0% found this document useful (0 votes)
30 views1,171 pages

IBM i System Administration Course Guide

This document is the Course Guide for IBM i System Administration, specifically for course code OL19G ERC 15.0. It includes information on course content, objectives, and various units covering IBM i concepts and technologies. The document also contains legal notices and trademark information related to IBM products and services.

Uploaded by

addysespinoza80
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
30 views1,171 pages

IBM i System Administration Course Guide

This document is the Course Guide for IBM i System Administration, specifically for course code OL19G ERC 15.0. It includes information on course content, objectives, and various units covering IBM i concepts and technologies. The document also contains legal notices and trademark information related to IBM products and services.

Uploaded by

addysespinoza80
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

V11.

cover

Front cover
Course Guide
IBM i System Administration
Course code OL19G ERC 15.0

Licensed to Deiver Hernandez for class on 3/1/2021


July 2017 edition
Notices
This information was developed for products and services offered in the US.
IBM may not offer the products, services, or features discussed in this document in other countries. Consult your local IBM representative
for information on the products and services currently available in your area. Any reference to an IBM product, program, or service is not
intended to state or imply that only that IBM product, program, or service may be used. Any functionally equivalent product, program, or
service that does not infringe any IBM intellectual property right may be used instead. However, it is the user's responsibility to evaluate
and verify the operation of any non-IBM product, program, or service.
IBM may have patents or pending patent applications covering subject matter described in this document. The furnishing of this
document does not grant you any license to these patents. You can send license inquiries, in writing, to:
IBM Director of Licensing
IBM Corporation
North Castle Drive, MD-NC119
Armonk, NY 10504-1785
United States of America
INTERNATIONAL BUSINESS MACHINES CORPORATION PROVIDES THIS PUBLICATION "AS IS" WITHOUT WARRANTY OF ANY
KIND, EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
NON-INFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Some jurisdictions do not allow disclaimer
of express or implied warranties in certain transactions, therefore, this statement may not apply to you.
This information could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein;
these changes will be incorporated in new editions of the publication. IBM may make improvements and/or changes in the product(s)
and/or the program(s) described in this publication at any time without notice.
Any references in this information to non-IBM websites are provided for convenience only and do not in any manner serve as an
endorsement of those websites. The materials at those websites are not part of the materials for this IBM product and use of those
websites is at your own risk.
IBM may use or distribute any of the information you provide in any way it believes appropriate without incurring any obligation to you.
Information concerning non-IBM products was obtained from the suppliers of those products, their published announcements or other
publicly available sources. IBM has not tested those products and cannot confirm the accuracy of performance, compatibility or any other
claims related to non-IBM products. Questions on the capabilities of non-IBM products should be addressed to the suppliers of those
products.
This information contains examples of data and reports used in daily business operations. To illustrate them as completely as possible,
the examples include the names of individuals, companies, brands, and products. All of these names are fictitious and any similarity to
actual people or business enterprises is entirely coincidental.
Trademarks
IBM, the IBM logo, and [Link] are trademarks or registered trademarks of International Business Machines Corp., registered in many
jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM
trademarks is available on the web at “Copyright and trademark information” at [Link]/legal/[Link].
© Copyright International Business Machines Corporation 1995, 2017.
This document may not be reproduced in whole or in part without the prior written permission of IBM.
US Government Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.

Licensed to Deiver Hernandez for class on 3/1/2021


V11.2
Contents

TOC

Contents
Trademarks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xxii

Course description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xxiii

Agenda . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xxv

Unit 1. IBM i overview and concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Power Systems with IBM i: Integrated by design . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Technology-independent machine interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
POWER Hypervisor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-5
Innovative IBM i technology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-6
Power Systems with IBM i expand rich heritage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-7
The IBM Power Systems family . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-8
The Power Systems with IBM i product line . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-9
POWER processor Technology Roadmap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-10
Single-level storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-12
Power Systems with IBM i devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-13
Sample configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-14
Software overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-15
Licensed Internal Code . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-16
Operating system IBM i (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-17
Operating system IBM i (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-18
Programming support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-19
Application software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-20
Display installed software on a system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-21
CL command structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-22
Library . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-23
Object identification (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-24
Object identification (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-25
Simple name versus qualified name . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-26
Library list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-27
Your job's library list is built at sign-on . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-28
Finding an object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-29
Types of jobs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-30
Starting and ending a job . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-31
Job control summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-32
Job properties (1 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-33
Job properties (2 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-34
Job properties (3 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-35
Job properties (4 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-36
Job properties (5 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-37
Job properties (6 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-38
Job properties (7 of 7) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-39
What is a job description? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-40
Job description attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-41
Message summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-42
Basic message queue communication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-43
Which output queue? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-44
Creating device descriptions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-45

© Copyright IBM Corp. 1995, 2017 iii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Automatic configuration naming conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-47


Additional objects required for remotes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-48
How the pieces fit together (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-49
How the pieces fit together (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-50
How the pieces fit together (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-51
Graphic systems management tool . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-52
Review questions (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-53
Review answers (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-54
Review questions (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-55
Review answers (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-56
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-57

Unit 2. Systems management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-2
IBM i Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3
7.1 was the final release of System i Navigator . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-4
Mobile IBM i Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-5
IBM i Access Family (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-6
IBM i Access Family (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-7
IBM i Access Client Solutions deployment (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-8
IBM i Access Client Solutions deployment (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-9
Main user interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-10
System configurations (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-11
System configurations (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-12
Console configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-13
Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-14
5250 Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-15
5250 Emulation (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-16
5250 Emulation (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-17
5250 Emulation (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-18
5250 Session Manager (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-19
5250 Session Manager (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-20
IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-21
IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-22
Welcome to IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-23
IBM Navigator for i : System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-24
IBM Navigator for i: Monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-26
IBM Navigator for i: Basic Operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-27
IBM Navigator for i: Work Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-29
Configuration and Service (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-30
Configuration and Service (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-32
IBM Navigator for i: Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-33
IBM Navigator for i: Integrated Server Administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-34
IBM Navigator for i: Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-35
IBM Navigator for i: Users and Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-37
Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-38
Journal Management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-39
Performance (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-40
Performance (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-41
Performance (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-42
File Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-44
Backup Recovery and Media Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-46
PowerHA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-48
Additional management enhancements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-51
Temporary and permanent storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-52
Challenges with temporary storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-53

© Copyright IBM Corp. 1995, 2017 iv


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Temporary storage accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-54


Temporary storage buckets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-55
WRKSYSSTS: Improved terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-56
Work with Active Jobs: Temporary Storage Used . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-57
WRKACTJOB: Temporary Storage (F11) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-58
Exercises . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-59
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-60
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-61
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-62

Unit 3. Security concepts and overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2
The objectives of system security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-3
Questions when planning for security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-4
Physical security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-5
Keylock security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-6
Monitoring physical security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-7
System tools used to secure your system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-8
Security is always active . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-10
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-11
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-12
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-13

Unit 4. Security-related system values. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-2
Security components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-3
Security-related system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-4
Locking system values by using service tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-5
4.1. Topic 1: Setting the level of security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-6
Topic 1: Setting the level of security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-7
QSECURITY system value . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-8
QSECURITY system value: Security level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-9
Security level 40 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-11
Steps to change from level 30 to level 40 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-12
Security level 50 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-14
Steps to change to security level 50 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-15
4.2. Topic 2: Using 5250 emulation to configure system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-17
Topic 2: Using 5250 emulation to configure system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-18
Security system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-19
Security-related system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-21
Security-related restore system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-22
System values that apply to passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-23
System values that control auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-24
4.3. Topic 3: Using IBM Navigator for i to configure system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-25
Topic 3: Using IBM Navigator for i to configure system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-26
Configuration and Service: System Values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-27
System Values: Auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-28
System Values: Date and Time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-29
System Values: Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-30
System Values: International system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-31
System Values: Jobs (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-32
System Values: Jobs (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-33
System Values: Jobs (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-34
System Values: Library lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-35
System Values: Messages and Service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-36
System Values: Password (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-37

© Copyright IBM Corp. 1995, 2017 v


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC System Values: Password (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-38


Password rules for changing password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-39
System Values: Performance (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-40
System Values: Performance (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-41
System Values: Power Control (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-42
System Values: Power Control (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-43
System Values: Printing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-44
System Values: Restart (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-45
System Values: Restart (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-46
System Values: Save and Restore (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-47
System Values: Save and Restore (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-48
System Values: Security (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-49
System Values: Security (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-50
System Values: Security (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-51
System Values: Signon . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-52
System Values: Storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-53
System Values: System and User Defaults . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-54
System Values: Network Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-55
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-56
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-57
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4-58

Unit 5. User security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-2
Security components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-3
5.1. Topic 1: User profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-4
Topic 1: User profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-5
Roles served by user profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-6
User profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-7
User profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-8
Appendix B: Default values for user profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-9
New user . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-10
Create a new user: 5250 interface (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-11
Create a new user: 5250 interface (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-12
Create new user: IBM Navigator for i (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-13
Create new user: IBM Navigator for i (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-14
Create new user: IBM Navigator for i (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-15
System privileges: Special authority: SPCAUT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-17
Privilege classes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-18
Create new user: IBM Navigator for i > Capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-19
Create new user: IBM Navigator for i > Jobs (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-21
Create new user: IBM Navigator for i > Jobs (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-22
Display Session: Limit capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-23
Create new user: IBM Navigator for i > Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-24
Create new user: IBM Navigator for i > Personal (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-25
Create new user: IBM Navigator for i > Personal (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-27
Appendix B: IBM-supplied user profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-29
User functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-30
Changing a user profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-32
Application Administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-33
Deleting a user profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-34
Exercise: Working with user profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-35
5.2. Topic 2: Group profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-36
Topic 2: Group profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-37
More facts about group profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-38
Roles served by group profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-39

© Copyright IBM Corp. 1995, 2017 vi


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC New Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-40


New Group: Properties (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-41
New Group: Properties (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-42
Group functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-44
Deleting a group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-45
Exercise: Working with group profiles . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-46
5.3. Topic 3: Service tools security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-47
Topic 3: Service tools security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-48
Service tools user ID administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-49
System service tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-50
Service tools user IDs in SST . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-51
QSECOFR terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-52
Lost password for QSECOFR . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-53
Changing DST passwords: Manual mode procedure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-54
Changing DST passwords: Menu navigation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-55
SST option 7: Allow change of security-related system values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-56
Review questions (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-58
Review answers (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-59
Review questions (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-60
Review answers (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-61
Review questions (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-62
Review answers (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-63
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-64

Unit 6. Resource security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-2
Security components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-3
6.1. Topic 1: Resource security concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-4
Topic 1: Resource security concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-5
User-owned objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-6
Primary group authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-7
QDFTOWN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-8
Where object permissions come from . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-9
Where *PUBLIC authority comes from . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-10
Specific object permissions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-11
Object management permissions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-12
Data permissions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-13
Commonly used permissions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-14
Specifying specific authority for objects in the integrated file system . . . . . . . . . . . . . . . . . . . . . . . . 6-15
6.2. Topic 2: Defining resource security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-17
Topic 2: Defining resource security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-18
Object permission: [Link] file system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-19
Basic and Details permission displays . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-20
Permission: Add and Remove . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-21
Permission: Customize . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-22
Permission: Authorization List . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-23
Change owner: Change Primary Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-24
Permission search order . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-25
6.3. Topic 3: Working with authorization lists. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-26
Topic 3: Working with authorization lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-27
Authorization list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-28
Create an authorization list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-29
Authorization list permissions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-30
Object secured by an authorization list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-31
Securing an object with an authorization list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-32
Authorization list considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-33

© Copyright IBM Corp. 1995, 2017 vii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Authorization list versus group profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-34


Groups and AUTLs compared . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-35
Exercise: Working with authorization lists . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-36
6.4. Topic 4: Column-level authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-37
Topic 4: Column-level authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-38
Column-level security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-39
Granting column-level permission . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-40
Column-level security considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-41
6.5. Topic 5: Row and Column Access Control (RCAC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-43
Topic 5: Row and Column Access Control (RCAC) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-44
What is RCAC? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-45
Row and Column Access Control terms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-46
Row and Column Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-47
6.6. Topic 6: Adopted authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-48
Topic 6: Adopted authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-49
Adopted authority (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-50
Adopted authority (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-51
DSPPGM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-52
Adopted authority (adopting a user profile) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-54
Adopted authority example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-55
Adopted authority (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-56
Adopted authority considerations (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-58
Adopted authority considerations (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-59
Authority checking (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-60
Authority checking (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-61
Fast path for object authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-62
Security example (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-63
Security example (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-64
Security example (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-65
Exercise: Working with object authority and adopted authority . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-66
Review questions (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-67
Review answers (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-68
Review questions (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-69
Review answers (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-70
Review questions (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-71
Review answers (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-72
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-73

Unit 7. Security auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-2
Audit: Why and how? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-3
Auditing: Some events to monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-4
Levels of auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-5
Examine your strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-6
An effective strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-7
Event monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-8
Using the history log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-9
Steps to implement auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-10
Values for the QAUDLVL and QAUDLVL2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-12
Auditing setup (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-14
Auditing setup (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-15
Auditing setup (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-16
Audit journal entries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-18
Audit-related files and messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-19
Action auditing for a specific user . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-20
Action auditing for a specific object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-21

© Copyright IBM Corp. 1995, 2017 viii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC User: Capabilities > Auditing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-22


Printing or viewing audit journal entries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-23
DSPJRN to view a specific entry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-24
DSPJRN to view > F10 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-25
Output DSPJRN to disk > print . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-26
Consider journaling critical files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-28
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-29
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-30
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7-31

Unit 8. Designing security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-2
Designing security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-3
Overall recommendation for security design . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-4
Planning and setting up system security guide . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-5
8.1. Topic 1: Library security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-6
Topic 1: Library security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-7
Library security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-8
8.2. Topic 2: Menu security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-9
Topic 2: Menu security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-10
Menu security: Design guidelines . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-11
User profile session startup: Menu security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-12
Menu security: Sign-on processing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-13
Sign-on processing (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-16
Sign-on processing (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-17
System Request screen security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-18
System Request screen: A secondary job . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-19
Restricting the use of System Request screen options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-20
8.3. Topic 3: Object security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-21
Topic 3: Object security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-22
Object security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-23
Command security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-24
Appendix C: Secured commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-25
System-defined authorities for files and programs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-26
System-defined authorities for libraries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-27
How library authority and object authority work together . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-28
Securing physical versus logical files (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-29
Securing physical versus logical files (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-30
Create Output Queue: Security attributes beyond resource security . . . . . . . . . . . . . . . . . . . . . . . . 8-31
Authority required to perform printing functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-33
Limit access to program function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-34
Authority to workstation (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-36
Authority to workstation (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-37
Data encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-38
8.4. Topic 4: Security save and restore considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-40
Topic 4: Security save and restore considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-41
Restricting save and restore operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-42
Backup and recovery of security information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-43
Authority information saved with an object . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-45
Other authority information that is saved . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-46
Restoring programs with restricted instructions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-47
8.5. Topic 5: Security Tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-48
Topic 5: Security Tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-49
Security tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-50
Security Tools (1 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-51
Security Tools (2 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-53

© Copyright IBM Corp. 1995, 2017 ix


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Security Tools (3 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-55


Security Tools (4 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-57
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-59
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-60
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-61

Unit 9. IBM Power Systems with IBM i: Availability overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-2
9.1. Topic 1: Availability concepts and overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-3
Topic 1: Availability concepts and overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-4
Availability concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-5
Estimating the value of availability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-7
What is an acceptable downtime? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-9
Types of outages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-11
Failure types (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-13
Failure types (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-15
IBM Power Systems with IBM i hardware features (1 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-17
IBM Power Systems with IBM i hardware features (2 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-18
IBM Power Systems with IBM i hardware features (3 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-20
IBM Power Systems with IBM i hardware features (4 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-22
IBM Power Systems with IBM i hardware features (5 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-23
IBM Power Systems with IBM i software features (1 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-24
IBM Power Systems with IBM i software features (2 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-26
IBM Power Systems with IBM i software features (3 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-28
IBM Power Systems with IBM i software features (4 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-30
IBM Power Systems with IBM i software features (5 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-32
IBM Power Systems with IBM i software features (6 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-33
9.2. Topic 2: LPAR and HMC concepts and overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-34
Topic 2: LPAR and HMC concepts and overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-35
PowerVM virtualization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-36
PowerVM virtualization editions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-38
What is logical partitioning? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-39
Allocating resources on an LPAR system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-41
Partition resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-43
Power Systems and operating systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-44
POWER Hypervisor functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-46
Software licensing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-48
Why would I use logical partitions? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-49
LPAR allows for consolidation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-50
HMC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-51
vHMC (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-52
VHMC (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-53
HMC and managed system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-54
Power Systems management: Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-55
HMC specification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-57
HMC interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-58
HMC interfaces classic versus enhanced . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-59
HMC user interfaces and access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-60
Remote access to the HMC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-61
Dynamic partitioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-62
How DLPAR works . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-63
Processor concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-64
Micro-Partitioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-66
Single Shared Pool with Capped and Uncapped Partitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-67
Capacity on demand . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-69
Virtual I/O . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-71

© Copyright IBM Corp. 1995, 2017 x


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC LPAR configuration process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-73


Where can I find more information on LPAR? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-75
9.3. Topic 3: Clustering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-76
Topic 3: Clustering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-77
PowerHA SystemMirror . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-78
PowerHA SystemMirror solutions overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-80
PowerHA SystemMirror Editions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-81
Clustering: What is a cluster? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-83
Clustering: Device Domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-85
Clustering: Cluster Resource Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-86
Clustering: Cluster Administrative Domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-89
Clustering: Copy Description and ASP Session . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-91
9.4. Topic 4: PowerHA Solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-92
Topic 4: PowerHA Solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-93
FlashCopy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-94
Geographic Mirroring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-95
Metro Mirror (Synchronous Copy) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-96
Global Copy: (Asynchronous PPRC) Continuous Copy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-97
Global Mirror - with Consistency Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-98
Global Mirror + Change Volumes (SVC Storwize) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-99
Global Mirror (Symmetrical): DS8000 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-100
Topic summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-101
Where can I find more information on clustering? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-102
9.5. Additional topics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-103
Topic 5: Additional topics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-104
Uninterruptible power supply . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-105
Power System action after power restored . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-106
UPS: System values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-110
UPS: When power fails . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-111
UPS: Time line of QUPSDLYTIM function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-112
UPS: Power loss controlled shutdown . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-113
UPS: Power handling program . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-114
Review questions (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-115
Review answers (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-116
Review questions (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-117
Review answers (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-118
Review questions (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-119
Review answers (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-120
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9-121

Unit 10. Disk management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-2
10.1. Topic 1: Concepts and overview of auxiliary storage pools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-3
Topic 1: Concepts and overview of auxiliary storage pools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-4
Types of disk pools (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-5
Types of disk pools (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-6
IASP: Extension of single level storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-8
Disk pool groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-9
Characteristics of IASPs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-10
Encryption for IASP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-11
Job namespace . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-12
Namespace . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-13
IASP supported object types as of IBM i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-14
IASP unsupported object types as of IBM i 7.2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-16
Libraries in an IASP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-17
IFS in an IASP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-18

© Copyright IBM Corp. 1995, 2017 xi


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC IFS objects in IASPs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-19


IASP visibility . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-20
Key concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-21
ASP benefits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-22
System ASP (ASP1) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-23
IBM Power Systems with IBM Navigator for i: Storage System Values . . . . . . . . . . . . . . . . . . . . . 10-25
User ASPs (ASP2-ASP32) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-26
Additional ASP considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-27
10.2. Topic 2: Concepts and overview of device parity protection: RAID-5 RAID-6 RAID10 . . . . . . . . . 10-28
Topic 2: Concepts and overview of device parity protection: RAID-5 RAID-6 RAID10 . . . . . . . . . . 10-29
Device parity protection (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-30
Device parity protection (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-31
RAID-5 RAID-6 and RAID-10 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-32
RAID-10 concept . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-34
Device parity protection benefits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-35
Device parity protection on input/output adapters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-36
Changing parity protection optimization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-38
Device parity protection limitations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-39
Write cache and auxiliary write cache IOA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-40
Disk protection with dual storage - RAID . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-42
Multi-initiator HA mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-43
10.3. Topic 3: Concepts and overview of mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-44
Topic 3: Concepts and overview of mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-45
Mirrored protection: Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-46
Mirroring definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-48
Mirrored protection: Benefits and considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-50
Disk-level mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-52
IOA-level mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-54
Bus-level mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-55
Expansion unit level mirrored protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-56
Protection level . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-57
Disk protection with dual storage - mirror . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-59
Mirroring performance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-60
Concurrent maintenance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-61
Mirrored protection planning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-62
Mirrored failure scenario . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-65
Mirroring versus device parity protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-66
10.4. Topic 4: Hot spare protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-68
Topic 4: Hot spare protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-69
Hot spare concept . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-70
Hot spare cost and limitations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-71
Starting stopping hot spare (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-73
Starting stopping hot spare (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-74
Managing hot spare . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-75
10.5. Topic 5: Multipathing. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-76
Topic 5: Multipathing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-77
Multipathing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-78
10.6. Topic 6: Disk configuration and recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-79
Topic 6: Disk configuration and recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-80
Disk configuration and protection procedures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-81
Recovery of disk failure or disk errors (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-82
Recovery of disk failure or disk errors (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-83
DASD disk management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-84
Work with Disk Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-85
Work with Disk Unit Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-88
10.7. Topic 7: Abnormal system end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-90

