................................................................................209SACONFIG statement..............................................................................................................................210SMFCONFIG statement........................................................................................................................... 213SMFPARMS statement.............................................................................................................................220SOMAXCONN statement..........................................................................................................................221SRCIP statement..................................................................................................................................... 222START statement..................................................................................................................................... 230STOP statement.......................................................................................................................................231TCPCONFIG statement............................................................................................................................232TRANSLATE statement............................................................................................................................ 239UDPCONFIG statement........................................................................................................................... 240VIPADYNAMIC statement summary....................................................................................................... 243VIPADYNAMIC - VIPADEFINE statement............................................................................................... 244VIPADYNAMIC - VIPABACKUP statement.............................................................................................. 248VIPADYNAMIC - VIPADELETE statement............................................................................................... 251VIPADYNAMIC - VIPADISTRIBUTE statement....................................................................................... 252VIPADYNAMIC - VIPARANGE statement................................................................................................ 269VIPADYNAMIC - VIPAROUTE statement................................................................................................ 272VIPADYNAMIC - VIPASMPARMS statement........................................................................................... 274

    Chapter 3. TCP/IP cataloged procedure (TCPIPROC)...........................................277Specifying TCP/IP address space parameters........................................................................................277Example of a TCP/IP cataloged procedure............................................................................................. 278Using output data sets.............................................................................................................................279

    Chapter 4. Protocol number and port assignments..............................................281Port assignments..................................................................................................................................... 281

    PROFILE.TCPIP port assignments..................................................................................................... 282/etc/services and ETC.SERVICES port assignments......................................................................... 284

    Chapter 5. Resolver setup and TCPIP.DATA configuration statements................. 289

    iv

  • Resolver setup statements......................................................................................................................289Resolver setup statement information and syntax conventions...................................................... 291CACHE NOCACHE statements........................................................................................................... 292CACHEREORDER NOCACHEREORDER statements.......................................................................... 293CACHESIZE statement.......................................................................................................................293COMMONSEARCH/NOCOMMONSEARCH statement........................................................................ 294DEFAULTIPNODES statement............................................................................................................295DEFAULTTCPIPDATA statement........................................................................................................ 296GLOBALIPNODES statement............................................................................................................. 297GLOBALTCPIPDATA statement.......................................................................................................... 298MAXTTL statement.............................................................................................................................299UNRESPONSIVETHRESHOLD statement.......................................................................................... 300; and # statements.............................................................................................................................302

    Configuration statements in TCPIP.DATA............................................................................................... 302system_name considerations............................................................................................................304Dynamically changing TCPIP.DATA statements................................................................................ 304Determining which TCPIP.DATA statements are being used............................................................ 306Syntax conventions for TCPIP.DATA configuration statements........................................................ 306ALWAYSWTO statement.....................................................................................................................307DATASETPREFIX statement...............................................................................................................307DOMAIN statement............................................................................................................................308DOMAINORIGIN statement...............................................................................................................308HOSTNAME statement.......................................................................................................................309LOADDBCSTABLES statement........................................................................................................... 310LOOKUP statement............................................................................................................................ 311MESSAGECASE statement................................................................................................................. 313NAMESERVER statement................................................................................................................... 313NOCACHE statement..........................................................................................................................314NOCACHEREORDER statement......................................................................................................... 314NSINTERADDR statement................................................................................................................. 315NSPORTADDR statement................................................................................................................... 317OPTIONS statement...........................................................................................................................318RESOLVERTIMEOUT statement......................................................................................................... 320RESOLVERUDPRETRIES statement...................................................................................................321RESOLVEVIA statement..................................................................................................................... 322SEARCH statement............................................................................................................................ 323SOCKDEBUG statement.....................................................................................................................325SOCKNOTESTSTOR statement.......................................................................................................... 325SOCKTESTSTOR statement................................................................................................................326SORTLIST statement..........................................................................................................................326TCPIPJOBNAME statement............................................................................................................... 328TCPIPUSERID statement................................................................................................................... 329TRACE RESOLVER statement.............................................................................................................329TRACE SOCKET statement.................................................................................................................330; and # statements.............................................................................................................................330

    Sample TCPIP.DATA data set (TCPDATA)................................................................................................330

