OSM access control

The intranode management network is intended for only authorized applications, such as those performing platform performance management functions. For more information about these applications, see IBM z Systems Ensemble Planning Guide.

The intranode management network can be accessed only through OSM interfaces. To use IOCTL calls to retrieve information about an OSM interface or to send or receive data over OSM interfaces on this network, an application must have READ authorization to the EZB.OSM.sysname.tcpname resource. If you start one of these authorized applications on a z/OS® image, authorize the application user ID to this SAF resource. In addition, authorize to this resource any user IDs that might issue diagnostic commands, such as Ping and Traceroute, over OSM interfaces to verify connectivity. Traffic over OSM interfaces is exempt from network access control.

For more information about the intranode management network, see TCP/IP in an ensemble.