© Copyright IBM Corp. 1995, 2017 xii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Topic 7: Abnormal system end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-91


Abnormal system end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-92
Restart after abnormal end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-94
Edit Rebuild of Access Paths . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-96
Edit Check Pending Constraints . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-98
Review questions (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-99
Review answers (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-100
Review questions (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-101
Review answers (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-102
Review questions (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-103
Review answers (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-104
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-105

Unit 11. Backup and recovery strategy using save/restore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-2
11.1. Topic 1: Overview of the save/restore capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-3
Topic 1: Overview of the save/restore capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-4
How important is save/restore? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-5
Uses for the save and restore capabilities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-6
Failures that can occur . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-7
11.2. Topic 2: Media used to back up your system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-8
Topic 2: Media used to back up your system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-9
Managing tapes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-10
Tape and tape library system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-12
Manage tapes and tape libraries 5250 interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-14
IBM Navigator for i: Manage tapes and tape libraries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-16
INZTAP: Initialize Tape . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-17
Virtual tape support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-19
Virtual tape implementation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-21
Create a virtual tape device description (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-23
Create a virtual tape device description (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-24
Create the image catalog for virtual tape support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-25
Create image catalog through IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-26
Work with Image Catalog WRKIMGCLG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-27
Create new virtual volume: ADDIMGCLGE command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-28
IBM Navigator for i: Create new virtual volume . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-30
Load image catalog: LODIMGCLG command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-31
Optical storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-33
IBM i: Installing Partition from an Image Catalog (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-35
IBM i: Installing Partition from an Image Catalog (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-36
IBM i: Installing Partition from an Image Catalog (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-37
IBM i network installing / upgrading multiple systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-39
Exercise: Media devices and virtual tape . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-40
11.3. Topic 3: Save operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-41
Topic 3: Save operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-42
SAV commands and menu options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-43
Save menu . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-44
SAVE option 21: Entire system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-46
SAVE option 22: System data only . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-47
SAVE option 23: All user data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-48
How the system performs save processing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-49
Where to perform the save to? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-50
SAVLIB: Save Library (1of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-51
SAVLIB: Save Library (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-53
SAVOBJ: Save Object (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-54
SAVOBJ: Save Object (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-55

© Copyright IBM Corp. 1995, 2017 xiii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC SAVCHGOBJ: Save Changed Objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-56


File systems: Save commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-57
SAVSYSINF command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-59
SAVSYSINF command considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-61
SAVSYSINF backup strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-62
Parameter: Save-while-active . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-63
Save-while-active parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-64
Save-outage time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-66
Checkpoint processing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-68
SAVF: Saving using a save file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-70
SAVF: Save File Commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-72
Miscellaneous SAV commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-74
Using Operational Assistant . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-76
Using BRMS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-77
IBM Navigator for i BRMS plugin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-78
Save tips and hints . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-79
11.4. Topic 4: Restore operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-81
Topic 4: Restore operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-82
Relationship between save and restore commands . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-83
Restore overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-84
Restore menu (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-85
RESTORE option 21: System and user data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-86
Restore menu (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-87
RESTORE option 22: System data only . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-88
RESTORE option 23: All user data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-89
Restore menu (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-90
What happens when you restore data? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-91
Sequence for restoring data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-94
Putting your system in a restricted state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-95
Recovery from an unsuccessful restore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-97
Special considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-99
Exercise: Save/Restore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-101
11.5. Topic 5: LPAR save/restore considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-102
Topic 5: LPAR save/restore considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-103
Logical partitions: Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-104
HMC: Backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-106
HMC: Restore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-107
LPAR save considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-108
Saving LPARs: Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-109
LPAR restoring: Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-110
Restore for LPARs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-111
D: IPL of partition from HMC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-112
Review questions (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-113
Review answers (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-114
Review questions (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-115
Review answers (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-116
Review questions (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-117
Review answers (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-118
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11-119

Unit 12. Journal management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-2
12.1. Topic 1: Journal management concepts. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-3
Topic 1: Journal management concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-4
Think about your most important data file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-5
Single-level storage . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-6

© Copyright IBM Corp. 1995, 2017 xiv


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Journal objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-7


Objects that can be journaled . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-8
Display Journal Entries . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-10
Display Journal Entry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-11
F10 = Display only entry details . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-13
12.2. Topic 2: Steps to implement journaling. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-14
Topic 2: Steps to implement journaling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-15
Implementing journaling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-16
Step 1: CRTJRNRCV command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-18
Step 2: CRTJRN command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-19
Step 3a: Access path command (STRJRNAP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-20
Step 3b: Library command (STRJRNLIB) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-21
Step 3c: Object command (STRJRNOBJ) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-22
Step 3d: Physical file command (STRJRNPF) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-23
Step 3e: IFS object command (STRJRN) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-24
IBM Navigator for i: Journaling Management (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-25
IBM Navigator for i: Journaling Management (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-26
Save objects . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-27
12.3. Topic 3: Journal receiver considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-28
Topic 3: Journal receiver considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-29
Managing the receiver chain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-30
System change journal management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-32
Journal receiver chain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-34
WRKJRNA command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-35
F15 = Work with Receiver Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-37
12.4. Topic 4: Determining the recovery points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-39
Topic 4: Determining the recovery points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-40
Determine the best recovery points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-41
Display Journal (1 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-42
Display Journal (2 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-44
Display Journal (3 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-45
Display Journal (4 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-46
Display Journal (5 of 5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-48
Journal codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-49
Finding the recovery point . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-50
Command to send a user entry . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-51
12.5. Topic 5: Performing a recovery. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-52
Topic 5: Performing a recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-53
Work with Journals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-54
Forward recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-56
Select option 2 to start forward recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-57
Forward recovery object type . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-58
Work with Forward Recovery for Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-59
Backout recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-61
Select option 3 to start backout recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-62
Backward recovery object type . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-63
Work with Backout Recovery for Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-64
APYJRNCHG command (forward recovery) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-65
RMVJRNCHG command (backout recovery) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-67
Operations that cause incomplete recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-68
Illogical conditions that stop APYJRNCHG or RMVJRNCHG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-70
12.6. Topic 6: Additional journaling topics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-71
Topic 6: Additional journaling topics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-72
SAVCHGOBJ: Journaling considerations (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-73
SAVCHGOBJ: Journaling considerations (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-75
SAVCHGOBJ: Journaling considerations (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-76

© Copyright IBM Corp. 1995, 2017 xv


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Which files should be journaled? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-77


How should files be assigned to journals? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-78
Should journal receivers be in a user ASP? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-79
Restore considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-80
Other journal considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-81
File journaling summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-82
Exercise: Journal management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-83
12.7. Topic 7: Remote journaling. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-84
Topic 7: Remote journaling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-85
Remote journal . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-86
Remote journal: Hot backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-87
Remote journal benefits . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-89
Remote journal commands and API . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-90
12.8. Topic 8: Access path protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-92
Topic 8: Access path protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-93
Introduction to access path journaling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-94
Access path protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-95
Access path's contribution to IPL time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-96
Edit Rebuild of Access Paths: EDTRBDAP command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-99
Explicit access path journaling (protection) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-101
System-managed access-path protection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-103
SMAPP performance and auxiliary storage use . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-105
Edit Recovery for Access Paths (EDTRCYAP) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-106
SMAPP contribution to system performance (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-109
SMAPP contribution to system performance (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-110
SMAPP summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-111
Review questions (1 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-112
Review answers (1 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-113
Review questions (2 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-114
Review answers (2 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-115
Review questions (3 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-116
Review answers (3 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-117
Review questions (4 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-118
Review answers (4 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-119
Review questions (5 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-120
Review answers (5 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-121
Review questions (6 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-122
Review answers (6 of 6) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-123
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12-124

Unit 13. Commitment control overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-2
What is commitment control? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-3
Why commitment control? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-4
Complex transactions with multiple users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-5
Functions of commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-6
Commitment control: Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-7
Rollback event . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-8
Previous example with commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-9
Commitment control requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-10
Start Commitment Control (STRCMTCTL) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-11
Record lock-level parameter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-13
Notify object parameter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-14
When is the notify object updated? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-16
Commitment control implementation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-17
Commitment control: Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-18

© Copyright IBM Corp. 1995, 2017 xvi


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Enhancements to database savepoints . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-19


IASP considerations for commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-20
XA transaction support for commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-23
IBM Navigator for i: Commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-25
IBM i Navigator: Support for commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-26
Exercise: Commitment control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-27
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-28
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-29
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13-30

Unit 14. Backup and recovery planning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-2
14.1. Topic 1: The environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-3
Topic 1: The environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-4
Balance costs of backup and recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-5
Can your business still function? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-6
Backup and recovery plan evaluation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-7
What to save and how often? (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-8
What to save and how often? (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-9
What to save and how often? (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-10
Save window/save strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-11
Simple save strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-13
Medium save strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-15
Complex save strategy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-16
Availability options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-18
Availability options by failure type: Recovery time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-19
14.2. Topic 2: Creating a disaster recovery plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-20
Topic 2: Creating a disaster recovery plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-21
Disaster recovery plan: Major goals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-22
Disaster recovery plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-23
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-25
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-26
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14-27

Unit 15. Problem determination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-2
15.1. Topic 1: Problem determination concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-3
Topic 1: Problem determination concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-4
Problem determination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-5
Problem determination process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-6
Classification of symptoms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-7
Problem solving tools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-9
SG24-8253: Diagnostic tools Redbooks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-11
15.2. Topic 2: Problem determination using 5250 emulation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-12
Topic 2: Problem determination using 5250 emulation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-13
Work with Active Jobs command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-14
Work with Active Jobs screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-15
Work with Job . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-16
Option 3: Display Job Run Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-17
Option 10: Job log or DSPJOBLOG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-18
Ending a job . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-19
End Job Abnormal . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-20
Display system operator messages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-21
History log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-22
Problem analysis: History log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-23
DSPLOG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-24

© Copyright IBM Corp. 1995, 2017 xvii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC DSPLOG QHST . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-25


Saving and deleting history logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-26
Copy screen . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-27
15.3. Topic 3: Problem determination using IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-28
Topic 3: Problem determination using IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-29
Active Jobs: Details . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-30
Active Jobs: Job Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-31
Active Jobs: Elapsed Performance Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-32
Job properties: General . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-33
Job properties: Performance and Printer Output . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-34
Job properties: Messages and Job Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-35
Job properties: Server and Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-36
Job properties: Date/Time and International . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-37
Job properties: Threads, Resources, and Other . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-38
End a job . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-39
Active Pools: Performance statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-40
System operator messages (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-42
System operator messages (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-43
15.4. Topic 4: Using the power off switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-44
Topic 4: Using the power off switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-45
Why use the power switch? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-46
Power down initiation using power push button or power switch . . . . . . . . . . . . . . . . . . . . . . . . . . 15-47
What can I do to help minimize problems? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-48
15.5. Topic 5: System cleanup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-49
Topic 5: System cleanup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-50
Cleaning up your system . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-51
Automatic cleanup (Operational Assistant) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-52
Tailoring automatic cleanup (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-53
Tailoring automatic cleanup (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-54
Tailoring automatic cleanup (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-55
Reorganize file . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-56
Reorganize file or table . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-57
Clear Save File (CRLSAVF) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-58
Reclaim Storage (RCLSTG) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-59
RCLSTG command . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-60
After running RCLSTG . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-61
Exercise: Problem determination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-62
Review questions (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-63
Review answers (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-64
Review questions (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-65
Review answers (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-66
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15-67

Unit 16. Introduction to Backup Recovery and Media Services. . . . . . . . . . . . . . . . . . . . . . . . . . 16-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-2
16.1. Topic 1: Overview of BRMS functions and features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-3
Topic 1: Overview of BRMS functions and features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-4
BRMS software (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-5
Backup Recovery and Media Services (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-6
BRMS: Restrictions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-8
Supported tape systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-9
FlashCopy support: Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-10
Overview of BRMS standard product functionality . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-12
BRMS main menu (GO BRMS) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-14
BRMS policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-15
Backup control groups (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-17

© Copyright IBM Corp. 1995, 2017 xviii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Backup control groups (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-18


Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-19
Media management (WRKMEDBRM) (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-20
Media management (WRKMEDBRM) (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-21
Media information (WRKMEDIBRM) (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-22
Media information (WRKMEDIBRM) (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-23
Recovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-24
Recovery with WRKMEDIBRM . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-25
Archive and Retrieval . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-26
Archive . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-27
Retrieval . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-28
Set Retrieve . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-29
Migration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-30
Migration control group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-31
Migration process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-32
BRMS network (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-33
BRMS network (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-35
BRMS Enterprise . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-36
BRMS Enterprise overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-37
BRMS Enterprise two models . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-38
BRMS Enterprise function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-39
BRMS Enterprise terminology (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-40
BRMS Enterprise terminology (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-42
How do I access the BRMS Enterprise function? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-44
Cloud Storage Solutions usage concepts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-45
IBM Cloud Storage Solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-46
IBM Cloud Storage Solutions for i (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-47
IBM Cloud Storage Solutions for i (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-48
Cloud Storage Solutions for i (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-49
Cloud storage: Cached backup IBM i environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-50
IBM i Cloud Storage Solutions for i (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-51
IBM i Cloud Storage Solutions for i (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-52
16.2. Topic 2: Overview of IBM Navigator for i and BRMS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-53
Topic 2: Overview of IBM Navigator for i and BRMS . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-54
IBM Navigator for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-55
16.3. Topic 3: Reference material . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-56
Topic 3: Reference material . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-57
BRMS wikis: developerWorks page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-58
BRMS Knowledge Center . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-59
Publications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-60
Where can I get education? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-61
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-62
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-63
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16-64

Unit 17. Power HA/DR solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-2
17.1. Topic 1: PowerHA overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-3
Topic 1: PowerHA overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-4
PowerHA SystemMirror . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-5
Lab services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-6
17.2. Topic 2: PowerHA solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-7
Topic 2: PowerHA solutions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-8
Geographic Mirroring (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-9
Geographic Mirroring (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-10
LUN-level switching (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-11

© Copyright IBM Corp. 1995, 2017 xix


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC LUN-level switching (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-12


FlashCopy: Single IASP multiple times to single target (1 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-13
FlashCopy: Single IASP multiple times to single target (2 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-14
FlashCopy: Single IASP multiple times to multiple targets (3 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . 17-15
FlashCopy: Single IASP multiple times to multiple targets (4 of 4) . . . . . . . . . . . . . . . . . . . . . . . . . 17-16
FlashCopy multiple IASPs to single target (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-17
FlashCopy multiple IASPs to single target (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-18
Live Partition Mobility (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-19
Live Partition Mobility (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-20
HyperSwap (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-21
HyperSwap (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-22
Full System FlashCopy (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-23
Full System FlashCopy (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-24
Full System Replication (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-25
Full System Replication (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-26
Independent Copy Services Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-27
Metro-Global Mirror (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-28
Metro-Global Mirror (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-29
Metro-Global Mirror (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-30
17.3. Topic 3: PowerHA/DR complex combinations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-31
Topic 3: PowerHA/DR complex combinations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-32
Metro-Global Mirror + FlashCopy (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-33
Metro-Global Mirror + FlashCopy (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-34
Live Partition Mobility + LUN-level switching (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-35
Live Partition Mobility + LUN-level switching (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-36
Live Partition Mobility + Metro-Global Mirror (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-37
Live Partition Mobility + Metro-Global Mirror (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-38
Full System FlashCopy for System with IASP (1 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-39
Full System FlashCopy for System with IASP (2 of 2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-40
Full System FlashCopy + Replication (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-41
Full System FlashCopy + Replication (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-42
Full System FlashCopy + Replication (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-43
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-44
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-45
Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17-46

Unit 18. Power SC for i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-1


Unit objectives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-2
PowerSC Tools for IBM I (1 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-3
PowerSC Tools for IBM I (2 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-4
PowerSC Tools for IBM I (3 of 3) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-5
Compliance Assessment and Reporting Tool Centralized reporting of IBM i security . . . . . . . . . . . 18-6
Security diagnostics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-7
Privileged Access Control . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-8
Network interface firewall for IBM i exit points . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-9
Password validation / synchronization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-10
IBM i password validation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-11
Two Factor Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-12
Access Control Monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-13
Certificate Expiration Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-14
Single Sign On Suite . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-15
Audit Reporting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-17
Secure Administrator for SAP on IBM i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-18
IBM i Security Services from IBM Systems Lab Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-19
Review questions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-20
Review answers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-21

© Copyright IBM Corp. 1995, 2017 xx


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Contents

TOC Unit summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18-22

© Copyright IBM Corp. 1995, 2017 xxi


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Trademarks

TMK

Trademarks
The reader should recognize that the following terms, which appear in the content of this training
document, are official trademarks of IBM or other companies:
IBM, the IBM logo, and [Link] are trademarks or registered trademarks of International Business
Machines Corp., registered in many jurisdictions worldwide.
The following are trademarks of International Business Machines Corporation, registered in many
jurisdictions worldwide:
Active Memory™ AIX 5L™ AIX®
Concert™ C3® DB™
DB2® developerWorks® Domino®
DS8000® Easy Tier® Electronic Service Agent™
Express® FlashCopy® HyperSwap®
IA® Lotus® Micro-Partitioning®
Notes® OmniFind® Operating System/400®
OS/400® POWER Hypervisor™ Power Systems™
Power Systems Software™ Power® PowerHA®
PowerSC™ PowerVM® POWER6®
POWER7+™ POWER7® POWER8®
ProtecTIER® Rational Team Concert™ Rational®
Redbooks® Service Director™ Storwize®
System i® System Storage® System z®
SystemMirror® 400®
Intel is a trademark or registered trademark of Intel Corporation or its subsidiaries in the United
States and other countries.
Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both.
Windows is a trademark of Microsoft Corporation in the United States, other countries, or both.
Java™ and all Java-based trademarks and logos are trademarks or registered trademarks of
Oracle and/or its affiliates.
UNIX is a registered trademark of The Open Group in the United States and other countries.
VMware is a registered trademark or trademark of VMware, Inc. or its subsidiaries in the United
States and/or other jurisdictions.
SoftLayer® is a trademark or registered trademark of SoftLayer, Inc., an IBM Company.
Other product and service names might be trademarks of IBM or other companies.

© Copyright IBM Corp. 1995, 2017 xxii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Course description

pref

Course description
IBM i System Administration

Duration: 4.5 days

Purpose
This course explains how to plan for, implement, and manage the ongoing operations of the Power
System with IBM i. Emphasis is on security, system availability, backup and recovery, system
software management, and problem determination. You are also introduced to the architecture and
terminology of IBM i and the Power Systems with IBM i.

Important

This course consists of several independent modules. The modules, including the lab exercises,
stand on their own and do not depend on any other content.

Audience
This course is designed for IT managers and their staff who are responsible for:
• Designing and implementing a security plan
• Implementing a backup and recovery plan
• Implementing a system availability plan
• Performing problem determination procedures and activities
This course is not recommended for system operators or end users.

Prerequisites
Before attending this course, students should:
• Attend the System Operator Workshop for IBM i (AS24G) or have the equivalent knowledge
and experience
• Have a basic understanding of security concepts on the Power System with IBM i
• Have a working knowledge of how to perform backup and recovery activities on the system

Objectives
• Describe the features, functions, and benefits of the Power System with IBM i relevant to
security
• Describe the security requirements for your Power System with IBM i

© Copyright IBM Corp. 1995, 2017 xxiii


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Course description

pref • Identify the system security features that satisfy your requirements
• Describe and implement the features and facilities of the Power System with IBM i available to
audit security
• List the elements of a security plan
• Describe the features, functions, and benefits of the Power Systems with IBM i relevant to
availability and recovery
• List the elements of a security plan and a backup and recovery plan
• Describe Power Systems with IBM i problem determination and resolution techniques
• Perform these activities using either a green screen 5250 emulation session (through command
line entry), by using IBM Navigator for i

Curriculum relationship
This course can be substituted by attending two other courses:
• IBM i Security Concepts and Implementation (OL50G/OV50)
• IBM i Recovery and Availability Management (OL51G/OV51)

© Copyright IBM Corp. 1995, 2017 xxiv


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Agenda

pref

Agenda

Note

The following unit and exercise durations are estimates, and might not reflect every class
experience.