    Chapter 6. z/OS Load Balancing Advisor and Load Balancing Agent..................... 335General syntax rules for z/OS Load Balancing Advisor...........................................................................335Starting the z/OS Load Balancing Advisor...............................................................................................336Load Balancing Advisor sample start procedure.................................................................................... 336Load Balancing Advisor configuration file statements........................................................................... 336

    agent_connection_port statement....................................................................................................338agent_id_list statement.....................................................................................................................338debug_level statement...................................................................................................................... 339lb_connection_v4 statement............................................................................................................. 340lb_connection_v6 statement............................................................................................................. 340

    v

  • lb_id_list statement........................................................................................................................... 341port_list statement............................................................................................................................ 342sysplex_group_name statement....................................................................................................... 344update_interval statement................................................................................................................ 345wlm statement................................................................................................................................... 345

    Starting the z/OS Load Balancing Agent................................................................................................. 346z/OS Load Balancing Agent sample start procedure.............................................................................. 347z/OS Load Balancing Agent configuration file statements..................................................................... 347

    advisor_id statement......................................................................................................................... 348debug_level statement...................................................................................................................... 348host_connection statement............................................................................................................... 349sysplex_group_name statement....................................................................................................... 350

    Chapter 7. Automated domain name registration................................................ 351General configuration rules for automated domain name registration................................................. 351Starting the automated domain name registration application............................................................. 352EZBADNRS sample start procedure for automated domain name registration application................. 352Automated domain name registration application configuration file ................................................... 353arm_element_suffix statement...............................................................................................................355debug_level statement............................................................................................................................356dns statement..........................................................................................................................................357gwm statement........................................................................................................................................359host_group statement.............................................................................................................................360ipaddrlist statement................................................................................................................................ 362key statement.......................................................................................................................................... 362server_group statement.......................................................................................................................... 363uuid statement.........................................................................................................................................364

    Chapter 8. IKE daemon...................................................................................... 367Starting the IKED using z/OS UNIX......................................................................................................... 367IKE cataloged procedure.........................................................................................................................367IKE environment variables...................................................................................................................... 368IKE daemon configuration file statements............................................................................................. 370

    IkeConfig statement...........................................................................................................................371NssStackConfig statement.................................................................................................................382IKE daemon configuration file sample.............................................................................................. 384

    Chapter 9. Network security services server.......................................................389Starting Network security services server using z/OS UNIX.................................................................. 389Network security services server cataloged procedure......................................................................... 389Network security services server environment variables...................................................................... 390Network security services server configuration file statements............................................................392

    NSS server configuration file sample.................................................................................................392IPSecDisciplineConfig statement...................................................................................................... 394NssConfig statement..........................................................................................................................397

    Chapter 10. Defense Manager daemon............................................................... 401Starting the DMD using z/OS UNIX (optional).........................................................................................401The Defense Manager daemon cataloged procedure (optional)............................................................401DMD environment variables.................................................................................................................... 402DMD configuration file statements..........................................................................................................404

    DmConfig statement.......................................................................................................................... 404DmStackConfig statement................................................................................................................. 406DMD configuration file sample...........................................................................................................408

    Chapter 11. OMPROUTE..................................................................................... 413Starting OMPROUTE using z/OS UNIX (optional)................................................................................... 413

    vi

  • OMPROUTE cataloged procedure (optional).......................................................................................... 413OMPROUTE parameters.......................................................................................................................... 414OMPROUTE environment variables.........................................................................................................415OMPROUTE configuration file statements.............................................................................................. 417

    INCLUDE statement........................................................................................................................... 417OSPF configuration statements.........................................................................................................418RIP configuration statements............................................................................................................434IPv6 OSPF configuration statements................................................................................................ 444IPv6 RIP configuration statements................................................................................................... 454Common configuration statements for RIP and OSPF......................................................................463

    Interfaces supported by OMPROUTE......................................................................................................472

    Chapter 12. TN3270E Telnet server.................................................................... 477Telnet profile statements overview.........................................................................................................477

    TELNETGLOBALS statements............................................................................................................ 477TELNETPARMS statements................................................................................................................477PARMSGROUP statements................................................................................................................ 477BEGINVTAM block..............................................................................................................................477INCLUDE statement........................................................................................................................... 477Telnet statement syntax.................................................................................................................... 478

