CA TCPaccess FTP Server for z/OS Policy Rule Sets

CA TCPaccess FTP Server for z/OS policy rule sets, together with your security package, let you control the transfer of files using FTP. A rule set is a grouping of rules.

An FTP policy rule set contains the following criteria to match the rule to FTP file transfer requests:

You can define a rule set containing FTP policy rules on your CA NetMaster FTM region and load it. You can define many rule sets of policy rules on your CA NetMaster FTM region; however, only one of the rule sets can be loaded at any one time.

The FTP policy rule sets are stored in the CA NetMaster FTM knowledge base and you can maintain them in this region. Rule set maintenance does not effect the loaded policy rule set; to change the loaded rule set, you need to reload it.

To activate a policy rule set, you must load a copy of the rule set.

The loaded policy rule set is enforced if an active SOLVE SSI has set PKTANALYZER=YES and the policy mode is ON. It does not depend on the CA NetMaster FTM region once it is loaded.

The user of the loaded policy rule set is CA TCPaccess FTP Server for z/OS.

Define a Policy Rule Set

To define a policy rule set

  1. Enter /FTADMIN.P.M at the command prompt.

    The FTP Policy Ruleset List panel appears.

  2. Press F4 (Add).

    The FTP Policy Ruleset panel appears.

  3. Complete the following fields:
  4. Press F3 (File).

    The definition is saved in the knowledge base.

Add Policy Rules to a Rule Set

During operation, only one rule set can be loaded; therefore, you should combine all the CA TCPaccess FTP Server for z/OS policy rules that are to be used together into the same rule set. You can create different rule sets to do the following:

To add a policy rule to a rule set

  1. Enter /FTADMIN.P.M at the command prompt.

    The File Transfer Ruleset List appears.

  2. Enter R beside the rule set to which you want to add rules.

    The FTP Policy Rule List appears.

    Note: Policy rules are evaluated in the order that they appear in the list, until a match is made.

  3. Press F4 (Add).

    The FTP Policy Rule panel appears.

  4. Complete the following fields:

More information:

FTP SAF Rule Considerations

How to Set Up a SAF Qualifier Under CA ACF2 for z/OS

How to Set Up a SAF Qualifier Under CA Top Secret for z/OS

How to Set Up a SAF Qualifier Under RACF

Load a Policy Rule Set

When a rule set is complete, you can activate it by loading it.

Note: Only one rule set can be active at any time.

To load a policy rule set

  1. Enter /FTADMIN.P.M at the command prompt.

    The FTP Policy Ruleset List appears.

  2. Type L beside the name of the rule set definition to load.

    The FTP Policy Ruleset panel appears, showing the name of the rule set definition to be loaded.

  3. Complete the following field:

Note: After you have loaded a policy rule set, it is highlighted in white in the rule set list. If you have made any changes to the rule set since it was loaded, then ** MODIFIED ** appears to the right of its name. If you make changes to the loaded rule set, they do not take effect until you reload the rule set.

Set Policy Mode for an Active Policy Rule Set

To set the policy mode for an active policy rule set

  1. Enter /FTADMIN.P.S at the command prompt.

    The FTP Policy Ruleset panel appears.

  2. Complete the following field:


Copyright © 2010 CA. All rights reserved.