Limited supportBMC provides limited support for this version of the product. As a result, BMC no longer accepts comments in this space. If you encounter problems with the product version or the space, contact BMC Support.BMC recommends upgrading to the latest version of the product. To see documentation for that version, see BMC AMI Ops Monitor for IP 3.9.

Enabling the IPSec NMI


Use the following procedure to enable the IPSec network management interface.

Note

If the IKE Daemon (IKED) address space is not active, the NMI will not connect and will fail with RC(00000081) RS(053B006C)and/or RC(00000468) RS(120D0253).

To enable the IPSec NMI

You can enable security by using one of the following methods:

  • Assign superuser status to the user who is associated with the MainView for IP PAS.
  • Add the following RACF resources in the SERVAUTH class:
    • EZB.NETMGMT.sysname.tcpprocname.IPSEC.DISPLAY (The variable sysname is the name of the MVS system on which the PAS is running.)
    • EZB.NETMGMT.sysname.tcpipname.IPSEC.CONTROL
    • EZB.IPSECCMD.sysname.tcpipname.* (The variable is the same for both display and control.)



 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*