    Telnet parameter statements in the Telnet profile.................................................................................480Rules for Telnet parameter statements and security parameters....................................................484BINARYLINEMODE statement...........................................................................................................485CHECKCLIENTCONN statement........................................................................................................ 485CLIENTAUTH statement.....................................................................................................................486CODEPAGE statement........................................................................................................................487CONNTYPE statement........................................................................................................................487CRLLDAPSERVER statement..............................................................................................................488DBCSTRACE statement......................................................................................................................489DBCSTRANSFORM statement............................................................................................................489DEBUG statement.............................................................................................................................. 490DISABLESGA statement.................................................................................................................... 492DROPASSOCPRINTER statement...................................................................................................... 492ENCRYPTION statement....................................................................................................................492EXPRESSLOGON statement...............................................................................................................493EXPRESSLOGONMFA statement........................................................................................................494FORMAT statement............................................................................................................................ 495FULLDATATRACE statement.............................................................................................................. 495INACTIVE statement..........................................................................................................................496INCLUDE statement........................................................................................................................... 496KEEPINACTIVE statement.................................................................................................................497KEEPLU statement............................................................................................................................. 497KEYRING statement...........................................................................................................................498LIMITQ statement.............................................................................................................................. 499LUSESSIONPEND statement............................................................................................................. 499MAXRECEIVE statement.................................................................................................................... 500MAXREQSESS statement................................................................................................................... 500MAXRUCHAIN statement...................................................................................................................501MAXTCPSENDQ statement................................................................................................................ 501MAXVTAMSENDQ statement............................................................................................................. 502MSG07 statement.............................................................................................................................. 502NACUSERID statement...................................................................................................................... 503OLDSOLICITOR statement.................................................................................................................503PASSWORDPHRASE statement......................................................................................................... 503PORT, SECUREPORT, and TTLSPORT statements.............................................................................504PROFILEINACTIVE statement........................................................................................................... 505PRTINACTIVE statement................................................................................................................... 505

    vii

  • REFRESHMSG10 statement.............................................................................................................. 506SCANINTERVAL and TIMEMARK statements....................................................................................506SEQUENTIALLU statement................................................................................................................ 507SGA statement................................................................................................................................... 507SHAREACB statement........................................................................................................................508SIMCLIENTLU statement................................................................................................................... 508SINGLEATTN statement.....................................................................................................................509SMFINIT and SMFTERM statements................................................................................................. 509SMFPROFILE statement.................................................................................................................... 510SNAEXT statement.............................................................................................................................511SSLTIMEOUT statement.....................................................................................................................512SSLV2 and NOSSLV2 statements.......................................................................................................512SSLV3 and NOSSLV3 statements.......................................................................................................512TCPIPJOBNAME statement............................................................................................................... 513TELNETDEVICE statement.................................................................................................................513TESTMODE statement........................................................................................................................515TIMEMARK statement........................................................................................................................515TKOGENLU, TKOGENLURECON, and NOTKO statements.................................................................515TKOSPECLU, TKOSPECLURECON, and NOTKO statements..............................................................517TN3270E statement...........................................................................................................................518TNSACONFIG statement....................................................................................................................519UNLOCKKEYBOARD statement..........................................................................................................521XCFGROUP statement........................................................................................................................521

    Telnet mapping statements in the Telnet profile....................................................................................523Rules for LU name specification........................................................................................................ 525Client identifier types and definitions................................................................................................526Rules for client identifier specification..............................................................................................527Rules for host name specification..................................................................................................... 527ALLOWAPPL statement......................................................................................................................528DEFAULTAPPL statement...................................................................................................................529DEFAULTLUS or SDEFAULTLUS statement........................................................................................ 530DEFAULTLUSSPEC or SDEFAULTLUSSPEC statement.......................................................................531DEFAULTPRT or SDEFAULTPRT statement........................................................................................532DEFAULTPRTSPEC or SDEFAULTPRTSPEC statement...................................................................... 533DESTIPGROUP statement..................................................................................................................534HNGROUP statement......................................................................................................................... 534INTERPTCP statement.......................................................................................................................535IPGROUP statement.......................................................................................................................... 536LINEMODEAPPL statement............................................................................................................... 537LINKGROUP statement...................................................................................................................... 538LUGROUP or SLUGROUP statement.................................................................................................. 538LUMAP statement...............................................................................................................................540MONITORGROUP statement..............................................................................................................541MONITORMAP statement.................................................................................................................. 543PARMSGROUP statement.................................................................................................................. 543PARMSMAP statement.......................................................................................................................544PORT statement................................................................................................................................. 544PRTDEFAULTAPPL statement............................................................................................................ 545PRTGROUP or SPRTGROUP statement..............................................................................................546PRTMAP statement............................................................................................................................ 547RESTRICTAPPL statement................................................................................................................. 548USERGROUP statement..................................................................................................................... 550USSTCP statement............................................................................................................................. 551

