Policy types and infrastructure overview

To implement networking policies for your users, you must use the z/OS® Communications Server policy infrastructure. You can use the policy types supported by the Policy Agent for any of the following purposes:

For more information about the policy types, see Policy types.

Based on the policy types that you want to implement, you must configure and start one or more policy infrastructure components:

For more information about syslogd, see Configuring the syslog daemon. For more information about the other policy infrastructure components, see Policy infrastructure components.

To determine the policy infrastructure components that you need to start based on which policy types you are implementing, see Table 1.

Table 1. Policy components needed per policy type
Policy type Component
  One or more instances per LPAR One instance per LPAR One instance per TCP/IP stack in an LPAR
  TCP/IP stack Policy Agent syslogd IKED NSSD DMD NSLAPM2 TRMD
QoS Required Required Required       Optional  
IDS Required Required Required         Required
AT-TLS Required Required Required          
IPSec filters Required Required Required     Optional   Required
IPSec VPNs Required Required Required Optional (dynamic VPNs) Optional (central key and certificate server)     Required
Policy-based routing Required Required Required          

You can use the IBM® Configuration Assistant for z/OS Communications Server for assistance with setting up and configuring security, JCL procedures, and configuration files for the following policy infrastructure components: