Prevent multiple connections from same IP address



All about SAF, RACF, encryption, Firewall, Risk assessment and integrity concepts

Prevent multiple connections from same IP address

Postby poojithas » Sat Sep 28, 2013 3:41 pm

Hi, I have a strange situation where in, our users are not able to connect to mainframe as they are getting blank LU number. After bit research we came to know that some geek is making multiple connections to our mainframe ip address. In our SYS1.TCPPARMS(TN3270) member it has been defined DEFAULTLUS TCPA00001..TCPA00500 ENDDEFAULTLUS , so the geek is making roughly 500 connection from his single IP ( probably doing it by programatically ).
How do we prevent multiple connections coming from a single IP address ? , I'm new to system programming on mainframe, please help.
poojithas
 
Posts: 15
Joined: Sun May 05, 2013 7:11 am
Has thanked: 0 time
Been thanked: 0 time

Re: Prevent multiple connections from same IP address

 

Re: Prevent multiple connections from same IP address

Postby dick scherrer » Mon Sep 30, 2013 6:43 am

Hello,

Suggest you speak with your network people and your security admins. I don't know the answer.

I do know that in my organizations this person would be warned and if this was repeated, they would be terminated.

If this person is Not in your organization, it sounds like you have a Severe Security Problem.
Hope this helps,
d.sch.
User avatar
dick scherrer
Global moderator
 
Posts: 6304
Joined: Sat Jun 09, 2007 8:58 am
Has thanked: 3 times
Been thanked: 91 times

Re: Prevent multiple connections from same IP address

Postby jaggz » Tue Oct 01, 2013 8:09 pm

Hello,

Restrict the user using RACF IP restriction command or put the user behind firewall. Use PAGENT to restrict the number of attempts
User avatar
jaggz
 
Posts: 356
Joined: Fri Jul 23, 2010 8:51 pm
Has thanked: 8 times
Been thanked: 4 times


Return to Mainframe Security

 


  • Related topics
    Replies
    Views
    Last post