Day 1
(00:30) Welcome, course administration, introductions, lab setup
(01:00) Unit 1: IBM i overview and concepts
(00:45) Unit 2: IBM I Management overview
(00:30) Exercise 1: Using IBM i Access Client Solutions
(00:45) Exercise 2: Exploring the user environment
(00:10) Unit 3: Security concepts and overview
(01:00) Unit 4: Security-related system values
(00:40) Unit 5: User security - Topic 1
(00:45) Exercise 3: Working with user profiles

Day 2
(00:10) Unit 5: User security - Topic 2
(00:45) Exercise 4: Working with group profiles
(00:20) Unit 5: User security - Topics 3
(00:45) Unit 6: Resource security - Topics 1 - 3
(00:30) Exercise 5: Working with authorization lists
(00:25) Unit 6: Resource security - Topics 4 - 6
(00:30) Exercise 6: Working with object authority and adopted authority
(00:30) Unit 7: Security auditing
(01:00) Unit 8: Designing security

Day 3
(02:00) Unit 9: IBM Power Systems with IBM i: Availability overview
(01:30) Unit 10: Disk management
(00:45) Unit 11: Backup and recovery strategy using save/restore - Topics 1 - 2
(00:25) Exercise 7: Media devices and virtual tape
(00:45) Unit 11: Backup and recovery strategy using save/restore - Topics 3 - 4

© Copyright IBM Corp. 1995, 2017 xxv


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Agenda

pref
Day 4
(00:25) Exercise 8: Save/restore
(00:30) Unit 11: Backup and recovery strategy using save/restore - Topics 5 - 6
(01:00) Unit 12: Journal management - Topics 1 - 6
(00:50) Exercise 9: Journal management
(00:30) Unit 12: Journal management -Topics 7 - 8
(01:00) Unit 13: Commitment control overview
(00:45) Exercise 10: Commitment control
(01:00) Unit 14: Backup and recovery planning

Day 5
(01:20) Unit 15: Problem determination
(00:45) Exercise 11: Problem determination
(00:45) Unit 16: Introduction to Backup Recovery and Media Services
(00:45) Unit 17: Power HA/DR solutions
(00:25) Unit 18: Power SC for i

© Copyright IBM Corp. 1995, 2017 xxvi


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

Unit 1. IBM i overview and concepts


Estimated time
01:00

Overview
This unit introduces the basic concepts of the IBM Power-based servers running IBM i. This
material is a review of some of the basic concepts that are taught in the prerequisite course,
System i Operator Workshop for V7.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 1-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHWKH,%03RZHU6\VWHPVZLWK,%0LDUFKLWHFWXUH
‡ 'HVFULEHZKDWREMHFWVDUHRQWKH,%0L
‡ ([SODLQWKHV\QWD[RI,%0LFRQWUROODQJXDJH &/ FRPPDQGV
‡ ([SODLQWKHFRQFHSWVRIOLEUDULHVOLEUDU\OLVWDQGMREV
‡ ([SODLQWKHFRQFHSWVRISULQWLQJRQWKH,%0L
‡ ([SODLQWKHGHYLFHGHVFULSWLRQDQGFUHDWLRQSURFHVV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 1-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

3RZHU6\VWHPVZLWK,%0L,QWHJUDWHGE\GHVLJQ

7UDGLWLRQDOV\VWHPV ,%03RZHU6\VWHPVZLWK,%0L
IBM i
‡ +LJKHUOHYHOIXQFWLRQVH[SRVHGWRXVHUVDQG
DSSOLFDWLRQVEDVHGRQ6/,&VHUYLFHV
'LUHFWRU\
%DFNXSDQG ‡ *UDSKLFDOXVHULQWHUIDFH
UHFRYHU\ ‡ 9DVWUDQJHRIKLJKOHYHOODQJXDJHIXQFWLRQV
&&53*&2%2/
7HFKQRORJ\LQGHSHQGHQWPDFKLQHLQWHUIDFH
2QOLQHWUDQVDFWLRQ
SURFHVVLQJ 6\VWHP/LFHQVHG,QWHUQDO&RGH
6HFXULW\ ‡ 3URFHVVFRQWURO
‡ 5HVRXUFHPDQDJHPHQW
‡ ,QWHJUDWHG64/FRPSOLDQWGDWDEDVH
5HODWLRQDO ‡ 6HFXULW\HQIRUFHPHQW
GDWDEDVH ‡ 1HWZRUNFRPPXQLFDWLRQV
-DYD ‡ )LOHV\VWHPV
‡ 6WRUDJHPDQDJHPHQW
‡ -DYDYLUWXDOPDFKLQH -90
2SHUDWLQJV\VWHP ‡ 2WKHUSULPLWLYHV

+DUGZDUHDQGPLFURFRGH ELW32:(532:(532:(5

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-2. Power Systems with IBM i: Integrated by design

Many functions that WERE traditionally been performed by system control programs or add-on
programs are integrated into the System Licensed Internal Code (SLIC) so that they can be
performed more efficiently.
SLIC and i together provide efficient use of system hardware resources.
This architectural feature is known as the technology-independent machine interface (TIMI).

© Copyright IBM Corp. 1995, 2017 1-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

7HFKQRORJ\LQGHSHQGHQWPDFKLQHLQWHUIDFH

3URJUDPV

7,0,

6/,&

ELW5,6&KDUGZDUH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-3. Technology-independent machine interface

IBM Power Systems with IBM i are atypical in that they are defined by software, not by hardware.
When a program presents instructions to the machine interface for execution, it thinks that the
interface is the system hardware, but it is not.
The instructions presented to TIMI pass through a layer of microcode before they are “understood”
by the hardware itself.
TIMI and SLIC allow the Power Systems with IBM i to take technology in stride.
New architectural features can be exploited to fully accommodate post reduced instruction set
computer (RISC) technologies, which might incorporate 96-bit or 128-bit processors or shifts to
different processor technologies.

© Copyright IBM Corp. 1995, 2017 1-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

32:(5+\SHUYLVRU

3URJUDPV 3URJUDPV 3URJUDPV


L $,; /LQX[

7,0,

6/,& 2)57$6 2)57$6

32:(5+\SHUYLVRU

ELW5,6&KDUGZDUH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-4. POWER Hypervisor

IBM Power Systems with IBM i work with a different structure when compared to the previous
technologies used with AS/400 and iSeries servers. Above the POWER5 technology-based
hardware is a code layer called the POWER Hypervisor.
This code is part of the firmware shipped with the Power Systems with IBM i hardware.
The POWER Hypervisor resides in flash memory on the Service Processor.
This firmware performs the initialization and configuration of the Power Systems with IBM i
hardware, as well as the virtualization support required to run up to 1000 partitions concurrently on
the IBM Power Systems with IBM i.
Partition Licensed Internal Code (PLIC) allows for management of multiple partitions of the Power
Systems with IBM i hardware.
It is included as part of the POWER Hypervisor.
The layers above the POWER Hypervisor are different for each supported operating system.
The layers of code supporting Linux and AIX consist of system firmware and Run-Time Abstraction
Services (RTAS).

© Copyright IBM Corp. 1995, 2017 1-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

,QQRYDWLYH,%0LWHFKQRORJ\

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-5. Innovative IBM i technology

IBM i has innovative technology built into the operating system throughout its lifecycle.
Here are some aspects of this technology.
These are the things that make IBM i operating system better than the other operating systems out
there.
The IBM i server delivers tremendous capacity growth in its product line. The IBM i Layer, also
known as Technology Independent Machine Interface (TIMI), made it possible to completely
change the underlying hardware with minimum, if any, impact to IBM i applications.
TIMI allows the system to incorporate significant new hardware technology quickly and
transparently. The ease with which customers migrated to these powerful systems is a testimony to
the fundamental strength of the server’s architecture.

© Copyright IBM Corp. 1995, 2017 1-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

3RZHU6\VWHPVZLWK,%0LH[SDQGULFKKHULWDJH
$WHFKQRORJ\IULHQGO\DUFKLWHFWXUHVXSSRUWLQJFRQWLQXRXVLQQRYDWLRQZLWKRXWGLVUXSWLRQ
$6H L6HULHV H6HUYHUL

$6

6\VWHPL

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-6. Power Systems with IBM i expand rich heritage

In 1988 IBM introduced the AS/400, bringing together two of IBM's most successful platforms of the
time: S/36 and S/38.
It was the first of a new generation of servers with a revolutionary virtualized operating system.
It allowed companies to simply write business applications that exploited its integrated database.
In 1995, moved to 64-bit technology. Then, in 2000, delivered Linux for Power, extending the
platform to open applications.
In 2004, delivered POWER5 and support for AIX.
In 2007, delivered POWER6 with the i570.
In 2008 unified UNIX server line, called System p, and System i.
In 2010 delivered POWER7.
In 2014 delivered POWER8.

© Copyright IBM Corp. 1995, 2017 1-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

7KH,%03RZHU6\VWHPVIDPLO\
,QQRYDWLYHSURYHQWHFKQRORJ\SURYLGLQJSODWIRUPFKRLFHWR
PDWFKXQLTXHEXVLQHVVQHHGV

6\VWHP]
7KHIODJVKLSIRU,%0
6\VWHPVLQQRYDWLRQDQGWKH
KHDUWRIDKLJKO\VHFXUH ,%03RZHU6\VWHPV
UHVLOLHQWDQGLQWHJUDWHG ,QVWDOOIDVWHUPDLQWDLQHDVLHU
LQIUDVWUXFWXUH *HWWKHSRZHUWRGRPRUH
VSHQGOHVV

6\VWHP6WRUDJH
&RQQHFWHG3URWHFWHG&RPSOHWH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-7. The IBM Power Systems family

All of IBM's systems and storage, along with the microelectronics upon which they are built, are part
of the same group today the same management structure. The best of IBM's technology is freely
shared among all of the product lines. As a result, we have the most comprehensive and
competitive systems and storage products in the industry today.
Although many common technologies are shared among the various products, each remains
distinct in the markets they serve. Each grew out of separate beginnings.
System z is the class if the industry in mainframes.
System Storage forged ahead with storage virtualization technologies.
Power Systems with IBM i are in a class by themselves. Its beginnings, its roots, are in business
computing. It doesn't require the technical expertise of a mainframe, though it functions with
mainframe characteristics. Its roots are not in personal computing, where Intel-based solutions
began, nor are they in engineering or scientific computing, where UNIX-based solutions began.
OpenPOWER LC servers - A dense, high data throughput server for your enterprise and cloud. Get
the flexibility you need for seamless data center and cloud integration while achieving new insights
faster through acceleration. OpenPOWER servers are different by design - engineered at every
level to be more powerful and open than anything else you can get.

© Copyright IBM Corp. 1995, 2017 1-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

7KH3RZHU6\VWHPVZLWK,%0LSURGXFWOLQH 3RZHU
(
3RZHU
(

3RZHU
66

3RZHU
6 0LGVL]HGWRODUJH
3RZHU HQWHUSULVHV
6

6PDOOWRPLGVL]HG
HQWHUSULVHV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-8. The Power Systems with IBM i product line

In 2000, IBM delivered Linux for POWER, extending the platform to open applications.
Then, in 2004, IBM delivered POWER5 and support for AIX. Step by step, we are moving away
from a platform that many consider exemplifies unique and proprietary, to one that is mainstream
and based on open technology.
In 2007, IBM began the rollout of POWER6 with the 570.
In 2009, IBM began the rollout of POWER7.
In 2014 IBM delivered POWER8 systems.

© Copyright IBM Corp. 1995, 2017 1-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

32:(5SURFHVVRU7HFKQRORJ\5RDGPDS

32:(5

32:(5

32:(5
QP
32:(5
QP
32:(5
QP

   

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-9. POWER processor Technology Roadmap

This visual charts the evolution of the POWER family of processors from the POWER5 in 2004 to
the current generation, POWER8, and even points to the future with POWER9.
Some details are provided as to the density of the components on each generation. The numbers in
the boxes below the graphic of the processor chips represent, in rough terms, the spacing of
components in nanometers or microns.
As these numbers get smaller over time we are seeing the evolution of the technology, of creating
processors with the components more tightly squeezed together. The advantage of this is to
increase the functionality of the processor and at the same time to reduce performance draining
latency.
The boxes below each generation highlight some of the enhancements to functionality associated
with the processor.
• POWER5 introduced simultaneous multi-threading (SMT).
• POWER6 included Altivec extensions that extended the range of high-performance workloads
that could be deployed on Power Systems.
• POWER7 increases the number of cores per chip, includes L3 cache on the chip, and extends
SMT.

© Copyright IBM Corp. 1995, 2017 1-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty
• POWER8 increases the number of cores per chip, includes L3 cache on the chip, and extends
SMT, twice increased bandwidth in comparison with POWER7/7+.
For IBM POWER clients, there is the certainty of the POWER architecture roadmap and the sense
of investment protection along with the proven evolution of the architecture to higher and higher
levels of functionality and performance.
In some comparisons, you can see Processor CPW value. Processor CPW: Represents maximum
relative performance running commercial processing workloads for a processor configuration. Use
this value to compare relative performance between models with the same or different number of
processors.
5250 CPW: Represents the relative performance available to perform 5250 OLTP (interactive)
workloads.

© Copyright IBM Corp. 1995, 2017 1-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

6LQJOHOHYHOVWRUDJH
9LUWXDODGGUHVVVSDFHZLWKREMHFWV
352*5$0 '$7$ '$7$ 352*5$0 '$7$ 352*5$0

352*5$0 352*5$0 '$7$ '$7$ '$7$

'$7$ 352*5$0 '$7$ 352*5$0 '$7$


-2%48(8( 28738748(8(
352*5$0 '$7$
86(5352),/( /,%5$5<

0DLQ $X[LOLDU\
VWRUDJH VWRUDJH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-10. Single-level storage

All system storage (whether main storage or disk storage) is addressed in the same way. This
single, device-independent addressing mechanism means that objects are referred to by name or
name and library, never by disk location. All objects are created as if they reside in a
18,446,744,000,000,000,000-byte address space. That is 18.4 quintillion bytes!
The IBM i's virtual addressing is independent of an object's physical location and also the type,
capacity, and number of disk units on the system.
What this means is that application programs do not require modification in order to take advantage
of new storage technologies. Users can leave all storage management entirely to the machine.

© Copyright IBM Corp. 1995, 2017 1-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

3RZHU6\VWHPVZLWK,%0LGHYLFHV

,QSXW 3URFHVV 2XWSXW

3URFHVVLQJ
XQLW

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-11. Power Systems with IBM i devices

The following devices can be attached to your Power Systems with IBM i:
• Printers
• Workstations
• Tape units
• CD-ROMs
• Remote controllers
• Personal computers (PCs)
• SAN (Storage Area Network) and Ethernet switches
Your system receives data (input) from several devices including each workstation, disk, tape, and
CD-ROM attached to the system. The processing unit (which is contained in the system unit)
processes the data. It performs operations on the input, such as adding numbers together or
comparing two values to determine whether they are the same. The IBM i then saves the data
(output) to disk or tape, or it sends the output to a printer or workstation.

© Copyright IBM Corp. 1995, 2017 1-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

6DPSOHFRQILJXUDWLRQ
,%03RZHU
6\VWHP

:RUNVWDWLRQ /$1 '9'WDSH


FRQWUROOHU 7DSHXQLW 86%
DGDSWHU XQLW

(WKHUQHW

Display
&RQVROH Display

Display

3ULQWHU

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-12. Sample configuration

This visual shows a sample Power System with IBM i configuration, which is the physical and
logical arrangement of devices and programs that make up a data processing system. This
configuration is simple so that it can be easily understood and read. Every Power Systems with IBM
i configuration varies depending on the needs of the business.

© Copyright IBM Corp. 1995, 2017 1-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

6RIWZDUHRYHUYLHZ

$SSOLFDWLRQ
VXSSRUW

3URJUDPPLQJ
VXSSRUW

/LFHQVHG,QWHUQDO
&RGH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-13. Software overview

In addition to knowing which devices are attached to your system and how to operate them, you
should also be familiar with your system software (or programs). A program contains a set of
instructions that allows you to perform one or more related tasks.
There are four primary categories of programs in the IBM i that build on each other. These are
illustrated in the graphic in the visual, and they are (from top to bottom) the application support, the
programming support, IBM i (operating system), and finally, the Licensed Internal Code (LIC).

© Copyright IBM Corp. 1995, 2017 1-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

/LFHQVHG,QWHUQDO&RGH

/LFHQVHG,QWHUQDO&RGH /,& LV


DJURXSRISURJUDPVORFDWHGLQ
VWRUDJHWKDWDOORZV,%0LWRUXQ
RQGLIIHUHQWSURFHVVRUPRGHOV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-14. Licensed Internal Code

Licensed Internal Code (LIC) is provided by IBM and is preinstalled on your Power Systems with
IBM i before the system is shipped.

© Copyright IBM Corp. 1995, 2017 1-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

2SHUDWLQJV\VWHP,%0L RI
‡ 2SHUDWLQJV\VWHP 66 
ƒ 3UHYLRXVO\FDOOHG26DQGL26
ƒ &XUUHQWO\QDPHG,%0L DW9595
‡ 'DWDEDVHPDQDJHPHQWV\VWHP
ƒ '%IRUL
‡ 6XSSRUWIRUDSSOLFDWLRQVQDWLYHWRRWKHURSHUDWLQJV\VWHPV
ƒ 81,;DSSOLFDWLRQSURJUDPPLQJLQWHUIDFHV $3,V SURYLGHFRQIRUPLW\WRPDQ\
81,;VWDQGDUGV
ƒ 3RUWDEOH$SSOLFDWLRQ6ROXWLRQV(QYLURQPHQW 3$6( $,;EDVHGDSSOLFDWLRQV
‡ $,;VXSSRUW
ƒ *XHVWRSHUDWLQJV\VWHP
‡ /LQX[VXSSRUW
ƒ *XHVWRSHUDWLQJV\VWHP

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-15. Operating system IBM i (1 of 2)

You can think of IBM i as the brain of the Power Systems with IBM i. It is a group of system
programs that control the overall operation of the Power System with IBM i. For example, IBM i
allows multiple interactive and batch jobs to run concurrently. It provides the interface that allows
operator control of those jobs and allows security to be set up on your system. i is provided by IBM
and comes preinstalled on your Power System with IBM i.
Although not all IBM i functions are needed in every installation, the full range of functions is
available on every Power System with IBM i.
However, note it is possible to install guest AIX or Linux partition but considering performance and
flexibility better is create Logical Partition LPAR using PowerVM.

© Copyright IBM Corp. 1995, 2017 1-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

2SHUDWLQJV\VWHP,%0L RI
‡ 6\VWHPUHVRXUFHPDQDJHPHQW
ƒ 3URFHVVRUV
ƒ 0HPRU\
ƒ 'LVN
‡ 6\VWHPFRQWUROLQWHUIDFH
ƒ &/VXSSRUW
í +LJKOHYHOSURJUDPPLQJODQJXDJH
ƒ 6\VWHPRUXVHUZULWWHQFRPPDQGV
‡ ,QWHJUDWHGVXSSRUWIRU
ƒ 6HFXULW\
ƒ &RPPXQLFDWLRQV
í 6\VWHPV1HWZRUN$UFKLWHFWXUH 61$ 7UDQVPLVVLRQ&RQWURO3URWRFRO,QWHUQHW3URWRFRO 7&3,3
í :LQGRZV1HWZRUN1HLJKERUKRRGVXSSRUW
í +773$SDFKHDQGVRIRUWK
ƒ 6\VWHPPDQDJHPHQW
í 6\VWHPPDQDJHGDFFHVVSDWKSURWHFWLRQ 60$33
í ,%01DYLJDWRUIRUL
í ,%0L&OLHQW$FFHVV6ROXWLRQV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-16. Operating system IBM i (2 of 2)

© Copyright IBM Corp. 1995, 2017 1-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

3URJUDPPLQJVXSSRUW

-DYD

,/( ,/(
53* &

+$76 ,/(
&2%2/

5DWLRQDO :HE)DFLQJ
'HYHORSHUIRU
3RZHU6\VWHPV
64/

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-17. Programming support

In addition to languages, such as Java, ILE RPG, ILE C, and ILE COBOL, there are tools that assist
you with the edit of source programs, the design of screen displays and menus, and the
deployment of web-based applications.
The Rational Developer for Power Systems Software product consists of the following workstation
tools:
• Source editing support for RPG, COBOL, and DDS
• Remote access to files, members, objects, libraries, and IFS files on the Power System with
IBM i
• Integration with Rational Team Concert for source control and collaborative application
development
• Debugging support for threads and variable changing and monitoring
• WebFacing
• Host Access Transformation Services (HATS)

© Copyright IBM Corp. 1995, 2017 1-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

$SSOLFDWLRQVRIWZDUH
‡ 7UDGLWLRQDODSSOLFDWLRQV
ƒ :RUNORDG
í ,QWHUDFWLYHFKDUDFWHUEDVHG RUJUHHQVFUHHQ
,QWHUDFWLYHFDSDFLW\ ,&3:
í %DWFK QRRQJRLQJXVHULQWHUDFWLRQ
7RWDOFDSDFLW\ &3:
ƒ 6XSSRUWWKURXJKVSHFLILF,%0LMREV
í $SSOLFDWLRQXVHUVDUH,%0LXVHUV
0RUHGHWDLOFRYHUHGLQWKHZRUNPDQDJHPHQWXQLW

‡ &OLHQWVHUYHUDSSOLFDWLRQV
ƒ :RUNORDG
í ,QIRUPDWLRQSURFHVVLQJ
,QWHUDFWLYH%DWFK
í 'DWDEDVHVHUYLQJ
1DWLYH,%0LVHUYHUDSSOLFDWLRQV
7KLUGSDUW\SUHZULWWHQVHUYHUDSSOLFDWLRQV
í ,QWHUDFWLRQZLWK,%0LMREV
$SSOLFDWLRQXVHUVPLJKWRUPLJKWQRWEHNQRZQWR,%0L
! )RUH[DPSOH6$3(536SHFLILFXVHUVNQRZQRQO\WRWKHDSSOLFDWLRQ
! )RUH[DPSOH%DDQ(536SHFLILFXVHUVNQRZQWR,%03RZHU6\VWHPVZLWK,%0L
,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-18. Application software

© Copyright IBM Corp. 1995, 2017 1-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

'LVSOD\LQVWDOOHGVRIWZDUHRQDV\VWHP

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-19. Display installed software on a system

To see a listing of the IBM licensed program products (LPP) installed on a system, you can use both
a 5250 green screen interface or the IBM Navigator for i.
To display this information when using a 5250 emulation session, issue the command Go LICPGM,
and then select option 10 - Display installed software. The command that is being called by this
menu option is Display Software Resources (DSPSFWRSC).
To display this information using IBM Navigator for i:
1. Expand the system folder under My Connections.
2. Expand Configuration and Service.
3. Expand Software.
4. Click Installed Products.

