Operating System - OpenVMS
1830250 Members
2749 Online
110000 Solutions
New Discussion

Turn off SET HOST for DECnet

 
Jan van den Ende
Honored Contributor

Re: Turn off SET HOST for DECnet

Thomas,

from your Forum Profile:


I have assigned points to 25 of 83 responses to my questions.

One not-yet-rated issue dates back to 2005.

Maybe you can find some time to do some assigning?

http://forums1.itrc.hp.com/service/forums/helptips.do?#33

Mind, I do NOT say you necessarily need to give lots of points. It is fully up to _YOU_ to decide how many. If you consider an answer is not deserving any points, you can also assign 0 ( = zero ) points, and then that answer will no longer be counted as unassigned.
Consider, that every poster took at least the trouble of posting for you!

To easily find your streams with unassigned points, click your own name somewhere.
This will bring up your profile.
Near the bottom of that page, under the caption "My Question(s)" you will find "questions or topics with unassigned points " Clicking that will give all, and only, your questions that still have unassigned postings.

Thanks on behalf of your Forum colleagues.

PS. - nothing personal in this. I try to post it to everyone with this kind of assignment ratio in this forum. If you have received a posting like this before - please do not take offence - none is intended!

PPS. - Zero points for this.

Proost.

Have one on me.

jpe
Don't rust yours pelled jacker to fine doll missed aches.
Wim Van den Wyngaert
Honored Contributor

Re: Turn off SET HOST for DECnet

And do not forget to disable set host /LAT too.

Wim
Wim
Wim Van den Wyngaert
Honored Contributor

Re: Turn off SET HOST for DECnet

To limit the incoming decnet sessions : put RJOBLIM on 0 (just tested it, it works but may be there are side effects).

Wim
Wim
John Abbott_2
Esteemed Contributor

Re: Turn off SET HOST for DECnet

> And do not forget to disable set host /LAT too

I think UAF MOD usr/NOLOCAL fixes this, but I can't test at the mo.

I share Bob's comments on using IDENTIFIERS and restricting access via SYLOGIN, I've used this with success in the past. (hint: F$GETDVI("TT","DEVNAM") )

I can't think of any settings in NCL or SYSGEN that will simply provide what you ask.

Regards
John.
Don't do what Donny Dont does
Wim Van den Wyngaert
Honored Contributor

Re: Turn off SET HOST for DECnet

I would prefer securing that someone gets in instead of getting out. If someone with a "portable VMS" node comes by, he should not be able to get in.

mc latcp set node /connections allows you to secure LAT (in/out).

Wim
Wim
Thomas A. Williams
Regular Advisor

Re: Turn off SET HOST for DECnet

Here's another method I found:

Remote network access:

When a user performs a remote login or task with the SET HOST or COPY command, they are required to enter username and passwords.
This function is controlled by a network object that can be removed from the systems so that only task-to-task communications over the DECnet network is allowed. The task-to-task function does not use the same listener objects as user functions.
To disable these functions the following logicals need to be set to â TRUEâ :

REM$NO_RTTDRIVER
REM$NO_CTDRIVER

This does not affect the ability to access the systems via TCPIP. These services can be disabled by restricting the FTP and TELNET capabilities.
This method is system-wide and will affect specific kinds of access to the node via DECnet. Significant testing is strongly recommended to ensure that functionality is maintained with this method of restriction.

This is what I was trying to remember with the "logicals" reference in my original post
Wim Van den Wyngaert
Honored Contributor

Re: Turn off SET HOST for DECnet

Note that this is decnet 4 only. The rjoblim works on 4 and +.

Wim
Wim
Thomas A. Williams
Regular Advisor

Re: Turn off SET HOST for DECnet

I just tried it on Phase 5 and it works.
Thomas A. Williams
Regular Advisor

Re: Turn off SET HOST for DECnet

Thomas,

from your Forum Profile:


I have assigned points to 25 of 83 responses to my questions.

One not-yet-rated issue dates back to 2005.

Maybe you can find some time to do some assigning?

http://forums1.itrc.hp.com/service/forums/helptips.do?#33

Mind, I do NOT say you necessarily need to give lots of points. It is fully up to _YOU_ to decide how many. If you consider an answer is not deserving any points, you can also assign 0 ( = zero ) points, and then that answer will no longer be counted as unassigned.
Consider, that every poster took at least the trouble of posting for you!

To easily find your streams with unassigned points, click your own name somewhere.
This will bring up your profile.
Near the bottom of that page, under the caption "My Question(s)" you will find "questions or topics with unassigned points " Clicking that will give all, and only, your questions that still have unassigned postings.

Thanks on behalf of your Forum colleagues.

PS. - nothing personal in this. I try to post it to everyone with this kind of assignment ratio in this forum. If you have received a posting like this before - please do not take offence - none is intended!

PPS. - Zero points for this.

Proost.

Have one on me.

jpe

====================================

Its fun to stroke each other off and say how good we are, I guess...

What does that get us? Seems childish to me but what do I know?

Oh, BTW - no offense meant toward you...
Hein van den Heuvel
Honored Contributor

Re: Turn off SET HOST for DECnet

>> What does that get us?

It gets us an indication of how useful the reply was towards helping the stated (or unstated) question.

In an ideal world others with similar questions would SEARCH (with google?) before asking their own question and stumble into this topic.

When the point assignment is done correctly, it allows future readers to focus on specific replies which gets important for longer exchanges like this very topic.

The 8+ range should therefor not be issue indiscriminently, just to stroke, but reserved for replies worth reading in the future. (Because of the technical detail, or because they are otherwise worth while like the great error code I found in my reply :^).

The 0 or 1 points assignments should be used sparingly also, mostly on request, because it really risks ticking of folks. You are addressing a folks in many cultures, and it is best to err on the safe side IMHO. The answer might not have helped you, or stated the obvious for you, but the person put in a (best) effort so you say thank you. Easy.

The Dutch speaking folks here (I am one!)
tend to measure out their points overly carefully/low. Some (seemingly) Indian folks hand out 10 points for a fart. Neither is right.

fwiw,
Hein (0 points for this please !)



Wim Van den Wyngaert
Honored Contributor

Re: Turn off SET HOST for DECnet

OK. works on 5 too. But ...

1) SYSGEN RJOBLIM can be monitored easily. So, if someone changes it, we get an alarm. Not so for logicals (SOX !!!).
2) RJOBLIM is a dynamic param.

fwiw

Wim
(would give it a 1 or 2 myself, but hey, I live about a hundred miles from Hein)
Wim
Thomas A. Williams
Regular Advisor

Re: Turn off SET HOST for DECnet

Hein - I agree to an extent...

BUT

Most folks coming here aren't going to know about OR bother with searching via points, or even attaching any significance to it...

I personally can't be bothered trying to figure it out...

But thats just one opinion out of many... To each his own.

Carry on...
Thomas A. Williams
Regular Advisor

Re: Turn off SET HOST for DECnet

>OK. works on 5 too. But ...

>1) SYSGEN RJOBLIM can be monitored easily. So, if someone changes it, we get an alarm. Not so for logicals (SOX !!!).

>2) RJOBLIM is a dynamic param.

>fwiw

>Wim

Wim - the environment I am involved with administering is highly controlled, so any modification of a system logical OR modification of sylogicals.com would be flagged multiple ways, including via HP Openview.

Additionaly, there would be no way to "temporarily redefine" this logical seeing as how a reboot is required, which would again be red-flagged immediately.

Thanks for the input, though. Kepp 'em coming.

Jeff