    Telnet USS table setup............................................................................................................................ 551General usage rules for Telnet USS macroinstructions.................................................................... 552USSCMD macroinstruction.................................................................................................................552USSMSG macroinstruction.................................................................................................................553USSPARM macroinstruction...............................................................................................................557

    viii

  • USSTAB macroinstruction..................................................................................................................559USSEND macroinstruction................................................................................................................. 560

    Telnet INTERPRET table setup................................................................................................................560General usage rules for Telnet INTERPRET macroinstructions........................................................560INTAB macroinstruction.................................................................................................................... 560LOGCHAR macroinstruction...............................................................................................................561ENDINTAB macroinstruction............................................................................................................. 564

    Telnet LU exit setup................................................................................................................................. 565Telnet LU exit setup operation...........................................................................................................565Requirements for LU exit routines..................................................................................................... 567LU exit routine parameter list............................................................................................................ 568

    Chapter 13. EXPRESS LOGON using DCAS.......................................................... 569Starting Digital Certificate Access Server............................................................................................... 569Digital Certificate Access Server (DCAS) sample procedure (EZADCASP)............................................ 571Digital Certificate Access Server (DCAS) environment variables........................................................... 571PassTicket server configuration file processing when using IBM System SSL...................................... 572Digital Certificate Access Server (DCAS) configuration file keywords and parameters........................ 572

    CLIENTAUTH...................................................................................................................................... 572IPADDR............................................................................................................................................... 573KEYRING.............................................................................................................................................573LDAPPORT.......................................................................................................................................... 573LDAPSERVER...................................................................................................................................... 574PORT...................................................................................................................................................574SAFKEYRING...................................................................................................................................... 574SERVERTYPE...................................................................................................................................... 575STASHFILE..........................................................................................................................................576TCPIP..................................................................................................................................................576TLSMECHANISM................................................................................................................................ 577TLSV1ONLY.........................................................................................................................................577V3CIPHER...........................................................................................................................................577Steps for setting up RACF for Digital Certificate Access Server (DCAS)...........................................578

    Chapter 14. File Transfer Protocol...................................................................... 579FTP server cataloged procedure (FTPD)................................................................................................. 579FTP server cataloged procedure (FTPD) parameters............................................................................. 581FTP server user exits............................................................................................................................... 582

    Sample server user exits....................................................................................................................583The FTCHKCMD user exit................................................................................................................... 583The FTPOSTPR user exit.................................................................................................................... 585The FTCHKIP user exit....................................................................................................................... 587The FTCHKPWD user exit...................................................................................................................588The FTCHKJES user exit.....................................................................................................................590The FTP server SMF user exit............................................................................................................ 591

    FTP client user exits................................................................................................................................ 591Sample client user exits.....................................................................................................................593The EZAFCCMD user exit................................................................................................................... 593The EZAFCREP user exit.................................................................................................................... 599Using both EZAFCCMD and EZAFCREP user exits.............................................................................601

    FTP configuration statements in FTP.DATA.............................................................................................601Summary of FTP client and server configuration statements.......................................................... 602

    FTP.DATA data set statements................................................................................................................ 619ACCESSERRORMSGS (FTP server) statement........................................................................................ 620ADMINEMAILADDRESS (FTP server) statement.................................................................................... 620ANONYMOUS (FTP server) statement.................................................................................................... 621ANONYMOUSFILEACCESS (FTP server) statement................................................................................623ANONYMOUSFILETYPEJES (FTP server) statement.............................................................................. 624

    ix

  • ANONYMOUSFILETYPESEQ (FTP server) statement............................................................................. 625ANONYMOUSFILETYPESQL (FTP server) statement..............................................................................626ANONYMOUSFTPLOGGING (FTP server) statement..............................................................................626ANONYMOUSHFSDIRMODE (FTP server) statement............................................................................. 627ANONYMOUSHFSFILEMODE (FTP server) statement............................................................................628ANONYMOUSHFSINFO (FTP server) statement.....................................................................................629ANONYMOUSLEVEL (FTP server) statement.......................................................................................... 630ANONYMOUSLOGINMSG (FTP server) statement..................................................................................632ANONYMOUSMVSINFO (FTP server) statement.................................................................................... 633APPLNAME (FTP server) statement........................................................................................................ 634ASATRANS (FTP client and server) statement........................................................................................635AUTOMOUNT (FTP client and server) statement....................................................................................635AUTORECALL (FTP client and server) statement....................................................................................636AUTOTAPEMOUNT (FTP client and server) statement........................................................................... 637BANNER (FTP server) statement............................................................................................................ 637BLKSIZE (FTP client and server) statement........................................................................................... 638BUFNO (FTP client and server) statement..............................................................................................639CCONNTIME (FTP client) statement....................................................................................................... 640CCTRANS (FTP client) statement............................................................................................................ 640CCXLATE (FTP server) statement............................................................................................................641CHKCONFIDENCE statement (FTP client and server) statement.......................................................... 642CHKPTFLUSH (FTP client) statement......................................................................................................643CHKPTINT (FTP client and server) statement........................................................................................ 644CHKPTPREFIX (FTP client) statement.................................................................................................... 645CIPHERSUITE (FTP client and server) statement.................................................................................. 646CLIENTERRCODES (FTP client) statement............................................................................................. 648CLIENTEXIT (FTP client) statement........................................................................................................649CONDDISP (FTP client and server) statement........................................................................................650CTRLCONN (FTP client and server) statement....................................................................................... 651DATACLASS (FTP client and server) statement...................................................................................... 652DATACTTIME (FTP client) statement...................................................................................................... 654DATAKEEPALIVE (FTP client and server) statement.............................................................................. 654DATATIMEOUT (FTP server) statement...................................................................................................655DB2 (FTP client and server) statement...................................................................................................656DB2PLAN (FTP cilent and server) statement..........................................................................................656DBSUB (FTP client and server) statement.............................................................................................. 657DCBDSN (FTP client and server) statement........................................................................................... 658DCONNTIME (FTP client and server) statement.....................................................................................659DEBUG (FTP client and server) statement..............................................................................................659DEBUGONSITE (FTP server) statement..................................................................................................661DEST (FTP server) statement.................................................................................................................. 662DIRECTORY (FTP client and server) statement...................................................................................... 662DIRECTORYMODE (FTP client and server) statement............................................................................663DSNTYPE (FTP client and server) statement.......................................................................................... 664DSWAITTIME (FTP client and server) statement................................................................................... 665DSWAITTIMEREPLY (FTP server) statement..........................................................................................666DUMP (FTP client and server) statement................................................................................................668DUMPONSITE (FTP server) statement....................................................................................................669EATTR (FTP client and server) statement...............................................................................................669EMAILADDRCHECK (FTP server) statement...........................................................................................671ENCODING (FTP client and server) statement....................................................................................... 671EPSV4 (FTP client) statement................................................................................................................. 672EXTENSIONS (FTP client and server) statement....................................................................................673FIFOIOTIME (FTP client and server) statement..................................................................................... 675FIFOOPENTIME (FTP client and server) statement............................................................................... 676FILETYPE (FTP client and server) statement..........................................................................................677FTPKEEPALIVE (FTP client and server) statement.................................................................................678FTPLOGGING (FTP server) statement.................................................................................................... 679

    x

  • FWFRIENDLY (FTP client) statement......................................................................................................680HFSINFO (FTP server) statement........................................................................................................... 681INACTIVE (FTP Server) statement.......................................................................................................... 681INACTTIME (FTP client) statement.........................................................................................................682ISPFSTATS (FTP client and server) statement........................................................................................683JESENTRYLIMIT (FTP server) statement................................................................................................683JESGETBYDSN (FTP server) statement.................................................................................................. 684JESINTERFACELEVEL (FTP server) statement....................................................................................... 685JESLRECL (FTP server) statement.......................................................................................................... 687JESPUTGETTO (FTP server) statement.................................................................................................. 687JESRECFM (FTP server) statement......................................................................................................... 688KEYRING (FTP client and server) statement.......................................................................................... 689LISTLEVEL (FTP server) statement......................................................................................................... 690LISTSUBDIR (FTP client and server) statement..................................................................................... 691LOGCLIENTERR (FTP client) statement..................................................................................................693LOGINMSG (FTP server) statement........................................................................................................ 694LRECL (FTP client and server) statement............................................................................................... 694MBDATACONN (FTP client and server) statement..................................................................................695MBREQUIRELASTEOL (FTP client and server) statement......................................................................697MBSENDEOL statement (FTP client and server) statement...................................................................698MGMTCLASS (FTP client and server) statement.................................................................................... 699MIGRATEVOL (FTP client and server) statement....................................................................................700MVSINFO (FTP server) statement...........................................................................................................700MVSURLKEY (FTP server) statement...................................................................................................... 701MYOPENTIME (FTP client) statement.....................................................................................................702NETRCLEVEL (FTP client) statement...................................................................................................... 702NONSWAPD (FTP server) statement.......................................................................................................703PASSIVEDATACONN (FTP server) statement..........................................................................................704PASSIVEDATAPORTS (FTP server) statement........................................................................................ 704PASSIVEIGNOREADDR (FTP client) statement...................................................................................... 705PASSIVEONLY (FTP client) statement.....................................................................................................706PASSPHRASE (FTP server) statement.................................................................................................... 707PDSTYPE (FTP client and server) statement.......................................................................................... 707PORTCOMMAND (FTP server) statement................................................................................................708PORTCOMMANDIPADDR (FTP server) statement.................................................................................. 709PORTCOMMANDPORT (FTP server) statement...................................................................................... 710PORTOFENTRY4 (FTP server) statement................................................................................................711PRIMARY (FTP client and server) statement.......................................................................................... 711PROGRESS (FTP client) statement..........................................................................................................712QUOTESOVERRIDE (FTP client and server) statement.......................................................................... 713RDW (FTP client and server) statement..................................................................................................714RECFM (FTP client and server) statement.............................................................................................. 714REMOVEINBEOF (FTP client and server) statement.............................................................................. 716REPLY226 (FTP server) statement..........................................................................................................717REPLYSECURITYLEVEL (FTP server) statement..................................................................................... 718RESTGET (FTP client) statement.............................................................................................................719RESTPUT (FTP server) statement........................................................................................................... 720RETPD (FTP client and server) statement...............................................................................................720SBDATACONN (FTP client and server) statement...................................................................................722SBSENDEOL statement (FTP client and server) statement....................................................................723SBSUB (FTP client and server) statement.............................................................................................. 725SBSUBCHAR (FTP client and server) statement.....................................................................................725SBTRANS (FTP client) statement............................................................................................................ 726SECONDARY (FTP client and server) statement..................................................................................... 727SECURE_CTRLCONN (FTP client and server) statement........................................................................ 728SECURE_DATACONN (FTP client and server) statement....................................................................... 729SECURE_FTP (FTP client and server) statement....................................................................................731SECURE_HOSTNAME (FTP client) statement......................................................................................... 732