© Copyright IBM Corp. 1995, 2017 1-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

&/FRPPDQGVWUXFWXUH

&RPPDQGQDPH 3DUDPHWHU

CRTLIB LIB(PAYLIB)
$FWLRQ ,WHP .H\ZRUG 9DOXH
DEEUHY

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-20. CL command structure

All IBM i functions are controlled with a single language called control language (CL). CL
commands have a special structure and parameters to tell the system how to perform requested
functions.
Individual commands can be executed on the command line, within a job stream or a program, and
in any type of job by anyone authorized to use a command. Even when a menu option is used to
perform a system function, one or more CL commands are executed by IBM i. There are over 1200
commands available on the Power Systems with IBM i.
Each command consists of a command name followed by zero, one, or several (up to 75) optional
parameters.
• A command name consists of two abbreviated parts: an action and an object on which the
action is performed.
• A parameter also has two parts: a keyword followed by a value in parentheses.
• Commands can be entered from the command line, through the command entry display, or by a
program.

© Copyright IBM Corp. 1995, 2017 1-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

/LEUDU\
2EMHFWQDPH 7\SH /RFDWLRQ
FILEC *FILE 
PROGA *PGM ##
DSPJOB *CMD 

PROGA
FILEC

DSPJOB

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-21. Library

A library is a special type of object that contains a named set of objects and is used to group
objects. Basically, it is a directory to other objects. It is not an allocation of space as on some other
systems.
The only way an object can be located and used is through the library that points to it. The objects
to which a library points are not physically in the library. In fact, they are not necessarily stored next
to one another (contiguously) on disk.
There are many libraries on IBM i. Objects are normally organized by library (either by IBM or the
administrator) based on their relationship to one another. Here are some examples of how objects
can be organized:
• For security
• For backup
• By application
• By owner
• By object type (program versus files)
• By use (production versus test)

© Copyright IBM Corp. 1995, 2017 1-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

2EMHFWLGHQWLILFDWLRQ RI

/LEUDU\QDPHW\SH

/LEUDU\
46<6

/LEUDU\ /LEUDU\
3$<52// 235/,%

3URJUDP )LOH )LOH )LOH


0$67(5 0$67(5 0$67(5 $&&28176

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-22. Object identification (1 of 2)

Every IBM i object has a name, occupies storage, and is stored within a library. Each object can be
created and deleted with CL commands. There are many types of objects on the system. Each
object type has its own identifier.
IBM i uses the object name plus the library name plus the object type to uniquely identify objects on
the Power System with IBM i. The graphic in the visual demonstrates this. There are two objects
named MASTER in library PAYROLL. One is a program (*PGM) and the other is a file (*FILE).
A library is an object used to group related objects and to find objects by name. Thus, a library is a
directory to a group of objects.

© Copyright IBM Corp. 1995, 2017 1-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

2EMHFWLGHQWLILFDWLRQ RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-23. Object identification (2 of 2)

The screen captures in the visual show the name, type, properties, and other characteristics of
each object.
When using a 5250 emulation screen, you can use the WRKLIB command to display the
information.
The alternative is to use the IBM Navigator for i interface. The [Link] file system supports the
Power Systems with IBM i server library structure. This file system gives you access to database
files and all of the other IBM i object types that the library support manages within the system and
basic user auxiliary storage pools (ASPs). To reach object do following:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management click File Systems.
4. Expand Integrated File Systems and then [Link].
5. Click your library to see all objects.

© Copyright IBM Corp. 1995, 2017 1-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

6LPSOHQDPHYHUVXVTXDOLILHGQDPH

6LPSOHQDPH PGM1

YHUVXV

4XDOLILHGQDPH LIB1/PGM1
/LEUDU\ 2EMHFW
QDPH QDPH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-24. Simple name versus qualified name

When an object is referred to simply by its name, the system uses the library list to locate the
object.
When an object is qualified, by also using the library name, the system is able to go directly to the
object without searching the library list.

© Copyright IBM Corp. 1995, 2017 1-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

/LEUDU\OLVW

QSYS *LIBL
6\VWHPOLEUDULHV
QSYS2
PD[LPXP
QHLPSYS
QUSRSYS

3URGXFWOLEUDULHV QRPGLE
QCBLLE

&XUUHQWOLEUDU\ PAYLIB
*CURLIB *USRLIBL
QGPL
8VHUOLEUDULHV QTEMP
PD[LPXP PAYTSTLIB

2QHDVVRFLDWHGZLWKHYHU\MRE

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-25. Library list

The IBM i uses a library list to find the files and programs you need when you run applications. The
library list is a list of libraries that the system searches sequentially for objects needed by the user.
It has two parts: the system portion and the user portion.
The system portion is specified in the QSYSLIBL system value. The system portion is used for i
libraries. The default for this system value does not need to be changed.
The user portion is provided by the QUSRLIBL system value, the initial library list specified in the
user's job description, or commands after the user is signed on. If you have an initial library list, it
overrides the QUSRLIBL system value. Application libraries should be included in the user portion
of the library list.

© Copyright IBM Corp. 1995, 2017 1-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

<RXUMRE VOLEUDU\OLVWLVEXLOWDWVLJQRQ

`
QSYSLIBL QSYS
QSYS2 6\VWHP
QSYS

` QHLPSYS SDUW
QSYS2
QUSRSYS
QHLPSYS
QUSRSYS 3URJUDP

` SURGXFW
SDUW
QUSRLIBL FREDLIB &XUUHQW
86(5352),/(

`
QGPL OLEUDU\
CURLIB(FREDLIB)
QTEMP

`
QGPL 8VHU
 
Job Descr INLLIBL
QTEMP SDUW
PAYLIB

`
QGPL 6,*121
QTEMP
PAYLIB &855(17/,%5$5< FREDLIB

 7KHMREGHVFULSWLRQFDQRYHUULGHV\VWHPYDOXHQUSRLIBL
 9DOXHHQWHUHGRQ6LJQ2QSDQHORYHUULGHVYDOXHLQSURILOH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-26. Your job's library list is built at sign-on

The library list is not a permanent structure. A library list is built for a job when it starts and is
deleted at end of job (EOJ).
A job is any piece of work accomplished on the Power System with IBM i.
Your library list can be modified after sign-on by using CL commands:

• CHGSYSLIBL (Change System Library List) Changes the system libraries


• CHGCURLIB (Change Current Library) Changes the current library
• ADDLIBLE (Add Library List Entry) Changes the user libraries
• RMVLIBLE (Remove Library List Entry) Changes the user libraries
• CHGLIBL (Change Library List) Changes the user libraries
• EDTLIBL (Edit Library List) Changes the user libraries

© Copyright IBM Corp. 1995, 2017 1-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

)LQGLQJDQREMHFW
6LPSOHQDPH &$//3$<
4XDOLILHGQDPH &$//3$<767/,%3$<

46<6 ,14/,% -RE VOLEUDU\OLVW

4&:: 4&;;; 3$< $3 QSYS


QSYS2 6\VWHPOLEUDULHV
QHLPSYS
4&=== 4&<<< 3$< $3 QUSRSYS

QRPG 3URGXFWOLEUDULHV
QCBL
3$<767/,% 3$</,% &XUUHQWOLEUDU\
PAYLIB
$3 3$< 3$< 3$<
QGPL 8VHUOLEUDULHV
QTEMP
3$< $3 3$< 3$< PAYTSTLIB
INQLIB

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-27. Finding an object

Which copy of the program PAY02 is run when it is called using the simple name?
This graphic illustrates how a library list dictates the system's search for objects. Program object
PAY02 from the PAYLIB library would be executed instead of PAY02 from the PAYTSTLIB library
because of the sequence of the libraries in the library list.

© Copyright IBM Corp. 1995, 2017 1-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

7\SHVRIMREV
-RE$XQLWRIZRUNWREHGRQHE\WKHV\VWHP

8VHUMREV
,QWHUDFWLYH
6\VWHPMREV
%DWFK $XWRVWDUW
6SRROLQJ
&RPPXQLFDWLRQ

4XDOLILHGMREQDPH&RQVLVWVRIWKHIROORZLQJWKUHHSDUWV
-REQXPEHU8VHUQDPH-REQDPH
60,7+357,19
,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-28. Types of jobs

A job is the basic unit of work on the system. Every job has a unique name, made up of a system
assigned sequential number, the name of the user running the job, and a user-assigned job name.
Spooling jobs are system-provided print programs (writers) that run similar to batch jobs and
print-spooled printer output. Using work management, you can control these writers.
Interactive jobs are workstation jobs, started when an operator signs on the workstation display and
ended when the user signs off the workstation display.
Traditionally, batch jobs are run by submitting requests for processing of data by programs that do
not need to interact with the user. These requests are placed on a job queue and run when system
resources become available.
Communication jobs are those which are started by a request made over a communication line
from another system.
Autostart jobs are specified to start automatically when their associated subsystem is started.
Autostart jobs typically do such things as set-up or clean up after an application, perform backups
of data files, start devices, or vary on or off communication lines.
Every job on the Power System with IBM i must be associated with a job description.

© Copyright IBM Corp. 1995, 2017 1-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

6WDUWLQJDQGHQGLQJDMRE

-REW\SH 6WDUW (QG


,QWHUDFWLYH 6LJQRQ 6LJQRII
%DWFK 3ODFHGRQMRET (2-
$XWRVWDUW 6WDUWVXEV\VWHP (2-
5HTXHVWIURPUHPRWH 6DPHDVEDWFKRU
&RPPXQLFDWLRQ
V\VWHP LQWHUDFWLYH
6SRROLQJ 6WDUWZULWHUFRPPDQG (QGZULWHUFRPPDQG

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-29. Starting and ending a job

Different types of jobs start and end in different ways.


Each time a user signs on to a workstation, a new interactive job begins. That job continues until
the user signs off.
A batch job begins when the job leaves the job queue.
An autostart job begins when its associated subsystem is started and ends when the job ends.
A communication job begins with a request from a remote system and depending upon whether it is
an interactive or batch job, ends when the user signs off or the job ends.
A spooling job begins when the printer writer is started and ends when the printer is ended.

© Copyright IBM Corp. 1995, 2017 1-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-REFRQWUROVXPPDU\
6%0-2%

-2%4
%$7&+

2874 :5,7(5 35,17(5

,17(5$&7,9(

&$//
WRKJOBQ WRKACTJOB WRKOUTQ WRKWTR
WRKSPLF

WRKUSRJOB
WRKSBMJOB

RU
,%01DYLJDWRUIRUL
,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-30. Job control summary

On this visual, the term job means user jobs, active batch and interactive jobs, jobs on job queues,
and jobs on output queues. After a job starts, you can locate that job, monitor its status and activity,
and change the way it processes, as well as change some of its printing characteristics now and in
the future.

© Copyright IBM Corp. 1995, 2017 1-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-31. Job properties (1 of 7)

Job attributes from the job description and user profile appear in a job's properties. To view this
information, follow these steps:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand Work Management.
4. Then click Active Jobs.
5. For particular job you can right-click to see pop-up menu.
6. For more information about job you can click Details.
7. Additionally you can click Properties to see more information about the job (look at the next
slide).

© Copyright IBM Corp. 1995, 2017 1-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-32. Job properties (2 of 7)

The details of specific jobs can be found on the following tabs:


• General: The job description name being used by the job and the subsystem that is controlling
it
• Performance: The job run priority, Time slice, and performance statistics.

© Copyright IBM Corp. 1995, 2017 1-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV  RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-33. Job properties (3 of 7)

The details of specific jobs can be found on the following tabs:


• Printer Output: Properties that affect the printed output of the job (these can be viewed or
changed).
• Messages allow you to view and change properties related to how messages for the job are
handled.

© Copyright IBM Corp. 1995, 2017 1-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV  RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-34. Job properties (4 of 7)

The details of specific jobs can be found on the following tabs:


• Job Log: Information detail to be kept for the job
• Server: Information about server jobs. For each server job, you can see the type of server, job
user identity, and if available, the client IP address.

© Copyright IBM Corp. 1995, 2017 1-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV  RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-35. Job properties (5 of 7)

The details of specific jobs can be found on the following tabs:


• Security: User profile for the job. Here you can find group profile if exist.
• Date/Time: Settings related to system time (these can be viewed or edited).

© Copyright IBM Corp. 1995, 2017 1-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV  RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-36. Job properties (6 of 7)

The details of specific jobs can be found on the following tabs:


• International: Properties that relate to text, character format, and language associated with the
job (these can be viewed or changed).
• Threads: Properties that relate to threads for a currently active job or one that is in a job queue
(these can be viewed or changed).

© Copyright IBM Corp. 1995, 2017 1-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-RESURSHUWLHV  RI

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-37. Job properties (7 of 7)

The details of specific jobs can be found on the following tabs:


• Resources: Information about system resources, such as memory pool and disk pool group
information for the job, as well as information on memory and processor affinity
• Other: Properties that relate to the accounting code, DDM connections, and switch settings
(these can be viewed or changed)

© Copyright IBM Corp. 1995, 2017 1-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

:KDWLVDMREGHVFULSWLRQ"

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-38. What is a job description?

A job description is an object that contains a set of information (attributes) that specifies how a job
should be run on the IBM i. There are many job descriptions on IBM i.
Each job run on a IBM i must have a job description associated with it. Each job description can
have multiple jobs associated with it.

© Copyright IBM Corp. 1995, 2017 1-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

-REGHVFULSWLRQDWWULEXWHV
‡ $MREGHVFULSWLRQFRQWDLQVDVSHFLILFVHWRIMREUHODWHGDWWULEXWHV
ƒ ,QLWLDOOLEUDU\OLVW
ƒ :KLFKMRETXHXHWRXVH
ƒ 6FKHGXOLQJSULRULW\
ƒ 5RXWLQJGDWD
ƒ 0HVVDJHTXHXHVHYHULW\
ƒ 2XWSXWTXHXHLQIRUPDWLRQ
ƒ 8VHUSDUDPHWHU

‡ 7KHDWWULEXWHVGHWHUPLQHKRZHDFKMRELVUXQRQWKHV\VWHP

• QDFTJOBD LVDV\VWHPVXSSOLHGMREGHVFULSWLRQLQOLEUDU\4*3/

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-39. Job description attributes

The job description holds properties that the job uses as it goes through the work management
lifecycle.
These properties include the user profile the job starts to run under, the request data (which tells the
job what it should do), and the initial user portion of the library list, as well as others.
The job description also holds information that tells the job which job queue to enter and the routing
data.
The routing data is later used by the subsystem to find the routing entry that contains information
needed for the job to start running.
The output queue is also defined within the job description. It tells where printer output (also called
spooled files) from a job goes.

© Copyright IBM Corp. 1995, 2017 1-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

0HVVDJHVXPPDU\
‡ 0HVVDJHV
ƒ 6HQGGLVSOD\UHVSRQGDQGUHPRYH
ƒ ,QIRUPDWLRQDOEUHDNRULQTXLU\
‡ 0HVVDJHTXHXHV
ƒ $OORFDWHDQGFKDQJHGHOLYHU\PRGH
ƒ %UHDNQRWLI\KROGDQGGHIDXOW

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-40. Message summary

Messages are used to communicate with the system or other users, monitor system activity, and
control jobs. The two main types of messages are informational and inquiry messages.
A workstation can communicate with many different message queues that exist on the Power
Systems with IBM i. The system has message queues for each device configured to the system
and a queue for the system operator (QSYSOPR), and application and system programs have
program and job message queues. Message queues are created when a workstation device
description is created, a user profile is created, or with the Create Message Queue (CRTMSGQ)
command.
Message queue modes determine how a message is delivered. There are four delivery modes:
• Break mode (*BREAK): When a message is received that is equal to or exceeds the severity
filter, the terminal alarm sounds, and the message is displayed immediately.
• Notify mode (*NOTIFY): This is the default mode for workstation and user message queues.
The message is held in the message queue, and the message light comes on.
• Hold mode (*HOLD): The user is never notified of messages that arrive in the message queue.
It is the responsibility of the user to periodically look in the queue for messages.
• Default mode (*DFT): Any messages requiring a reply are answered with the default reply set
up for the message. Information only messages are ignored.

© Copyright IBM Corp. 1995, 2017 1-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

%DVLFPHVVDJHTXHXHFRPPXQLFDWLRQ
352),/(
'63 235

CRTDEVDSP: CRTUSRPRF
8VHU
235 PHVVDJH
TXHXH
'63

:RUNVWDWLRQ
PHVVDJH
TXHXH

CRTMSGQ: $5'(37 46<6235 6\VWHPVXSSOLHG

8VHUFUHDWHG 6\VWHPRSHUDWRU
PHVVDJHTXHXH PHVVDJHTXHXH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-41. Basic message queue communication

This visual depicts some of the commands that are associated with and use message and
message queue information.

© Copyright IBM Corp. 1995, 2017 1-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

:KLFKRXWSXWTXHXH"
-REGHVFULSWLRQ

-RE VSURFHVV *USRPRF


2874
DFFHVVJURXS 3$* QDPH

3URJUDP 8VHUSURILOH
2XWSXWWR 'HIDXOW 2874 *WRKSTN
SULQWHU RXWSXWTXHXH QDPH
ILOH
'HYLFHGHVFULSWLRQ
3ULQWHU *DEV
2874
ILOH QDPH

6322/ YES 357'(9 *SYSVAL


QDPH
2874 *JOB
QDPH 6\VWHPYDOXH
PRT01
4357'(9
QDPH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-42. Which output queue?

As each job starts, work management checks the objects (job description, user profile, workstation
device description) and system value (QPRTDEV) in the order shown on the visual to determine
whether a valid output queue name or printer device is defined. Once a valid output queue or
printer device is encountered, the search ends.
If the job description, user profile, and workstation device description all contain default entries for
the output queue and printer device, the printer name in the QPRTDEV system value is used. By
default, this system value contains the name of the first printer configured on the system (usually
PRT01).

© Copyright IBM Corp. 1995, 2017 1-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

&UHDWLQJGHYLFHGHVFULSWLRQV
‡ $XWRPDWLFQAUTOCFG  
ƒ /RFDOZRUNVWDWLRQFRQWUROOHUV
ƒ /RFDOWDSHGULYHV
ƒ /RFDOGLVNHWWHGULYHV
ƒ /RFDOSULQWHUV
ƒ /RFDOGLVSOD\VWDWLRQ
ƒ /RFDODUHDQHWZRUN

‡ 0DQXDO
ƒ 5HPRWHGHYLFHV
ƒ &RPPXQLFDWLRQV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-43. Creating device descriptions

Communicating with the IBM i requires the use of configuration objects, which usually include the
following:
Line descriptions: Line descriptions define the physical interface between the local system and
the remote system, controller, or network and the protocol used for communications. Line
descriptions can also include information about the line speed, whether the line is switched or
non-switched, and the network address or telephone number of the local system.
Controller descriptions: The controller description describes the characteristics of the remote
system, controller, or network that is to communicate with the local system. Controller descriptions
can describe an actual physical controller or logically represent the connection to another system or
network.
Device descriptions: The device description describes the characteristics of the physical or logical
device that is to communicate with the local system. Device descriptions can describe a physical
device or logically represent a communications session or a program running on another system.
These descriptions can be configured either automatically or manually by using CL commands.

© Copyright IBM Corp. 1995, 2017 1-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty
To automatically configure your local controllers and devices, use the system value QAUTOCFG. The
QAUTOCFG (automatic configuration) system value is set to yes by default, if you do not change this
default value then the system continues to automatically configure any local controllers and devices
you attach. This includes any new local workstation controllers and tape controllers and any new
twinaxial display stations, twinaxial printers, tape units, diskette units, optical units, and media
library devices.
The system automatically assigns names to all your local devices. The names that are assigned
depend on what you selected on the Device configuration naming option on the Set Major
Options display. The naming convention that you can select is one of the following:
• Normal naming convention
• System/36 style naming convention
• Naming convention that is based on the device address
The system value that is set with this menu option is QDEVNAMING that controls automatic
configuration naming for your devices.

© Copyright IBM Corp. 1995, 2017 1-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

$XWRPDWLFFRQILJXUDWLRQQDPLQJFRQYHQWLRQV
'HYLFH 1RUPDO 6 '(9$'5

:RUNVWDWLRQFRQWUROOHU CTL01 CTL01 CTL01

'LVSOD\VWDWLRQV DSP01, DSP02 W1, W2 DSP(CPA)*

3ULQWHUV PRT01, PRT02 P1, P2 PRT(CPA)*

'LVNHWWHGULYH DKT01 I1

7DSHGULYH TAP01 T1

3DVVWKUXGHYLFH QPADEV*

6<67(09$/8(QDEVNAMING
& &RQWUROOHU 3 3RUW $ 'HYLFHDGGUHVV
,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-44. Automatic configuration naming conventions

Automatic configuration uses one of three methods for naming your local controllers and devices.
The graphic in the visual shows the normal naming convention (*NORMAL), the System/36 style
naming convention (*S36), and the naming convention that is based on the device address
(*DEVADR).

© Copyright IBM Corp. 1995, 2017 1-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

$GGLWLRQDOREMHFWVUHTXLUHGIRUUHPRWHV

5HPRWH *CTL
ZRUNVWDWLRQ CRTCTLRWS
/LQH FRQWUROOHU

,%0L
*DEV
'LVSOD\ CRTDEVDSP
*LIN

CRTLIN x x x
*DEV
3ULQWHU CRTDEVPRT

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-45. Additional objects required for remotes

A device description is software that identifies a piece of hardware to the system. A user profile is
software that identifies a user to the system. Device configuration for local devices can be created
automatically by the system, but user profiles must be created by a user with *SECADM special
authority.
The Create Controller Description (remote workstation) (CRTCTLRWS) command creates a
controller description for a remote workstation controller. For more information about using this
command, see the Communications Configuration book, SC41-5401. Restriction: You must have
input/output system configuration (*IOSYSCFG) special authority to use this command.
The Create Device Description (display) (CRTDEVDSP) command creates a device description for a
display device. Restriction: You must have input/output system configuration (*IOSYSCFG)
special authority to use this command.
The Create Device Description (printer) (CRTDEVPRT) command creates a device description for a
printer device. Restriction: You must have input/output system configuration (*IOSYSCFG) special
authority to use this command.

© Copyright IBM Corp. 1995, 2017 1-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

+RZWKHSLHFHVILWWRJHWKHU RI

06* 'HYLFH
GHVFULSWLRQ

$XWNH\ZRUG
'HYLFH
GHVFULSWLRQ

$87NH\ZRUG

06*
8VHUSURILOH
*WRKSTN
2874 *DEV
QDPH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-46. How the pieces fit together (1 of 3)

The user profile controls much of what a user can do on the system. This is discussed in the
security unit.

© Copyright IBM Corp. 1995, 2017 1-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

+RZWKHSLHFHVILWWRJHWKHU RI

8VHUSURILOH

&XUUHQWOLEUDU\


,QLWLDOSURJUDP


,QLWLDOPHQX


$XWKRUL]DWLRQV
6SHFLDO
8VHUFODVV
3DVVZRUG

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-47. How the pieces fit together (2 of 3)

The general properties of a job determine how the system runs each job. Some of the properties
are grouped in the job description for easier, multiple job management. The system knows what
properties to get and when based on how the job properties are specified.

© Copyright IBM Corp. 1995, 2017 1-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

+RZWKHSLHFHVILWWRJHWKHU RI
-2%4
-REGHVFULSWLRQ %DWFKMREV


DZDLWLQJH[HFXWLRQ
-RETXHXH



2XWSXWTXHXH

 0DLQVWRUDJH
/LEUDU\OLVW

06*4 2874
0HVVDJHV 2XWSXW
DZDLWLQJYLHZ DZDLWLQJSULQW

8VHUZRUNVWDWLRQ
,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-48. How the pieces fit together (3 of 3)

Job description attributes such as job queue, output queue, and initial library list determine various
aspects of how the job executes and uses resources.

© Copyright IBM Corp. 1995, 2017 1-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

*UDSKLFV\VWHPVPDQDJHPHQWWRRO
‡ ,%01DYLJDWRUIRUL
ƒ :HEEDVHGWRROIRU
PDQDJLQJL
ƒ $GGLWLRQV
í 3HUIRUPDQFH'DWD
,QYHVWLJDWRU
í +LJK$YDLODELOLW\
6ROXWLRQV
0DQDJHU
í %DFNXSDQG5HFRYHU\
0HGLD6ROXWLRQV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-49. Graphic systems management tool

IBM Navigator for i is a web base tool provided as a part of IBM i (no extra charge).

© Copyright IBM Corp. 1995, 2017 1-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH7KH7,0,LVDVHSDUDWHO\RUGHUHGVRIWZDUH

 7UXHRUIDOVH7KLVV\VWHPDGGUHVVHVERWKPDLQVWRUDJH
PHPRU\ DQGDX[LOLDU\VWRUDJH GLVN E\XVLQJWKHVDPH
DGGUHVVLQJVFKHPH

 7UXHRUIDOVH7KH/,&PXVWEHLQVWDOOHGE\WKHFXVWRPHU

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-50. Review questions (1 of 2)

© Copyright IBM Corp. 1995, 2017 1-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH7KH7,0,LVDVHSDUDWHO\RUGHUHGVRIWZDUH
7KHDQVZHULVIDOVH

 7UXH RUIDOVH7KLVV\VWHPDGGUHVVHVERWKPDLQVWRUDJH
PHPRU\ DQGDX[LOLDU\VWRUDJH GLVN E\XVLQJWKHVDPH
DGGUHVVLQJVFKHPH
7KHDQVZHULVWUXH

 7UXHRUIDOVH7KH/,&PXVWEHLQVWDOOHGE\WKHFXVWRPHU
7KHDQVZHULVIDOVH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-51. Review answers (1 of 2)

© Copyright IBM Corp. 1995, 2017 1-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH-DYDLVQRWVXSSRUWHGRQWKLVV\VWHP

 7UXHRUIDOVH8VLQJDVLPSOHQDPLQJFRQYHQWLRQLVWKHEHVW
PHWKRGIRUORFDWLQJRUDFFHVVLQJDQREMHFWRQWKHV\VWHP

 7UXHRUIDOVH7KH*8,DOORZV\RXWRPDQDJH,%0LDVZHOO
DVLQWHUIDFH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-52. Review questions (2 of 2)

© Copyright IBM Corp. 1995, 2017 1-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH-DYDLVQRWVXSSRUWHGRQWKLVV\VWHP
7KHDQVZHULVIDOVH

 7UXHRUIDOVH8VLQJDVLPSOHQDPLQJFRQYHQWLRQLVWKHEHVW
PHWKRGIRUORFDWLQJRUDFFHVVLQJDQREMHFWRQWKHV\VWHP
7KHDQVZHULVIDOVH

 7UXH RUIDOVH7KH*8,DOORZV\RXWRPDQDJH,%0LDVZHOO
DVLQWHUIDFH
7KHDQVZHULVWUXH

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-53. Review answers (2 of 2)

© Copyright IBM Corp. 1995, 2017 1-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 1. IBM i overview and concepts

Uempty

8QLWVXPPDU\
‡ 'HVFULEHWKH,%03RZHU6\VWHPVZLWK,%0LDUFKLWHFWXUH
‡ 'HVFULEHZKDWREMHFWVDUHRQWKH,%0L
‡ ([SODLQWKHV\QWD[RI,%0LFRQWUROODQJXDJH &/ FRPPDQGV
‡ ([SODLQWKHFRQFHSWVRIOLEUDULHVOLEUDU\OLVWDQGMREV
‡ ([SODLQWKHFRQFHSWVRISULQWLQJRQWKH,%0L
‡ ([SODLQWKHGHYLFHGHVFULSWLRQDQGFUHDWLRQSURFHVV

,%0LRYHUYLHZDQGFRQFHSWV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 1-54. Unit summary

© Copyright IBM Corp. 1995, 2017 1-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

Unit 2. Systems management


Estimated time
00:45

Overview
This unit provides an overview of the current available systems management product for IBM i.

How you will check your progress


• Review questions
• Exercises

© Copyright IBM Corp. 1995, 2017 2-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHWKHDYDLODEOHPDQDJHPHQWSURGXFW
‡ 'HVFULEHWKHHQKDQFHPHQWVWR,%0L$FFHVV
‡ 'HVFULEHWKHPDLQIXQFWLRQDOLW\RI,%0&OLHQW$FFHVV6ROXWLRQV
‡ 'HVFULEHWKHHQKDQFHPHQWVRI,%06\VWHPV1DYLJDWRUIRUL
‡ .QRZDGGLWLRQDOPDQDJHPHQWHQKDQFHPHQWV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 2-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%0L$FFHVV

KWWSVZZZ
LEPFRPV\VWHPVSRZHUVRIWZDUH
LDFFHVVLQGH[KWPO

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-2. IBM i Access

© Copyright IBM Corp. 1995, 2017 2-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

ZDVWKHILQDOUHOHDVHRI6\VWHPL1DYLJDWRU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-3. 7.1 was the final release of System i Navigator

IBM System i Navigator stopped being refreshed, and V7.1 was the last version of this product.
However it continues to be supported using PTFs.

© Copyright IBM Corp. 1995, 2017 2-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

0RELOH,%0L$FFHVV
‡ L$FFHVVIRU:HEQHZ0RELOHLQWHUIDFH VKLSSHGZLWK
;+

‡ $FFHVV\RXU,%0LIURP$1<ZHEHQDEOHGPRELOH
GHYLFH
L3KRQH
L3DG
‡ %DVLF6\VWHPDQG0DQDJHPHQWIXQFWLRQ $QGURLG
ƒ 9LHZ&38XWLOL]DWLRQSDJHIDXOWVGLVNXWLOL]DWLRQGLVNSRRO 6XUIDFH
XVDJHMREVDQGRSHUDWRUPHVVDJHVRQDGDVKERDUG
ƒ 9LHZDQGPDQDJHMREVPHVVDJHVRXWSXWTXHXHVILOHV
SULQWHUV
ƒ 9LHZ37)VDQG37)*URXSV
ƒ 9LHZDGGLQVHUWDQGXSGDWHGDWDEDVHUHFRUGV
ƒ %XLOGUXQVDYH64/VWDWHPHQWVZLWKDQ64/ZL]DUG
ƒ 6WDUWRQHRUPRUHHPXODWLRQVHVVLRQVZLWKWKHDELOLW\
WRUHFRQQHFWHYHQDIWHUDGHYLFHSRZHUGRZQ
ƒ ([WUDFWGDWDIURPDYDULHW\RI,%0LUHVRXUFHVLQWRDWDEOH
XVLQJRSWLRQDOFROXPQVHOHFWLRQ
ƒ 'LVWULEXWHDQGPDQDJHILOHVWRRWKHUXVHUVIURPDFRPPRQ
GRZQORDGORFDWLRQ
6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-4. Mobile IBM i Access

© Copyright IBM Corp. 1995, 2017 2-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%0L$FFHVV)DPLO\ RI
7KH,%0L$FFHVV)DPLO\RI3URGXFWV
‡ ,%0L$FFHVVIRU:LQGRZV ;(
í &OLHQW$FFHVV
í 0RVWPDWXUHDQGZLGHO\XVHGSURGXFW
! 6\VWHPL1DYLJDWRU ! 'DWD$FFHVV3URYLGHUV
! 'LVSOD\DQG3ULQWHU(PXODWLRQ ! 5HPRWH&RPPDQG
! 'DWD7UDQVIHU ! 3ULQW'ULYHUV
! 2SHUDWLRQV&RQVROHDQG9LUWXDO&RQWURO3DQHO

ƒ ,%0L$FFHVVIRU:HE ;+
í ,%0L6\VWHP+RVWHG+70/EDVHGZHESURGXFW
í 9HU\UREXVWFDSDELOLW\WKDWKDVEHHQZHOOUHFHLYHG
! 'LVSOD\ ! ,QWHJUDWHG)LOH6\VWHP$FFHVV
! 3ULQW$FFHVV ! &RPPDQGV
! 'DWDEDVH$FFHVV ! -REV

ƒ ,%0L$FFHVVIRU/LQX[ ;/
í /LJKWO\HPEUDFHGSURGXFWVSHFLILFDOO\IRU/LQX[5302SHUDWLQJ6\VWHPV
! 2'%&SURYLGHU
! 'LVSOD\
! 5HPRWH&RPPDQG
6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-5. IBM i Access Family (1 of 2)

© Copyright IBM Corp. 1995, 2017 2-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%0L$FFHVV)DPLO\ RI
‡ ,%0L$FFHVV&OLHQW6ROXWLRQV ;-
ƒ &RQVROLGDWHVFRPPRQO\XVHGWDVNVIRUPDQDJLQJ\RXU,%0LLQWRRQHVLPSOLILHGORFDWLRQ
ƒ 7KHFRUHRIWKHSURGXFWLVD-DYDFOLHQWWKDWLVQRWSODWIRUPVSHFLILF
ƒ 5XQVRQPRVWIXOOIHDWXUHGFOLHQWVHUYHU2SHUDWLQJ6\VWHPVWKDWVXSSRUW-DYDRUKLJKHUVXFKDV
PRVWYHUVLRQVRI:LQGRZV0DFLQWRVKDQG/LQX[
ƒ 6DPHGHSOR\PHQWFRQILJXUDWLRQVHWWLQJVSUREOHPGHWHUPLQDWLRQDFURVVDOOSODWIRUPV
ƒ )HDWXUHVLQFOXGH

í GLVSOD\DQGSULQWHUHPXODWLRQEDVHGRQ,%0 V+RVWRQ'HPDQG
í 6HVVLRQ0DQDJHUVXSSRUWPRGHOHGDIWHU,%03HUVRQDO&RPPXQLFDWLRQV6HVVLRQ0DQDJHU
í 0XOWLSOHODQJXDJHVXSSRUWIRUFRQFXUUHQWHPXODWLRQVHVVLRQVRQWKHVDPHFOLHQW
í 'DWD7UDQVIHUVLPLODUWR,%0L$FFHVVIRU:LQGRZV'DWD7UDQVIHUSOXVVXSSRUWIRU2SHQ'RFXPHQW
VSUHDGVKHHW RGV ([FHO:RUNERRN [OV[ DQGRWKHUILOHIRUPDWV
í 'DWD7UDQVIHULQWHJUDWLRQZLWK([FHODQG2SHQ2IILFH
í 6LPSOLILHG66/&RQILJXUDWLRQ
í 'RZQORDGDQGYLHZLQJRIVSRROILOHV
í ,%0L9LUWXDO&RQWURO3DQHOIRU/$1DQG+0&FRQVROHV
í HPXODWLRQIRU/$1DQG+0&FRQVROHV
í &RQVROLGDWLRQRIKDUGZDUHPDQDJHPHQWLQWHUIDFHFRQILJXUDWLRQVLQFOXGLQJ$60,,90DQG+0&
í 5XQ64/VFULSWV
í 64/3HUIRUPDQFH&HQWHU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-6. IBM i Access Family (2 of 2)

The IBM i Access Client Solutions 5733XJ1 can be downloaded from the Entitled Software Support
(ESS) website under 5761-SS1 (feature codes 5817, 5818, 5819) or 5770-SS1 (feature codes
5817, 5818, or 5819).
For test you can download it also from a technology preview website of this product. It is available
for an evaluation period of 120 days.
[Link]

© Copyright IBM Corp. 1995, 2017 2-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%0L$FFHVV&OLHQW6ROXWLRQVGHSOR\PHQW RI
‡ ,%0L$FFHVV&OLHQW6ROXWLRQVLVQRWLQVWDOOHGWRWKHFOLHQWRSHUDWLQJ
V\VWHPLWLVGHSOR\HG
ƒ 7KHUHLVQRLQVWDOODWLRQSURJUDPIRUWKHFRUHRIWKHSURGXFW

‡ $FFHVV&OLHQW6ROXWLRQVGHSOR\PHQW
ƒ 7KHGHSOR\PHQWLQYROYHVWKHFOLHQWEXQGOHEHLQJSODFHGZKHUHYHULWZLOOEH
H[HFXWHGIURPDQGGHWHUPLQLQJZKHUHWKHSURGXFWVHWWLQJVDUHJRLQJWREH
VWRUHG

‡ &OLHQW%XQGOH
ƒ &RQWDLQVWKH-DYDH[HFXWDEOH-DUSURSHUWLHVILOHSODWIRUPVSHFLILFVWDUW
H[HFXWDEOHVDQG-DYD6FULSWVWDUWVDPSOHVSURGXFWGRFXPHQWDWLRQDQG
OLFHQVLQJQRWLFHV
ƒ $OOWKDWLVUHTXLUHGWREHGHSOR\HGLVWKH-DYDH[HFXWDEOH-DU
ƒ 7KHUHVWLVRSWLRQDO

‡ 1R-5(GLVWULEXWHG
ƒ ,%0L$FFHVV&OLHQW6ROXWLRQVGRHVQRWGHSOR\DVSHFLILF-5(
ƒ 5HOLHVRQD-DYDRUKLJKHU-5(WREHDFFHVVLEOHRQWKHFOLHQW26
6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-7. IBM i Access Client Solutions deployment (1 of 2)

IBM i Access Client Solutions is the newest member of the IBM i Access Family of products. It
provides a Java based platform-independent interface that runs on most operating systems that
support Java including Linux, Mac, and Windows. IBM i Access Client Solutions consolidates the
most commonly used tasks for managing your IBM i into one simplified location.
IBM i Access Client Solutions uses the same IBM i host servers as the other IBM i Access Family
products and requires the same IBM i Access Family license (XW1) in order to use the 5250
emulation and Data Transfer features.
Also, available are two optional packages that include middleware for using and developing client
applications for Windows and Linux:
• IBM i Access Client Solutions - Windows Application Package
• IBM i Access Client Solutions - Linux Application Package

© Copyright IBM Corp. 1995, 2017 2-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%0L$FFHVV&OLHQW6ROXWLRQVGHSOR\PHQW RI
‡ 7KHUHDUHWZRPDLQWKLQJVWKDWFDQEHFRQWUROOHGZLWKWKH,%0L$FFHVV
&OLHQW6ROXWLRQVGHSOR\PHQW
ƒ :KHUHWKHSURGXFWLVODXQFKHGIURP
ƒ :KHUHWKHXVHU¶VFRQILJXUDWLRQLVVWRUHG

‡ %RWKRIWKHVHORFDWLRQVFDQEDVLFDOO\EHDQ\ZKHUHGHVLUHG
ƒ /RFDO3&2SHUDWLQJ6\VWHP
ƒ 1HWZRUN6KDUH)LOH6\VWHP
ƒ 3RUWDEOH0HGLDRU86%IODVKGULYH

‡ 7KH\FDQEHORFDWHGLQGLIIHUHQWSODFHV
ƒ 3URGXFWFDQEHODXQFKHGIURPORFDO3&26ZKLOHFRQILJXUDWLRQLVVWRUHGRQ
D1HWZRUNILOHV\VWHP

‡ 2ULQWKHVDPHORFDWLRQ
ƒ 3URGXFWFDQEHODXQFKHGZLWKFRQILJXUDWLRQILOHVDOOVWRUHGRQD86%IODVK
GULYH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-8. IBM i Access Client Solutions deployment (2 of 2)

© Copyright IBM Corp. 1995, 2017 2-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

0DLQXVHULQWHUIDFH
‡ 3URYLGHDQHDV\WRXVHODXQFKSRLQWIRUIHDWXUHV
‡ %XLOGDQLQIUDVWUXFWXUHWKDWLVH[WHQVLEOHIRUWKHIXWXUH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-9. Main user interface

IBM i Access Client Solutions provides a platform independent interface which consolidates the
most common tasks for using and managing your IBM i system. Additional information about each
task is available by either moving the cursor over the task or by using the tab and arrow keys to
navigate between groups and tasks. To select a task, click the task or use the Tab and arrow keys
to navigate to a task and then press the Enter key.

© Copyright IBM Corp. 1995, 2017 2-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

6\VWHPFRQILJXUDWLRQV RI
‡ 8VHWKH6\VWHP&RQILJXUDWLRQVSDQHOWRVWRUHFRQQHFWLRQLQIRUPDWLRQRQ
WKH,%0L6\VWHPVWKDWZLOOEHXVHG

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-10. System configurations (1 of 2)

© Copyright IBM Corp. 1995, 2017 2-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

6\VWHPFRQILJXUDWLRQV RI
‡ &UHDWH(GLWRU'HOHWHFRQQHFWLRQLQIRUPDWLRQIRU,%0L6\VWHPVWKDW
DUHXVHG
ƒ 6\VWHPQDPH:KDWLVHQWHUHGE\WKHXVHUWRFRQQHFWWRIRUWKLVKRVW
ƒ ,3DGGUHVV:KDWWKH3&¶V'16HQYLURQPHQWODVWUHWXUQHGZKHQFRQQHFWLQJ
WRWKH6\VWHP1DPH
ƒ 6HUYLFHKRVWQDPH7KH6\VWHP¶VFRQVROHKRVWQDPHRU,3DGGUHVVDV
FRQILJXUHG
ƒ 'HVFULSWLRQ'HILQHGE\WKHXVHUZKHQFUHDWHG

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-11. System configurations (2 of 2)

© Copyright IBM Corp. 1995, 2017 2-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&RQVROHFRQILJXUDWLRQ
‡ &RQVROHLQIRUPDWLRQLVFRQILJXUHGLQWKH6\VWHP&RQILJXUDWLRQSDQHO
ƒ /$1&RQVROH9LUWXDO&RQWURO3DQHO
í 6HUYLFH+RVW1DPH
ƒ +0&&RQVROH
í +RVW1DPHRU,3DGGUHVVWRWKH+0&
3UR[\LQWHUIDFH
í 6XSSRUWV66/
ƒ +DUGZDUH0DQDJHPHQW,QWHUIDFHV
í +RVWQDPHRU,3DGGUHVV
&DQDSSHQGDSRUWWRWKHQDPHRUDGGUHVV
x.x.x.xSRUW
í 'HVFULSWLRQ
í ([DPSOHVRIPDQDJHPHQWLQWHUIDFHV
$GYDQFHG6\VWHP0DQDJHPHQW
,QWHUIDFH $60,
,QWHJUDWHG9LUWXDOL]DWLRQ0DQDJHU ,90
+DUGZDUH0DQDJHPHQW&RQVROH +0&

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-12. Console configuration

© Copyright IBM Corp. 1995, 2017 2-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&RQVROH
‡ &RQVROH2SHQVDQLQWHUDFWLYHFRQVROHWRWKHFXUUHQWV\VWHP
‡ 9LUWXDO&RQWURO3DQHO2SHQVD9LUWXDO&RQWURO3DQHOLI/$1&RQVROHLV
XVHGIRUWKHFXUUHQWV\VWHP
‡ +DUGZDUH0DQDJHPHQW,QWHUIDFH2SHQVDZHEEURZVHUWRWKH
PDQDJHPHQWFRQVROHVSHFLILHGIRUWKHFXUUHQWV\VWHP

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-13. Console

© Copyright IBM Corp. 1995, 2017 2-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&RQVROH
‡ +0&&RQVROH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-14. 5250 Console

© Copyright IBM Corp. 1995, 2017 2-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

(PXODWLRQ RI
‡ 2SHQVDQ,%07HOQHWVHVVLRQWRWKHFXUUHQWV\VWHP

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-15. 5250 Emulation (1 of 3)

© Copyright IBM Corp. 1995, 2017 2-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

(PXODWLRQ RI
‡ 3URYLGHVQHDUO\LGHQWLFDOLQWHUDFWLRQORRNDQGIHHOWRWKH$FFHVVIRU
:LQGRZV3&HPXODWRU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-16. 5250 Emulation (2 of 3)

© Copyright IBM Corp. 1995, 2017 2-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

(PXODWLRQ RI
‡ ,%0L$FFHVV&OLHQW6ROXWLRQV(PXODWLRQVHVVLRQVDUHVDYHGDV
.hod ILOHV
ƒ $FFHVVIRU:LQGRZV3&.ws ILOHVFDQEHLPSRUWHGLQWR.hod ILOHV
ƒ .hod ILOHVFDQDOVREHVDYHGRXWVLGHRIWKH6HVVLRQ0DQDJHU
í 1HHGWRVHWXSDILOHDVVRFLDWLRQLQWKH3&2SHUDWLQJ6\VWHPWRUXQWKHILOHDQG
KDYHLWRSHQWKHHPXODWRU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-17. 5250 Emulation (3 of 3)

© Copyright IBM Corp. 1995, 2017 2-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

6HVVLRQ0DQDJHU RI
‡ 6HVVLRQ0DQDJHU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-18. 5250 Session Manager (1 of 2)

© Copyright IBM Corp. 1995, 2017 2-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

6HVVLRQ0DQDJHU RI
‡ 6LPLODUWR$FFHVVIRU:LQGRZV3&6HVVLRQ0DQDJHU
ƒ 6WDUWDVDYHGVHVVLRQ
ƒ &UHDWHQHZ'LVSOD\RU3ULQWHUVHVVLRQ
ƒ &UHDWHD0XOWLSOHVHVVLRQVWDUWEDWFKILOHIURPH[LVWLQJVDYHGVHVVLRQV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-19. 5250 Session Manager (2 of 2)

© Copyright IBM Corp. 1995, 2017 2-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-20. IBM Navigator for i

© Copyright IBM Corp. 1995, 2017 2-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-21. IBM Navigator for i

The Navigator for i family of products provide a comprehensive set of system management features
for IBM i. Using rich graphical user interfaces, maintaining your IBM i has never been easier! Tasks
included in the consoles cover everything from basic system’s control to DB2 for i database control
and beyond.
Optional products such as Domino, BRMS, High Availability, Advanced Job Scheduler, and
OmniFind are readily available and automatically “plugged in” when installed.

© Copyright IBM Corp. 1995, 2017 2-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

:HOFRPHWR,%01DYLJDWRUIRUL

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-22. Welcome to IBM Navigator for i

Welcome to the new look for IBM Navigator for i. By default, on the welcome screen you will see
system health Dashboard that allows you quickly verify whether the system is OK or not.
IBM Navigator for i includes a number of Welcome pages that allow you to quickly find the task that
you want to perform. Additionally, many new functions were added to the IBM Navigator for i.
Optional can appear products like BRMS or PowerHA if installed. Now we go through some
functions to see how easy is use this GUI. To start work with IBM Navigator for i do following:
• Log on to the system using web browser [Link] add.

© Copyright IBM Corp. 1995, 2017 2-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL6\VWHP

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-23. IBM Navigator for i : System

On the left pane, click System.


The welcome page provides links to the most commonly used System tasks. To view a complete list
of available tasks, expand the All Tasks node in the navigation area.
System operations include viewing system status, messages, disk status, passwords, application
administration, and 5250 emulation.
System Status
The System Status panel displays statistical information about your system for that instant in time.
The exception is the CPU usage field, which displays a cumulative average during the time
displayed in the Elapsed time field. If you are monitoring a situation, you can update the values
that are displayed on these tabs by clicking one of the Refresh buttons.
History log
History logs help you track and control system activity. When you maintain an accurate history log,
you can monitor specific system activities that help analyze problems. History logs differ from job
logs. Job logs record the sequential events of a job. History logs record certain operational and
status messages that relate to all jobs in the system.

© Copyright IBM Corp. 1995, 2017 2-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Application Administration
The administration system is a central system that is used to manage many of the properties used
by the system. A system administrator must use Application Administration to configure a system
before it can act as an administration system. Typically, a network has only one system acting as an
administration system.
5250 Emulation
Allows you to start a 5250 Emulation session from the same emulation portlet that is available in
IBM i Access for Web.

© Copyright IBM Corp. 1995, 2017 2-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL0RQLWRU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-24. IBM Navigator for i: Monitor

On the left pane, click Monitor.


IBM i Monitors allow you to monitor your system.
You can monitor performance and your message queue.

© Copyright IBM Corp. 1995, 2017 2-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL%DVLF2SHUDWLRQV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-25. IBM Navigator for i: Basic Operations

On the left pane, click Basic Operations.


The welcome page provides links to the most commonly used Basic Operation tasks. To view a
complete list of available tasks, expand the All Tasks node in the navigation area.
Basic Operations allow you to easily manage lists of messages, printer output, and printers.
From IBM Navigator for i, you can display a list of messages. You can view all messages,
messages for the system operator, or QSYSMSG messages. You can also specify which columns
of information you want to display in the list and in what order you want the columns to be
displayed.
Messages
From the message list, you can reply to a message, send a new message, delete one or more
messages, and display the properties of a message.
Printers
You can display a list of printers. You can customize the list to specify which printers you want to
include in the list. For example, you can specify the name of a printer or you can select from a list of
printers. You can also specify which columns of information you want to display in the list and in
what order you want the columns to be displayed.

© Copyright IBM Corp. 1995, 2017 2-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Printer output
You can display a list of printer output. You can customize the list to specify which printer output you
want to include in the list. For example, you can include all printer output for a specified user. You
can also specify which columns of information you want to display in the list and in what order you
want the columns to be displayed.

© Copyright IBM Corp. 1995, 2017 2-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL:RUN0DQDJHPHQW

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-26. IBM Navigator for i: Work Management

On the left pane, click Work Management.


The welcome page provides links to the most commonly used Work Management tasks. To view a
complete list of available tasks, expand the All Tasks node in the navigation area.
Work management functions control the work performed on the system. The work management
environment supports all interactive and batch work. In addition, work management contains the
functions you need to distribute resources for your applications so that your system can handle
your applications.

© Copyright IBM Corp. 1995, 2017 2-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&RQILJXUDWLRQDQG6HUYLFH RI

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-27. Configuration and Service (1 of 2)

On the left pane, click Configuration Service.


The welcome page provides links to the most commonly used Configuration and Service tasks. To
view a complete list of available tasks, expand the All Tasks node in the navigation area.
Configuration and Service provides functions to help you manage both hardware and software on
your system.
System values
You can view and change the system values that affect the operating environment in the entire
system. You can manage time zones for each system or logical partition and use Time
management to synchronize your system time with an external time source.
Disk management
The disk management functions allow you to view and manipulate large disk configurations. This
includes the ability to view subsets of all disk units, view disk units in a physical and logical
hierarchical layout, and sort the disk units by various criteria such as size, resource name, or
associated controller. You can access wizards that provide streamlined disk maintenance
procedures for installing disk units, creating and protecting disk pools, adding disk units, and
replacing failed disk units.

© Copyright IBM Corp. 1995, 2017 2-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Note some function required DST/SST user ID and password and the service tools password level
value for must be PWLVL 2.

© Copyright IBM Corp. 1995, 2017 2-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&RQILJXUDWLRQDQG6HUYLFH RI

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-28. Configuration and Service (2 of 2)

Configuration and Service PTF management


On the left pane, expand Configuration Service and then click All Tasks.
Under Program Temporary Fix, you can find function to manage PTFs. One of them is, Compare
and Update. Click this option, then on the main pane you will see Compare and Update Wizard.
This wizard helps you compare the PTF and PTF group levels of a source system to the levels of
one or more target systems. The results show what PTFs or PTF groups are missing, as well as
what are extra on each target system.
You can automatically send and install the missing PTFs or PTF groups onto the target systems
once the compare results are shown, or just view the results.
You can also choose to update the target systems directly from the source system without viewing
the compare results. Each target system will request its missing PTFs from the source system.

© Copyright IBM Corp. 1995, 2017 2-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL1HWZRUN

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-29. IBM Navigator for i: Network

On the left pane, click Network.


The welcome page provides links to the most commonly used Network tasks. To view a complete
list of available tasks, expand the All Tasks node in the navigation area.
Your understanding of networking technologies is a vital part of your company's total e-business
solution. Using IBM Navigator for i, you can work with TCP/IP configuration, Remote access
services, networking servers, and IP Policies.
TCP/IP configuration
Use TCP/IP Configuration to manage and monitor your TCP/IP network. TCP/IP Configuration
provides wizards for configuring both IPv4 and IPv6 lines, interfaces, and routes. TCP/IP
Configuration allows you to view and configure TCP/IP properties, such as domain and host name
settings, and to start or stop TCP/IP interfaces. In addition, TCP/IP Configuration provides you
utilities to troubleshoot your network, such as trace route and PING.
Domain Name System
The Domain Name System (DNS) is a distributed database of all of the IP addresses and their
associated domain names. Each DNS server is responsible for knowing only a small fraction of all
the addresses that exist. The servers work together, referring queries that they cannot answer to
other servers that are authoritative.

© Copyright IBM Corp. 1995, 2017 2-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL,QWHJUDWHG6HUYHU$GPLQLVWUDWLRQ

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-30. IBM Navigator for i: Integrated Server Administration

On the left pane, click Integrated Server Administration.


The welcome page provides links to the most commonly used Integrated Server Administration
tasks. To view a complete list of available tasks, expand the All Tasks node in the navigation area.
You can manage your Network Server Description, Network Servers Storage Space. Network
Server Host Adapters, Network service processor network server configuration (NWSCFG type
SRVPRC) represents the System x service processor or the BladeCenter management module.
More about this you can find at:
[Link]

© Copyright IBM Corp. 1995, 2017 2-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL6HFXULW\

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-31. IBM Navigator for i: Security

On the left pane, click Security.


The welcome page provides links to the most commonly used Security tasks. To view a complete
list of available tasks, expand the All Tasks node in the navigation area.
Security functions allow you to plan and implement security on your system.
Authorization lists
An authorization list groups objects with similar security requirements together. An authorization list
contains a list of users and groups, and the authority each has to the objects secured by the list.
Object permissions
Permissions include all of a user's authority, or the type of access, allowed to an object.
Cryptographic Services Key Management
From IBM Navigator for i, Cryptographic Services Key Management allows you to store and
manage master keys and keystores. Since you will be exchanging sensitive data to manage master
keys and keystores, it is recommended that you use a secure session.

© Copyright IBM Corp. 1995, 2017 2-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Intrusion detection system
The intrusion detection system (IDS) notifies you of attempts to hack into, disrupt, or deny service
to the system. These potential intrusions are logged as journal entries in the security audit journal
and displayed in the new Intrusion Detection System graphical user interface (GUI). IDS also
monitors for potential extrusions, where your system might be used as the source of the attack.

© Copyright IBM Corp. 1995, 2017 2-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

,%01DYLJDWRUIRUL8VHUVDQG*URXSV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-32. IBM Navigator for i: Users and Groups

On the left pane click Users and Groups.


The welcome page provides links to the most commonly used Users and Groups tasks. To view a
complete list of available tasks, expand the All Tasks node in the navigation area.
Users and Groups displays a complete list of the users and groups configured on the system. You
can use this functional area to manage users and groups.
You can use IBM Navigator for i to view and manage IBM i users and groups.

© Copyright IBM Corp. 1995, 2017 2-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

'DWDEDVH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-33. Database

On the left pane click Database.


The welcome page provides links to the most commonly used Database tasks. To view a complete
list of available tasks, expand the All Tasks node in the navigation area.
Database is a graphical interface that you can use to perform many of your common administrative
database operations. Most operations are based on Structured Query Language (SQL), but you do
not need to fully understand SQL to perform them.
Using the database function you can access and modify objects, work with performance monitors,
as well as access the Health center.

© Copyright IBM Corp. 1995, 2017 2-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

-RXUQDO0DQDJHPHQW

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-34. Journal Management

On the left pane, click Journal Management.


The welcome page provides links to the most commonly used Journal Management tasks. To view
a complete list of available tasks, expand the All Tasks node in the navigation area.
A journal is an object that records changes to the file by sending information to the journal receiver.
This information includes the file name and library it belongs to, the job ID, user ID, workstation ID,
program name, date and time, type of activity, and relative record number of the affected record.
You can also record information before and after a change takes place, giving you a more complete
picture of the change being made.
You can work with journals and journal receivers using the IBM Navigator for i interface.

© Copyright IBM Corp. 1995, 2017 2-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

3HUIRUPDQFH RI

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-35. Performance (1 of 3)

On the left pane click Performance.


The welcome page provides links to the most commonly used Performance tasks. To view a
complete list of available tasks, expand the All Tasks node in the navigation area.
You can collect performance data in a collection by using a collector. To start collecting data, you
must configure and start a collector. Once some data is collected into a collection, you can view the
collection to investigate the data contained in the collection.

© Copyright IBM Corp. 1995, 2017 2-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

3HUIRUPDQFH RI

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-36. Performance (2 of 3)

On the left pane click Performance and under click Investigate Data.
Investigate Data
This task starts the Performance Data Investigator. It allows you to display a pre-described format
for organizing and displaying data called a perspective. The data used in the investigation comes
from a collection you choose. This panel is the starting point for all data analysis in the Performance
Data Investigator (PDI) tool. It also allows you to begin designing new perspectives or configure
your user preferences.

© Copyright IBM Corp. 1995, 2017 2-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

3HUIRUPDQFH RI

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-37. Performance (3 of 3)

On the left pane click Performance and under click Graph History.
Types of Historical data
The Graph History function provides access to Collection Services historical performance data,
both summary and detail.
Summary
Historical summary data is the system level or summarized metrics that are useful in identifying
trends or detecting changes in a system over a long period of time.
Summary data can be kept for 1 month up to 50 years.
Summary metrics are derived from detail performance data and other relevant supplementary data.
Summary data is stored in database files beginning with QAPMHM*.
Detail
Historical detail data is the detailed performance data from Collection Services. This data is useful
to look deeper into a problem identified while viewing historical summary data.
Detail data can be kept for 7 to 60 days.

© Copyright IBM Corp. 1995, 2017 2-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Detail metrics are filtered from collection services base metrics by reducing the number saved and
saving only the top elements as requested by configuration data filter settings.
Detail data is stored in database files beginning with QAPMHD*.
Historical data retention
The historical data retention period is configurable and is used to determine how long historical
data should be retained on the system. When historical data is older than the retention period
setting, it will be automatically deleted by the Collection Services server job (QYPSPFRCOL) the
next time the collector is started or cycled.
Historical data retention maximums depend on whether PM Agent is on or not.
Performance Management Agent (PM Agent) can be enabled using the Configure Collection
Services command in Navigator for i under the Data Retention tab. Without PM Agent enabled, the
summary data will provide up to one month of data, and the detail data will be up to 7 days worth.
With PM Agent enabled, the summary data can be set to save up to 50 years? worth, and the detail
data can be set to save up to 60 days.
Tips on using Graph History function
To maximize the screen available for charting, use the Hide Navigation icon to close the left
navigation panel.
Context Section
Use the Context Section to modify the metric and dates shown on the chart.
• Metric: Select a metric and click Refresh button to update graph.
• Library: Defaults to QPFRHIST. Modify to find historical data in another library.

© Copyright IBM Corp. 1995, 2017 2-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

)LOH6\VWHPV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-38. File Systems

On the left pane, click File Systems.


The welcome page provides links to the most commonly used File Systems tasks. To view a
complete list of available tasks, expand the All Tasks node in the navigation area.
File Systems are a part of IBM i that supports stream input/output and storage management similar
to personal computer and UNIX operating systems. They also provide a similar hierarchical
directory structure.
Integrated file systems
The integrated file system is a part of the IBM i operating system that supports stream input/output
and storage management similar to personal computer and UNIX operating systems, and provides
a similar hierarchical folder structure. Select Integrated File System from IBM Navigator for i to
display a list of all IBM i file systems to which you are authorized. You can access IBM i objects by
specifying the path through the folders to the object.
A file share is a folder path on the IBM i model that the IBM i NetServer shares with PC clients on
the network. A file share can consist of any integrated file system folder on the IBM i model.

© Copyright IBM Corp. 1995, 2017 2-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
IBM i NetServer
IBM i NetServer opens the door to file and print serving using Windows Network Neighborhood. No
additional software is needed since IBM i NetServer is integrated in the server operating system
and PC clients on the network utilize the file and print-sharing functions included in the PC
operating systems.
Network file systems
The Network File System (NFS) provides you with access to data and objects that are stored on a
remote NFS server. An NFS server can export a Network File System that NFS clients can then
mount dynamically.

© Copyright IBM Corp. 1995, 2017 2-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-39. Backup Recovery and Media Services

Optional if installed.
On the left pane, click Backup Recovery and Media Services.
Backup, Recovery and Media Services helps you manage saves and media. It also enables you to
restore objects that you have previously saved. BRMS enables you to manage your most critical
and complex saves simply and easily, ensuring that you can recover your system fully in the event
of a disaster or failure.
BRMS assists you in establishing a disciplined approach to designing and managing your save
operations, and provides you with an orderly way to retrieve lost or damaged data. It also enables
you to track all of your media from creation to expiration, and keep your system running smoothly
by performing daily maintenance activities.
Within BRMS you can create control groups to set criteria for certain types of save operations. You
can create either a backup control group or an archive control group. Backup control groups
perform save operations on active data that is necessary for your day to day operations. Backup
control groups set criteria on when saves occur, how these saves are performed, and where
information is saved. You can create multiple backup control groups to perform full system saves to
changes only saves. By running backup control groups regularly, you can use a disaster recovery
report that steps you through your recovery procedures.

© Copyright IBM Corp. 1995, 2017 2-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
Unlike backup control groups, archive control groups save objects that are used infrequently, but
might need to be accessed for later use if needed. The saved objects are removed from the
system. For example, you might have legacy customer information stored in a database and you
want to free disk space by archiving this data to media. Another difference between backup and
archive is the difference between restore and retrieve. In general, objects saved as part of a backup
are recovered from the save media. Archived objects are retrieved from the media and then after
they are used can be rearchived back to the media. Note: Objects that are saved using an archive
control group are not included in the system disaster recovery report.

© Copyright IBM Corp. 1995, 2017 2-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

3RZHU+$

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-40. PowerHA

On the left pane, click PowerHA.


Welcome to PowerHA (High Availability). The PowerHA interface is designed for ease of managing
and monitoring your high availability environment. You can configure your environment, check the
environment status, and perform actions to fix problems from any node in the cluster with PowerHA
installed. You will need to have PowerHA installed on all of your cluster nodes in order to use the
PowerHA interface effectively.
The Welcome page provides a very quick summary of the elements of your high availability
environment. If you do not have a cluster configured, you can click the Create a new cluster link to
set one up.
If you have a cluster configured, the beginning of the page contains the banner area. The banner
area contains the name of your cluster, the local node name, and the PowerHA logo.
Cluster
The name of the cluster of which the local node is currently a member.
The Welcome page will auto-refresh approximately every 60 seconds, at which time PowerHA will
recollect all of the data about the high availability environment, and update the status icons on the
page.

© Copyright IBM Corp. 1995, 2017 2-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
PowerHA will detect your cluster and any configured elements of your cluster. The following
elements will be detected and the status summarized with one or more icons next to each element:
• Cluster Nodes
• Independent ASPs
• Cluster Administrative Domains
• Cluster Resource Groups
• TCP/IP Interfaces
• Manage HyperSwap
The next section is the list of the elements of your high availability environment.
Cluster nodes
When you click the Cluster Nodes link, the page that contains a list of all of the nodes in your cluster
will be displayed. The Cluster Nodes page will provide a more detailed meaning of the icons shown
next to the element on the welcome page.
Independent ASPs
When you click the Independent ASPs link, the page that contains a list of all of the independent
auxiliary storage pools (ASPs) on all of the cluster nodes will be displayed. The Independent ASPs
page will provide a more detailed meaning of the icons shown next to the element on the welcome
page.
Cluster administrative domains
When you click the Cluster Administrative Domains link, the page that contains a list of all of the
cluster administrative domains in your high availability environment will be displayed. The Cluster
Administrative Domains page will provide a more detailed meaning of the icons shown next to the
element on the welcome page.
Cluster resource groups
When you click the Cluster Resource Groups link, the page that contains a list of all of the cluster
resource groups in your high availability environment will be displayed. The Cluster Resource
Groups page will provide a more detailed meaning of the icons shown next to the element on the
welcome page.
TCP/IP interfaces
When you click the TCP/IP Interfaces link, the page that contains a list of all of the TCP/IP
interfaces that are being used in your high availability environment will be displayed. The TCP/IP
Interfaces page will provide a more detailed meaning of the icons shown next to the element on the
welcome page.
Manage HyperSwap
When you click the Manage HyperSwap link, the page that contains a list of all of the *SYSBAS and
Independent ASPs that are under HyperSwap configuration in your high availability environment
will be displayed. The Manage HyperSwap Page will provide a more detailed example: How to
diagnose a problem in your high availability environment using the PowerHA interface.

© Copyright IBM Corp. 1995, 2017 2-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty
You open the PowerHA interface and you see the following on the Welcome page:
• First example image
▪ You notice the Error image icon next to the Cluster Nodes element. What should you do?
An Error image icon indicates a problem that requires immediate investigation. You click
the Cluster Nodes element first to find out what the problem is.
You then see the following:
• Second example image
▪ You see the Error image icon for the Failed status of node NEWYORK. You might want to
spend some time investigating why the node failed, or you might want to try to start the node
now. You start the node as shown here:
• Third example image
▪ You will see a progress indicator that tells you the node is in the process of starting. Once
the start request has completed successfully, you see the following:
• Fourth example image
▪ Once you click close on the progress page, you see:
• Fifth example image
▪ Now you return to the Welcome page, and you see the following:
• Sixth example image
▪ In the example scenario, the failed node was the main problem. Once the node was
successfully started, all other problems and warnings disappeared.
The investigation process described can be applied to any situation that you find when using the
PowerHA interface.

© Copyright IBM Corp. 1995, 2017 2-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

$GGLWLRQDOPDQDJHPHQW
HQKDQFHPHQWV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-41. Additional management enhancements

© Copyright IBM Corp. 1995, 2017 2-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

7HPSRUDU\DQGSHUPDQHQWVWRUDJH
‡ 7HPSRUDU\VWRUDJH
ƒ &DOOHGµXQSURWHFWHGVWRUDJH¶ SUH:5.6<6676 
ƒ 7HPSRUDU\VWRUDJHLVUHFODLPHGRQHDFK,3/RIWKHRSHUDWLQJV\VWHP
ƒ 7HPSRUDU\VWRUDJHKDVEHHQ³FKDUJHG´DWDMREOHYHO
ƒ 7HPSRUDU\VWRUDJHFDQDOVREHVKDUHGDFURVVPXOWLSOHMREV

‡ 3HUPDQHQWVWRUDJH
ƒ 6WRUDJHIRUDOOSHUPDQHQWREMHFWVLQOLEUDULHVDQGGLUHFWRULHV
ƒ 3HUVLVWVDFURVVDQ,3/RIWKHRSHUDWLQJV\VWHP
ƒ 3HUPDQHQWVWRUDJHLVFKDUJHGWRWKHXVHUSURILOHWKDWRZQVWKHREMHFW

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-42. Temporary and permanent storage

© Copyright IBM Corp. 1995, 2017 2-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

&KDOOHQJHVZLWKWHPSRUDU\VWRUDJH
‡ +DUGWRILQGODUJHVWFRQVXPHUVRIWHPSVWRUDJH
ƒ 7HGLRXVWRILQGZKLFKMREKDVXVHGWKHPRVWWHPSRUDU\VWRUDJH

‡ 7RWDOVFRXOGEHLQDFFXUDWHRUPLVOHDGLQJ
ƒ ,IMRE$ DOORFDWHVVKDUHGPHPRU\DQGMRE% GHDOORFDWHVWKHVKDUHGPHPRU\
WKHVWRUDJHIRUWKHVKDUHGPHPRU\LVGHGXFWHGIURPMRE%QRWMRE$

‡ 6RPHWHPSRUDU\VWRUDJHXVDJHQRW³FKDUJHG´WRDQ\MRE
ƒ 7HPSRUDU\VWRUDJHGHVLJQHGWREHVKDUHGDFURVVMREV

‡ 1RWHWKDWREMHFWVLQ47(03DUHSHUPDQHQW REMHFWV
ƒ 6WRUDJHFKDUJHGWKHVDPHDVDQ\OLEUDU\IRUREMHFWVLQ47(03

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-43. Challenges with temporary storage

© Copyright IBM Corp. 1995, 2017 2-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

7HPSRUDU\VWRUDJHDFFRXQWLQJ
‡ $FFXUDWHO\DFFRXQWIRUWHPSRUDU\VWRUDJHIRUHDFKMREDVZHOODVDFFXUDWHO\DFFRXQW
IRUV\VWHPIXQFWLRQVWKDWXVHWHPSRUDU\REMHFWVQRWVFRSHGWRDMRE
‡ ([LVWLQJ VXSSRUWIRUtemporary storage tracking VKRXOGQRWEHFRQIXVHGZLWKWKHQHZ
VXSSRUWIRUtemporary storage accounting

‡ 7HPSRUDU\VWRUDJHWUDFNLQJ
ƒ 7HPSRUDU\VWRUDJHLVJHQHUDOO\DVVRFLDWHGZLWKDMRE
í 7KHWHPSRUDU\VWRUDJHLVDXWRPDWLFDOO\IUHHGZKHQWKHMREHQGV
ƒ 2SWLRQDOO\WHPSRUDU\VWRUDJHZRXOGQRWEHWUDFNHGRUDVVRFLDWHGZLWKDMRE
í 7KHVWRUDJHLVQRWDXWRPDWLFDOO\IUHHGZKHQWKHMREHQGV

‡ 7HPSRUDU\VWRUDJHDFFRXQWLQJ
ƒ 0RVWWHPSRUDU\VWRUDJHZLOOEHFKDUJHGWRWKHFUHDWLQJSURFHVV
ƒ )RUWHPSRUDU\VWRUDJHXVHGEH\RQGWKHVFRSHRIWKHFUHDWLQJSURFHVV
í ,GHQWLI\WKHJOREDOWHPSRUDU\VWRUDJHDFFRXQWLQJEXFNHWWRWUDFNWKHVWRUDJHIRU
WKHWHPSRUDU\REMHFW

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-44. Temporary storage accounting

© Copyright IBM Corp. 1995, 2017 2-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

7HPSRUDU\VWRUDJHEXFNHWV
‡ %XFNHWVIRUWHPSRUDU\VWRUDJHVFRSHGWRWKHMRE

‡ %XFNHWVIRUWHPSRUDU\VWRUDJHVFRSHGWRWKHV\VWHP
ƒ ([DPSOHVDUHWHPSRUDU\8')6DQG326,;VKDUHGPHPRU\REMHFWV

‡ ³1RFKDUJH´DOORFDWLRQVFDQQRZEHWUDFNHG
ƒ 8VHGE\/,& /LFHQVHG,QWHUQDO&RGH WDVNVRURWKHUV\VWHPVHUYLFHV

‡ 7HPSVWRUDJHFDQEHWUDFNHGIRUDOORFDWLRQVWKDWSHUVLVWDIWHUDMREHQGV

‡ 1HZLQWHUIDFHVWRVKRZDOOWHPSRUDU\VWRUDJHEXFNHWVLQXVH
ƒ 7RWDORIDOOEXFNHWVZLOOPDWFKWKHWHPSRUDU\VWRUDJHWRWDOUHSRUWHGE\6\VWHP
6WDWXV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-45. Temporary storage buckets

© Copyright IBM Corp. 1995, 2017 2-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

:5.6<6676,PSURYHGWHUPLQRORJ\

3UH

RUODWHU

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-46. WRKSYSSTS: Improved terminology

© Copyright IBM Corp. 1995, 2017 2-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

:RUNZLWK$FWLYH-REV7HPSRUDU\6WRUDJH8VHG
‡ $OVRMREVLQDFWLYHPHPRU\SRROVMREVLQDFWLYHVXEV\VWHPV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-47. Work with Active Jobs: Temporary Storage Used

You can work with Temporary Stored Used through IBM Navigator for i.
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane, you will see all active jobs in default column setup the last column on the
right is Temporary Storage Used in MB.

© Copyright IBM Corp. 1995, 2017 2-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

:5.$&7-2%7HPSRUDU\6WRUDJH )

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-48. WRKACTJOB: Temporary Storage (F11)

Using WRKACTJOB you can work with temporary storage using 5250 screen.
To see temporary storage usage press F11 twice.

© Copyright IBM Corp. 1995, 2017 2-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

([HUFLVHV
‡ Using IBM i Access Client Solutions
ƒ /DXQFKWKHSURGXFW
ƒ /DXQFKDQGFRQILJXUHGLVSOD\VHVVLRQV
ƒ &UHDWHDFXVWRPL]HGSDFNDJHIRUDGYDQFHGGHSOR\PHQWWHFKQLTXHV

‡ Exploring the user environment


ƒ &UHDWHDOLEUDU\
ƒ &UHDWHDQRXWSXWTXHXH
ƒ &UHDWHDMREGHVFULSWLRQ
ƒ &KDQJH\RXURZQXVHUSURILOH
ƒ &KDQJH\RXUFXUUHQWOLEUDU\
ƒ $GGDQGUHPRYHOLEUDULHVIURPWKHXVHUSRUWLRQRI\RXUOLEUDU\OLVW

8VHU,'2/xx
3DVVZRUG2/3:' 7KHSDVVZRUGLVVHWWRH[SLUH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-49. Exercises

© Copyright IBM Corp. 1995, 2017 2-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH,%0&OLHQW$FFHVV6ROXWLRQLVWKHQH[WSURGXFW
DIWHU,%0L1DYLJDWRU

 :KLFKRIIROORZLQJFDQEHPDQDJHXVLQJ,%0&OLHQW$FFHVV
IRUL
D &RQVROH XVLQJ/$1RU+0&
E (PXODWRU
F 9LUWXDO&RQWURO3DQHO
G 'DWDWUDQVIHU
H 5XQ64/
I $OORIDERYH

 7UXHRUIDOVH&DQFRPSDUHLQVWDOO37)XVLQJ,%01DYLJDWRU
IRULRQIHZSDUWLWLRQVVHUYHUV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-50. Review questions

© Copyright IBM Corp. 1995, 2017 2-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH,%0&OLHQW$FFHVV6ROXWLRQLVWKHQH[WSURGXFW
DIWHU,%0L1DYLJDWRU
7KHDQVZHULVWUXH

 :KLFKRIIROORZLQJFDQEHPDQDJHXVLQJ,%0&OLHQW$FFHVV
IRUL
D &RQVROH XVLQJ/$1RU+0&
E (PXODWRU
F 9LUWXDO&RQWURO3DQHO
G 'DWDWUDQVIHU
H 5XQ64/
I $OORIWKHDERYH
7KHDQVZHULVDOORIWKHDERYH

 7UXH RUIDOVH&DQFRPSDUHLQVWDOO37)XVLQJ,%01DYLJDWRU
IRULRQIHZSDUWLWLRQVVHUYHUV
7KHDQVZHULVWUXH

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-51. Review answers

© Copyright IBM Corp. 1995, 2017 2-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 2. Systems management

Uempty

8QLWVXPPDU\
‡ 'HVFULEHWKHDYDLODEOHPDQDJHPHQWSURGXFW
‡ 'HVFULEHWKHHQKDQFHPHQWVWR,%0L$FFHVV
‡ 'HVFULEHWKHPDLQIXQFWLRQDOLW\RI,%0&OLHQW$FFHVV6ROXWLRQV
‡ 'HVFULEHWKHHQKDQFHPHQWVRI,%06\VWHPV1DYLJDWRUIRUL
‡ .QRZDGGLWLRQDOPDQDJHPHQWHQKDQFHPHQWV

6\VWHPVPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 2-52. Unit summary

© Copyright IBM Corp. 1995, 2017 2-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

Unit 3. Security concepts and overview


Estimated time
00:10

Overview
The IBM Systems family covers a wide range of users. Security on the System i platform is flexible
enough to meet the requirements of this wide range of users and situations. You need to
understand the features and options available so that you can adapt them to your own security
requirements.
In this unit, we will overview the tools at your disposal to secure your system, control what users are
allowed to do, and secure who can access the data and limit what they do can to that data. This unit
will discuss the concepts, and the following units will cover the specific details.

How you will check your progress


• Review questions

References
SG24-5302-10 System i Security Reference
IBM Publications Center
[Link]
US

© Copyright IBM Corp. 1995, 2017 3-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

8QLWREMHFWLYHV
‡ /LVWDQGGLVFXVVWKHREMHFWLYHVRIV\VWHPVHFXULW\
‡ 'HVFULEHZKDWSK\VLFDOVHFXULW\HQWDLOV
‡ /LVWDQGGHVFULEHWKHFDSDELOLWLHVRIWKHV\VWHPWRROVDYDLODEOHWRVHFXUH
\RXUV\VWHP

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 3-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

7KHREMHFWLYHVRIV\VWHPVHFXULW\
‡ &RQILGHQWLDOLW\
ƒ 3URWHFWLQJDJDLQVWGLVFORVLQJLQIRUPDWLRQWRXQDXWKRUL]HGSHRSOH
ƒ 5HVWULFWLQJDFFHVVWRFRQILGHQWLDOLQIRUPDWLRQ
ƒ 3URWHFWLQJDJDLQVWFXULRXVV\VWHPXVHUVDQGRXWVLGHUV

‡ ,QWHJULW\
ƒ 3URWHFWLQJDJDLQVWXQDXWKRUL]HGFKDQJHVWRGDWD
ƒ 5HVWULFWLQJPDQLSXODWLRQRIGDWDWRDXWKRUL]HGSURJUDPV
ƒ 3URYLGLQJDVVXUDQFHWKDWGDWDLVWUXVWZRUWK\

‡ $YDLODELOLW\
ƒ 3UHYHQWLQJDFFLGHQWDOFKDQJHVRUGHVWUXFWLRQRIGDWD
ƒ 3URWHFWLQJDJDLQVWDWWHPSWVE\RXWVLGHUVWRDEXVHRUGHVWUR\V\VWHP
UHVRXUFHV

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-2. The objectives of system security

System security is often associated with external threats, such as hackers or business rivals.
However, protection against system accidents by authorized system users is often the greatest
benefit of a well-designed security system. In a system without good security features, pressing the
wrong key might result in deleting important information. System security can prevent this type of
accident.
The best security system functions cannot produce good results without good planning. Security
that is set up in small pieces, without planning, can be confusing. It is difficult to maintain and to
audit. Planning does not imply designing the security for every file, program, and device in
advance. It does imply establishing an overall approach to security on the system and
communicating that approach to application designers, programmers, and system users.

© Copyright IBM Corp. 1995, 2017 3-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

4XHVWLRQVZKHQSODQQLQJIRUVHFXULW\
‡ $V\RXSODQVHFXULW\RQ\RXUV\VWHPDQGGHFLGHKRZPXFKVHFXULW\\RX
QHHGFRQVLGHUWKHIROORZLQJTXHVWLRQV

ƒ ,VWKHUHDFRPSDQ\SROLF\RUVWDQGDUGWKDWUHTXLUHVDFHUWDLQOHYHORI
VHFXULW\"

ƒ 'RWKHFRPSDQ\DXGLWRUVUHTXLUHVRPHOHYHORIVHFXULW\"

ƒ +RZLPSRUWDQWLV\RXUV\VWHPDQGWKHGDWDRQLWWR\RXUEXVLQHVV"

ƒ +RZLPSRUWDQWLVWKHHUURUSURWHFWLRQSURYLGHGE\WKHVHFXULW\IHDWXUHV"

ƒ :KDWDUH\RXUFRPSDQ\VHFXULW\UHTXLUHPHQWVIRUWKHIXWXUH"

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-3. Questions when planning for security

To facilitate installation, many of the security capabilities on your system are not activated when
your system is shipped. Recommendations are provided in this topic collection to bring your system
to a reasonable level of security. Consider the security requirements of your own installation as you
evaluate the recommendations

© Copyright IBM Corp. 1995, 2017 3-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

3K\VLFDOVHFXULW\
&RPSXWHUURRP 6\VWHP

'LVSOD\VWDWLRQV
%DFNXSWDSHV

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-4. Physical security

Physical security includes protecting the system unit, system devices, and backup media from
accidental or deliberate damage. Most of the measures you take to ensure the physical security of
your system, are external to the system.

© Copyright IBM Corp. 1995, 2017 3-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

.H\ORFNVHFXULW\

/RZ +LJK
0DQXDO 1RUPDO $XWRPDWLF 6HFXUH
8VHGHGLFDWHGVHUYLFH
<HV 1R 1R 1R
WRROV
/RDGV\VWHPIURPWDSH <HV 1R 1R 1R
&KDQJH,3/VRXUFH <HV 1R 1R 1R
,3/WKURXJKVZLWFK <HV <HV 1R 1R
5HPRWH,3/ 1R <HV <HV 1R
PWRDWNSYS:RUNVWDWLRQ <HV <HV <HV <HV
2IIWKURXJKSRZHUVZLWFK <HV 1R 1R 1R

0DQXDO 1RUPDO
8VHGHGLFDWHGVHUYLFH
<HV 1R
WRROV

/RDGV\VWHPIURP
<HV 1R
WDSH'9'
/RDGV\VWHPIURPGLVNV <HV <HV

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-5. Keylock security

Few years ago Power System Server was secure by keylock. Setting key in special positions you
can set up higher or lower server security level by allowing or not some operations.
Today physical keys are not used anymore to secure Power Servers, but they are still used to
manage boot type. You can manage it using HMC (Hardware Management Console).
The keylock position, which establishes the power-on and power-off modes that are allowed for the
system, might be Manual or Normal. For security reasons, the recommendation is that you do not
set the keylock position to Manual. Manual position allows you to start Dedicated Service Tolls
(DST).

© Copyright IBM Corp. 1995, 2017 3-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

0RQLWRULQJSK\VLFDOVHFXULW\
‡ ,IWKHFRPSXWHULVEHKLQGDGRRUORFNHGWKDWXVHVDQHQWU\FRGHHQVXUH
WKDWWKHFRGHLVFKDQJHGUHJXODUO\
‡ 5HVWULFWSK\VLFDODFFHVVWRVDYHDQGUHVWRUHGHYLFHVVXFKDVWDSHXQLWV
DQGRSWLFDOXQLWV
‡ (QVXUHWKDWEDFNXSPHGLDLVSURWHFWHGIURPGDPDJHDQGWKHIW
‡ 5HVWULFWDFFHVVWRSXEOLFO\ORFDWHGZRUNVWDWLRQVDQGWKHFRQVROH

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-6. Monitoring physical security

© Copyright IBM Corp. 1995, 2017 3-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

6\VWHPWRROVXVHGWRVHFXUH\RXUV\VWHP
‡ 6HFXULW\OHYHO
‡ 6\VWHPYDOXHV
‡ 6LJQLQJ
‡ 6LQJOHVLJQRQHQDEOHPHQW
‡ 8VHUSURILOHV
‡ *URXSVSURILOHV
‡ 5HVRXUFHVHFXULW\
‡ 'DWDHQFU\SWLRQ
‡ 6HFXULW\DXGLWMRXUQDO

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-7. System tools used to secure your system

Security level
There are five levels of security that can be set with the QSECURITY system value. The different
levels that can be specified are level 10, 20, 30, 40 or 50. Specific details are covered later in the
class.
System values
Allow you to define system-wide security settings, and to provide customization for many
characteristics of your Power System with IBM i.
Signing
Signing your software object is particularly important if the object was transmitted across the
Internet, or stored on media that you feel may have been modified. The digital signature can be
used to detect if the object has been altered.
Digital signatures, and their use for verification of software integrity can be managed according to
your security policies by using the Verify Object Restore (QVFYOBJRST) system value, the Check
Manager tool. Additionally, you can choose to sign your own programs (all licensed programs that
are shipped with the system are signed).

© Copyright IBM Corp. 1995, 2017 3-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty
Single signon enablement
Single signon is an authentication process in which a user can access more than one system by
entering a single user ID and password. To enable a single sign-on environment, IBM provides two
technologies. They work together to enable users to sign in with their Windows user name and
password, and be authenticated to Power Systems with IBM i in the network: Network
Authentication Service (NAS) and Enterprise Identity Mapping (EIM). Operating systems use
Kerberos protocol to authenticate users to the network. A secure, centralized system, called a key
distribution center, authenticates principals (Kerberos users) to the network.
User profiles
The user profile is a powerful and flexible tool that is used to control what the user can do and
customize the way that the system appears to that user.
Groups profiles
A group profile is a special type of user profile. Rather than giving authority to each user
individually, you can use a group profile to define authority for a group of users.
Resource security
The ability to access an object is called authority. Resource security on the IBM i operating system
enables you to control object authorities by defining who can use which objects and how those
objects can be used.
You can specify detailed authorities, such as adding records or changing records. Or you can use
the system-defined subsets of authorities: *ALL, *CHANGE, *USE, and *EXCLUDE.
Files, programs, and libraries are the most common objects requiring security protection, but you
can specify authority for any object on the system.
Data encryption
IBM i offers the possibility to encrypt data at ASP level and Database Column level. ASP encryption
can be turned off and on and the data encryption key can be changed for an existing user ASP.
These changes take a significant amount of time as all the data in the disk pool needs to be
processed. This would affect system performance.
Field procedures are user written exit programs that get executed every time that a column is
changed or new values are inserted.
Security audit journal
You can use security audit journals to audit the effectiveness of security on your system. The IBM i
operating system provides the ability to log selected security-related events in a security audit
journal. Several system values, user profile values, and object values control which events are
logged. Object Integrity (CHKOBJITG) command, and the Digital Certificate

© Copyright IBM Corp. 1995, 2017 3-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

6HFXULW\LVDOZD\VDFWLYH

6,*121
+DUU\

0(18 $87+25,7<

3$<52//
$87+25,7<
0(18

3$<(',7
$87+25,7<
352*5$0

2SHUDWLRQDO
5HDG
3$<52//
([HFXWH
'$7$

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-8. Security is always active

On the IBM i, security was architected from the ground up. Security is always available and active.
Based on what level of security you choose to configure and implement, determines how secure
your system will be.