    xi

  • SECUREIMPLICITZOS (FTP client and server) statement......................................................................732SECURE_LOGIN (FTP server) statement................................................................................................ 734SECURE_MECHANISM (FTP client) statement.......................................................................................735SECURE_PASSWORD (FTP server) statement........................................................................................736SECURE_PASSWORD_KERBEROS (FTP server) statement....................................................................738SECURE_PBSZ (FTP client and server) statement................................................................................. 739SECURE_SESSION_REUSE (FTP client and server) statement..............................................................740SEQNUMSUPPORT (FTP client) statement............................................................................................. 742SMF (FTP server) statement....................................................................................................................743SMFAPPE (FTP server) statement........................................................................................................... 745SMFDCFG (FTP server) statement.......................................................................................................... 746SMFDEL (FTP server) statement............................................................................................................. 747SMFEXIT (FTP server) statement............................................................................................................748SMFJES (FTP server) statement..............................................................................................................749SMFLOGN (FTP server) statement.......................................................................................................... 750SMFREN (FTP server) statement.............................................................................................................751SMFRETR (FTP server) statement...........................................................................................................752SMFSQL (FTP server) statement............................................................................................................. 753SMFSTOR (FTP server) statement...........................................................................................................754SOCKSCONFIGFILE (FTP client) statement............................................................................................755SPACETYPE (FTP client and server) statement...................................................................................... 756SPREAD (FTP client and server) statement............................................................................................ 757SQLCOL (FTP client and server) statement.............................................................................................757SSLV3 (FTP client and server connection) statement............................................................................ 758STARTDIRECTORY (FTP server) statement............................................................................................ 759STORCLASS (FTP client and server) statement...................................................................................... 759SUPPRESSIGNOREWARNINGS (FTP client and server) statement....................................................... 760TAPEREADSTREAM (FTP server) statement........................................................................................... 761TLSCERTCROSSCHECK (FTP client and server) statement.................................................................... 762TLSMECHANISM (FTP client and server) statement.............................................................................. 762TLSPORT (FTP client and server) statement...........................................................................................763TLSRFCLEVEL (FTP client and server) statement................................................................................... 764TLSTIMEOUT (FTP client and server) statement....................................................................................765TRACE (FTP client and server) statement...............................................................................................766TRACECAPI (FTP client) statement.........................................................................................................766TRAILINGBLANKS (FTP client and server) statement........................................................................... 767TRUNCATE (FTP client and server) statement........................................................................................768UCOUNT (FTP client and server) statement........................................................................................... 768UCSHOSTCS (FTP client and server) statement..................................................................................... 769UCSSUB (FTP client and server) statement............................................................................................770UCSTRUNC (FTP client and server) statement....................................................................................... 770UMASK (FTP client and server) statement..............................................................................................771UNICODEFILESYSTEMBOM (FTP client and server) statement.............................................................772UNITNAME (FTP client and server) statement....................................................................................... 773UNIXFILETYPE (FTP client and server) statement.................................................................................774VCOUNT (FTP client and server) statement............................................................................................776VERIFYUSER (FTP server) statement..................................................................................................... 776VOLUME (FTP client and server) statement............................................................................................778WRAPRECORD (FTP client and server) statement................................................................................. 779WRTAPEFASTIO (FTP client and server) statement............................................................................... 779XLATE (FTP server) statement................................................................................................................ 780FTP server environment variables.......................................................................................................... 781SOCKS configuration statements in SOCKSCONFIGFILE.......................................................................781

    DIRECT statement..............................................................................................................................782SOCKD statement...............................................................................................................................783

    Chapter 15. Syslog daemon................................................................................785

    xii

  • Syslog daemon files.................................................................................................................................785Starting syslogd with a cataloged procedure..........................................................................................785Starting syslogd from the UNIX shell...................................................................................................... 787Syslogd environment variables............................................................................................................... 789Syslogd configuration statements...........................................................................................................792

    Global syslogd configuration statements..........................................................................................792Syslogd rule configuration statement................................................................................................795

    Syslogd browser tool............................................................................................................................... 803Providing library access..................................................................................................................... 804Adding the syslogd browser to the ISPF primary option menu........................................................ 804

    Chapter 16. Policy Agent and policy applications................................................ 807Policy configuration files......................................................................................................................... 807

    Policy Agent configuration files overview..........................................................................................807Policy Agent configuration statements overview.............................................................................. 808General syntax rules for Policy Agent................................................................................................808

    Policy Agent general configuration file statements................................................................................821AutoMonitorApps statement............................................................................................................. 828AutoMonitorParms statement........................................................................................................... 832ClientConnection statement.............................................................................................................. 833Codepage statement..........................................................................................................................834CommonIDSConfig statement...........................................................................................................835CommonIPSecConfig statement....................................................................................................... 836CommonRoutingConfig statement.................................................................................................... 836CommonTTLSConfig statement.........................................................................................................837DynamicConfigPolicyLoad statement................................................................................................838IDSConfig statement..........................................................................................................................844IPSecConfig statement...................................................................................................................... 845LogLevel statement............................................................................................................................846PolicyPerfMonitorForSDR statement.................................................................................................847PolicyPerformanceCollection statement...........................................................................................849PolicyServer statement......................................................................................................................852QOSConfig statement.........................................................................................................................855ReadFromDirectory statement.......................................................................................................... 856RoutingConfig statement................................................................................................................... 862ServerConnection statement.............................................................................................................863ServicesConnection statement..........................................................................................................867SetSubnetPrioTosMask statement.................................................................................................... 870TcpImage and PEPInstance statement.............................................................................................872TTLSConfig statement........................................................................................................................874

    AT-TLS policy statements........................................................................................................................ 876TTLSCipherParms statement.............................................................................................................877TTLSConnectionAction statement.....................................................................................................882TTLSConnectionAdvancedParms statement.....................................................................................884TTLSEnvironmentAction statement.................................................................................................. 890TTLSEnvironmentAdvancedParms statement.................................................................................. 893TTLSGroupAction statement............................................................................................................. 904TTLSGroupAdvancedParms statement............................................................................................. 906TTLSGskAdvancedParms statement.................................................................................................908TTLSGskHttpCdpParms statement................................................................................................... 911TTLSGskLdapParms statement......................................................................................................... 912TTLSGskOcspParms statement.........................................................................................................915TTLSKeyringParms statement........................................................................................................... 922TTLSRule statement...........................................................................................................................922TTLSSignatureParms statement........................................................................................................927

    IDS policy statements............................................................................................................................. 930IDSAction statement..........................................................................................................................930

    xiii

  • IDSAttackCondition statement..........................................................................................................932IDSExclusion statement.................................................................................................................... 940IDSReportSet statement....................................................................................................................942IDSRule statement.............................................................................................................................944IDSScanEventCondition statement................................................................................................... 947IDSScanExclusion statement............................................................................................................ 950IDSScanGlobalCondition statement..................................................................................................951IDSTRCondition statement................................................................................................................ 952

    IPSec policy statements..........................................................................................................................954IpDataOffer statement.......................................................................................................................955IpDynVpnAction statement............................................................................................................... 961IpFilterGroup statement....................................................................................................................967IpFilterPolicy statement.................................................................................................................... 968IpFilterRule statement.......................................................................................................................970IpGenericFilterAction statement.......................................................................................................976IpLocalStartAction statement........................................................................................................... 978IpManVpnAction statement...............................................................................................................984IpService statement...........................................................................................................................991IpServiceGroup statement................................................................................................................ 996KeyExchangeAction statement..........................................................................................................997KeyExchangeGroup statement........................................................................................................ 1004KeyExchangeOffer statement..........................................................................................................1005KeyExchangePolicy statement........................................................................................................ 1011KeyExchangeRule statement...........................................................................................................1015LocalDynVpnGroup statement.........................................................................................................1017LocalDynVpnPolicy statement......................................................................................................... 1018LocalDynVpnRule statement........................................................................................................... 1018LocalSecurityEndpoint statement................................................................................................... 1023RemoteIdentity statement.............................................................................................................. 1028RemoteSecurityEndpoint statement............................................................................................... 1031

    Policy-based routing policy statements............................................................................................... 1035RouteTable statement......................................................................................................................1035RoutingAction statement.................................................................................................................1045RoutingRule statement.................................................................................................................... 1046

    QoS policy statements.......................................................................................................................... 1050PolicyAction statement....................................................................................................................1050PolicyRule statement.......................................................................................................................1058ServiceCategories statement.......................................................................................................... 1065ServicePolicyRules statement......................................................................................................... 1069

    Reusable policy statements..................................................................................................................1072IpAddr statement.............................................................................................................................1073IpAddrGroup statement.................................................................................................................. 1074IpAddrSet statement....................................................................................................................... 1075IpOptionGroup statement............................................................................................................... 1076IpOptionRange statement............................................................................................................... 1076IpProtocolGroup statement.............................................................................................................1077IpProtocolRange statement............................................................................................................ 1078IpTimeCondition statement.............................................................................................................1078Ipv6NextHdrGroup statement.........................................................................................................1080Ipv6NextHdrRange statement........................................................................................................ 1081PortGroup statement....................................................................................................................... 1081PortR