© Copyright IBM Corp. 1995, 2017 3-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH7KHREMHFWLYHVRIVHFXULW\DUHFRQILGHQWLDOLW\
LQWHJULW\DQGDYDLODELOLW\

 3K\VLFDOVHFXULW\LQFOXGHVZKLFKRIWKHIROORZLQJ"
D &RQWUROOLQJDFFHVVWRWKH&38
E 6HFXULQJWKHWDSHVWKDWDUHXVHGIRUEDFNXS
F 6HFXULQJWKHSULQWHUVWKDWDUHFRQQHFWHGWR\RXUV\VWHP
G $OORIWKHDERYH

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHPRGHV\RXFDQ
VHOHFWIRU\RXUV\VWHP"
D 0DQXDO
E 1RUPDO
F 6HFXUH

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-9. Review questions

© Copyright IBM Corp. 1995, 2017 3-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH7KHREMHFWLYHVRIVHFXULW\DUHFRQILGHQWLDOLW\
LQWHJULW\DQGDYDLODELOLW\
7KHDQVZHULVWUXH

 3K\VLFDOVHFXULW\LQFOXGHVZKLFKRIWKHIROORZLQJ"
D &RQWUROOLQJDFFHVVWRWKH&38
E 6HFXULQJWKHWDSHVWKDWDUHXVHGIRUEDFNXS
F 6HFXULQJWKHSULQWHUVWKDWDUHFRQQHFWHGWR\RXUV\VWHP
G $OORIWKHDERYH
7KHDQVZHULVDOORIWKHDERYH

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHPRGHV\RXFDQ
VHOHFWIRU\RXUV\VWHP"
D 0DQXDO
E 1RUPDO
F 6HFXUH
7KHDQVZHULV6HFXUH
6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-10. Review answers

© Copyright IBM Corp. 1995, 2017 3-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 3. Security concepts and overview

Uempty

8QLWVXPPDU\
‡ /LVWDQGGLVFXVVWKHREMHFWLYHVRIV\VWHPVHFXULW\
‡ 'HVFULEHZKDWSK\VLFDOVHFXULW\HQWDLOV
‡ /LVWDQGGHVFULEHWKHFDSDELOLWLHVRIWKHV\VWHPWRROVDYDLODEOHWRVHFXUH
\RXUV\VWHP

6HFXULW\FRQFHSWVDQGRYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 3-11. Unit summary

© Copyright IBM Corp. 1995, 2017 3-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

Unit 4. Security-related system values


Estimated time
01:00

Overview
There are three components used to implement security on this system. The operating system
continually checks system values, user profiles, and an object's resource security as it receives
requests from users to determine whether that user will be allowed to access the object in question.
In this unit, we will discuss system values and how you use these to customize many
characteristics of your system. Security is an integral part of the operating system. It is not an
add-on or extra purchase feature of an application.

How you will check your progress


• Review questions

References
SG24-5302-10 System i Security Reference
IBM Publications Center
[Link]
US

© Copyright IBM Corp. 1995, 2017 4-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

8QLWREMHFWLYHV
‡ /LVWDQGH[SODLQWKHOHYHOVRIVHFXULW\DYDLODEOH
‡ 'HVFULEHWKHFDSDELOLW\LQVHUYLFHWRROVWRORFNRXWXVHUVIURPFKDQJLQJ
V\VWHPYDOXHV
‡ /LVWWKHVWHSVWRPRYHIURPRQHVHFXULW\OHYHOWRDQRWKHU
‡ 'HILQHWKHGLIIHUHQWFDWHJRULHVRIV\VWHPYDOXHVDYDLODEOH
‡ ([SODLQKRZWRXVHVHFXULW\SROLFLHVWRVHWV\VWHPYDOXHV
‡ /LVWWKHFRPPDQGVXVHGWRVHWV\VWHPYDOXHVZKHQXVLQJDQHPXODWLRQ
‡ /LVWWKHVWHSVXVHGLQ,%01DYLJDWRUIRUL WRPDQLSXODWHV\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 4-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\FRPSRQHQWV

3HRSOH 2EMHFWV
XVHUV UHVRXUFHV
,QGLYLGXDO
8VHUSURILOHV
REMHFWV

-REGHVFULSWLRQV /LEUDU\GLUHFWRU\

*URXSSURILOHV $XWKRUL]DWLRQOLVWV

6\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-2. Security components

There are three components used to implement security on this system. The operating system
continually checks system values, user profiles, and objects as it receives requests from users to
determine whether that user is allowed to access the object in question.
In this unit, we discuss system values and how you use these to customize many characteristics of
your system.
Security is an integral part of the operating system. It is not an add-on or extra purchase feature of
an application.

© Copyright IBM Corp. 1995, 2017 4-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\UHODWHGV\VWHPYDOXHV
‡ 3XUSRVH
ƒ 8VHGWRGHILQHFXVWRPL]HG VHFXULW\ FKDUDFWHULVWLFVRQWKHV\VWHP
‡ +RZWRVHW
ƒ HPXODWLRQ
í WRKSYSVAL :RUNZLWKV\VWHPYDOXHV
í CHGSYSVAL 'LUHFWO\FKDQJHV\VWHPYDOXHV
ƒ ,%01DYLJDWRUIRUL
í &RQILJXUDWLRQDQG6HUYLFH!6\VWHP9DOXHV
‡ $XWKRULW\UHTXLUHG
ƒ 0XVWKDYH 6(&$'0DQG $//2%-DXWKRULW\WRFKDQJHVHFXULW\UHODWHGV\VWHP
YDOXHV
ƒ &DQEHORFNHGZLWKDQRSWLRQWKURXJKGHGLFDWHGVHUYLFHWRROV '67 RUV\VWHP
VHUYLFHWRROV 667

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-3. Security-related system values

© Copyright IBM Corp. 1995, 2017 4-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

/RFNLQJV\VWHPYDOXHVE\XVLQJVHUYLFHWRROV
6WHSVWRORFNXQORFNXVLQJSTRSST
 6LJQRQWRDQHPXODWLRQVHVVLRQ
 (QWHUWKHSTRSST FRPPDQG
 7\SH\RXUVHUYLFHWRROVXVHU,'DQGSDVVZRUG
 6HOHFWRSWLRQ :RUNZLWKV\VWHPVHFXULW\
 6HOHFWRSWLRQ WRORFNRURSWLRQ WRXQORFN

6WHSVWRORFNXQORFNZKHQXVLQJ'67
 /RDGWKHLQLWLDOSURJUDPLQDWWHQGHGPRGH
 6HOHFWRSWLRQ 8VHGHGLFDWHGVHUYLFHWRROVIURPWKH,3/RU,QVWDOO
6\VWHPGLVSOD\
 6LJQRQWR'67ZLWK\RXUVHUYLFHWRROVXVHU,'DQGSDVVZRUG
 6HOHFWRSWLRQ :RUNZLWKV\VWHPVHFXULW\
 6HOHFWRSWLRQ WRORFNRURSWLRQ WRXQORFN

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-4. Locking system values by using service tools

You can use system service tools (SST) or dedicated service tools (DST) to lock and unlock the
security-related system values. However, you must use DST if you are in recovery mode because
SST is not available during this mode. Otherwise, use SST to lock or unlock the security-related
system values.
You can restrict the following system values by using the lock option:
QALWJOBITP QAUTORMT QLMTDEVSSN QLMTSECOFR
QRETSVRSEC QALWOBJRST QAUTOVRT QCRTAUT
QPWDLVL QRMTSIGN QALWUSRDMN QSCANFS
QMAXSGNACN QRMTSRVATR QAUDCTL QPWDPOSDIF
QCRTOBJAUD QMAXSIGN QPWDMINLEN QPWDEXPITV
QAUDENACN QDEVRCYACN QPWDCHGBLK QDSCJOBITV
QSCANFSCTL QAUDFRCLVL QDSPSGNINF QAUDLVL2
QPWDRQDDGT QSECURITY QAUDLVL QUSEADPAUT
QPWDEXPWRN QPWDRQDDIF QSHRMEMCTL QPWDVLDPGM
QFRCCVNRST QPWDLMTAJC QPWDRULES
QAUTOCFG QINACTMSGQ QPWDLMTCHR
QVFYOBJRST QPWDMAXLEN QPWDLMTREP

© Copyright IBM Corp. 1995, 2017 4-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
4.1. Topic 1: Setting the level of security

© Copyright IBM Corp. 1995, 2017 4-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

7RSLF6HWWLQJWKHOHYHORI
VHFXULW\

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-5. Topic 1: Setting the level of security

© Copyright IBM Corp. 1995, 2017 4-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

46(&85,7<V\VWHPYDOXH
‡ 3XUSRVH
ƒ 8VHGWRVSHFLI\WKHOHYHORIVHFXULW\WREHHQIRUFHGRQWKHV\VWHP

‡ +RZWRVHW
ƒ HPXODWLRQWRKSYSVAL QSECURITY
ƒ ,%01DYLJDWRUIRUL&RQILJXUDWLRQDQG6HUYLFH!6\VWHP9DOXHV!
6HFXULW\!*HQHUDO WDE

‡ $XWKRULW\UHTXLUHG
ƒ 0XVWKDYH 6(&$'0DQG $//2%-DXWKRULW\WRFKDQJHV\VWHPYDOXHV
ƒ &DQEHORFNHGZLWKDQRSWLRQWKURXJKVHUYLFHWRROV '67DQG667

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-6. QSECURITY system value

System security level specifies the level of security on the system. A change to this system value
takes effect at the next IPL.
The shipped value is 40 (Protect from undocumented system interfaces).

© Copyright IBM Corp. 1995, 2017 4-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

46(&85,7<V\VWHPYDOXH6HFXULW\OHYHO

/HYHO (QKDQFHGLQWHJULW\

/HYHO 6\VWHPLQWHJULW\
/HYHO 5HVRXUFH
/HYHO 3DVVZRUG

5HFRPPHQGHGYDOXH/HYHO

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-7. QSECURITY system value: Security level

You can choose how much security you want the system to enforce by setting the security level
(QSECURITY) system value. If you want to change the security level, use the Work with System
Values (WRKSYSVAL) command.
The comparison of the functions supported by the different levels of security is:
Function Level 30 Level 40 Level 50
User name required to sign on. Yes Yes Yes
Password required to sign on. Yes Yes Yes
Password security active. Yes Yes Yes
Menu and initial program security active. Yes Yes Yes
Limit capabilities support active. Yes Yes Yes
Resource security active. Yes Yes Yes
Access to all objects. No No No
User profile created automatically. No No No
Security auditing capabilities available. Yes Yes Yes
Programs that contain restricted instructions cannot be
Yes Yes Yes
created or recompiled.
Programs that use unsupported interfaces fail at run time. No Yes Yes

© Copyright IBM Corp. 1995, 2017 4-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
Function Level 30 Level 40 Level 50
Enhanced hardware storage protection is enforced for all
No Yes Yes
storage.
Library QTEMP is a temporary object. No No No
*USRSPC, *USRIDX, and *USRQ objects can be created
Yes Yes Yes
only in libraries specified in the QALWUSRDMN system value.
Pointers used in parameters are validated for user domain
No Yes Yes
programs running in system state.
Message handling rules are enforced between system and
No No Yes
user state programs.
A program's associated space cannot be directly modified. No Yes Yes
Internal control blocks are protected. No Yes Yes

© Copyright IBM Corp. 1995, 2017 4-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\OHYHO

/HYHO (QKDQFHGLQWHJULW\

/HYHO 6\VWHPLQWHJULW\
/HYHO 5HVRXUFH
/HYHO 3DVVZRUG

‡ 3UHYHQWVXVHRIXQVXSSRUWHGLQWHUIDFHV
‡ 3UHYHQWVXVHRIUHVWULFWHGLQVWUXFWLRQV
‡ &RQWUROVXVHRIMREGHVFULSWLRQVRQSBMJOB
‡ 3UHYHQWVVLJQRQZLWKRXWDXVHU,'DQGSDVVZRUG
‡ (QKDQFHGKDUGZDUHVWRUDJHSURWHFWLRQ
‡ 'HIDXOWIRUQSECURITY V\VWHPYDOXH

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-8. Security level 40

Level 40 is referred to as system integrity security. At this level, the system itself is protected
against users. User-written programs cannot directly access the internal control blocks through
pointer manipulation.
Select system security level using IBM Navigator for i.
Security level 40:
• Prevents accessing objects through unsupported interfaces. Example: Calling the command
processing program for the SIGNOFF command
• Prevents accessing internal system structures with C/400, Pascal, or Assembler
• Controls use of job descriptions on SBMJOB
• Does not allow *SBSD to allow signon without entering user ID and password
• Enables enhanced hardware storage protection, defining system information on disk as
read/write, read only, or no access
At level 20-30, action is usually allowed but logged to QAUDJRN journal.
At level 40-50, action usually fails and is logged to QAUDJRN journal.

© Copyright IBM Corp. 1995, 2017 4-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6WHSVWRFKDQJHIURPOHYHOWROHYHO
 $FWLYDWHWKHVHFXULW\DXGLWLQJIXQFWLRQ

 6HWWKHQAUDLVL V\VWHPYDOXHWRLQFOXGH AUTFAIL DQG


PGMFAIL

 0RQLWRUWKHDXGLWMRXUQDOIRU AUTFAIL DQG PGMFAIL


HQWULHVZKLOHUXQQLQJDOORI\RXUDSSOLFDWLRQVDWVHFXULW\OHYHO


 ,I\RXKDYHDQ\SURJUDPV &2%2/53* WKDWZHUHFUHDWHG


LQ9HUVLRQ5HOHDVHRUEHIRUHXVHWKHCHGPGM FRPPDQG
ZLWKWKHFRCCRT SDUDPHWHUWRFUHDWHYDOLGDWLRQYDOXHVIRU
WKRVHSURJUDPV VHHQRWH 

 0DNHFRUUHFWLRQVWRDQ\DSSOLFDWLRQVWKDWDUHORJJLQJ
IDLOXUHV

 &KDQJHWKHQSECURITY YDOXHWRDQGSHUIRUPDQ,3/
6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-9. Steps to change from level 30 to level 40

Before migrating to level 40, make sure that all of your applications run successfully at security
level 30. Security level 30 gives you the opportunity to test resource security for all of your
applications. Follow these steps to migrate to security level 40:
1. Activate the security auditing function, if you have not already done so.
2. Make sure that the QAUDLVL system value includes *AUTFAIL and *PGMFAIL. *PGMFAIL logs
journal entries for any access attempts that violate the integrity protection at security level 40.
3. Monitor the audit journal for *AUTFAIL and *PGMFAIL entries while running all of your
applications at security level 30. Pay particular attention to the following reason codes in AF
type entries:
▪ C: Object validation failure
▪ D: Unsupported interface (domain) violation
▪ J: Job-description and user-profile authorization failure
▪ R: Attempt to access protected area of disk (enhanced hardware storage protection)
▪ S: Default sign-on attempt
These codes indicate the presence of integrity exposures in your applications. At security level 40,
these programs fail.

© Copyright IBM Corp. 1995, 2017 4-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
4. If you have any programs (COBOL, RPG) that were created before Version 5 Release 4 or
before, use the CHGPGM command with the FRCCRT parameter to create validation values for
those programs. At security level 40, the system translates any program that is restored without
a validation value. This can add considerable time to the restore process.
Restore program libraries as part of your application test. Check the audit journal for validation
failures.
5. Based on the entries in the audit journal, take steps to correct your applications and prevent
program failures.
6. Change the QSECURITY value to 40 and perform an IPL.
Program conversion is not required if upgrading to IBM i 7.1 from IBM i 6.1.
If upgrading to IBM i 7.1 from IBM i 5.4 or any previous release, program conversion is required for
all programs that use the IBM i Machine Interface (MI). This conversion upgrades and refreshes
programs to take advantage of the latest system enhancements, including enhanced system
integrity, improved performance, and a range of new operating system and processor capabilities.
In order for a program to be converted, its creation data (sometimes referred to as observability)
must be available. Programs created for IBM i V5R1 or later automatically retain creation data
sufficient for conversion. Clients and ISVs with programs created for OS/400 V4R5 and earlier need
to ensure that creation data is available for the conversion process.
IBM provided the Analyze Object Conversion (ANZOBJCVN) tool for IBM i 5.3 and 5.4 (i5/OS V5R3
and V5R4) to help you plan for program conversion. This tool helps you identify potential
conversion difficulties, if any, and estimates the time required for program conversion.

© Copyright IBM Corp. 1995, 2017 4-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\OHYHO

/HYHO (QKDQFHGLQWHJULW\
/HYHO 6\VWHPLQWHJULW\
/HYHO 5HVRXUFH
/HYHO 3DVVZRUG

• QTEMP(QKDQFHGSURWHFWLRQIURPRWKHUMREV
‡ 3DUDPHWHUYDOLGDWLRQZKHQFDOOLQJV\VWHPSURJUDPV
‡ 0HVVDJHKDQGOLQJUHVWULFWLRQVEHWZHHQXVHUDQGV\VWHPSURJUDPV
‡ ,QWHUQDOFRQWUROEORFNVSURWHFWHGIURPPRGLILFDWLRQ
‡ 5HVWULFWLQJXVHUGRPDLQREMHFWW\SHV USRSPC USRIDXDQG USRQ

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-10. Security level 50

Level 50 is referred to as enhanced system integrity security. Level 50 is the recommended level of
security for most businesses because it offers the highest level of security currently possible. Not
only is the system protected against user-written programs, but it ensures that users only have
access to data on the system, rather than information about the system itself. This offers greater
security against anyone attempting to learn about your system.

© Copyright IBM Corp. 1995, 2017 4-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6WHSVWRFKDQJHWRVHFXULW\OHYHO
 (YDOXDWHWKHQALWUSRDMN V\VWHPYDOXH

 5HFRPSLOHDQ\SURJUDPV &2%2/53* WKDWZHUH


FRPSLOHGXVLQJDSUHYLRXVFRPSLOHUYHUVLRQ

 &KDQJHWKHVHFXULW\YDOXHWRDQGSHUIRUPDQ,3/

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-11. Steps to change to security level 50

If your current security level is 30 or 40, you need to evaluate the QALWUSRDMN value and
recompile some programs to prepare for security level 50.
Most of the additional security measures that are enforced at security level 50 do not cause audit
journal entries at lower security levels. Therefore, an application cannot be tested for all possible
integrity error conditions before changing to security level 50.
The actions that cause errors at security level 50 are uncommon in normal application software.
Most software that runs successfully at security level 40 also runs at security level 50.
If you are currently running your system at security level 30 or 40, do the following to prepare for
security level 50:
1. Evaluate the QALWUSRDMN system value. Controlling user domain objects is important to
system integrity.
2. Recompile any programs (COBOL, RPG) were compiled with previous compiler version.
3. Change security value to 50 and perform an IPL.
You can go directly from security level 30 to security level 50. Running at security level 40 as an
intermediate step does not provide significant benefits for testing.

© Copyright IBM Corp. 1995, 2017 4-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
If you are currently running at security level 40, you can change to security level 50 without extra
testing. Security level 50 cannot be tested in advance. The additional integrity protection that is
enforced at security level 50 does not produce error messages or journal entries at lower security
levels.

© Copyright IBM Corp. 1995, 2017 4-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
4.2. Topic 2: Using 5250 emulation to configure
system values

© Copyright IBM Corp. 1995, 2017 4-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

7RSLF8VLQJHPXODWLRQ
WRFRQILJXUHV\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-12. Topic 2: Using 5250 emulation to configure system values

© Copyright IBM Corp. 1995, 2017 4-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\V\VWHPYDOXHV
‡ 3XUSRVH
ƒ 6SHFLI\V\VWHPYDOXHVWKDWFRQWUROVHFXULW\RQWKHV\VWHP

‡ +RZWRVHW
ƒ WRKSYSVAL *SEC
í :RUNZLWKWKHV\VWHPYDOXHVWKDWDUHLQWKHVHFXULW\FDWHJRU\ 

‡ $XWKRULW\UHTXLUHG
ƒ 8VHUSURILOHPXVWKDYH $//2%-DQG 6(&$'0DXWKRULW\

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-13. Security system values

Security system values allow you to set security function to support the decisions you made when
developing your security policy. Most of the changes take effect immediately and do not require an
IPL of the system.
Security system values that control security on your system are as follows:
• QALWOBJRST: Allow object restore option
• QALWUSRDMN: Allow user domain objects in the libraries
• QAUDCTL: Auditing control
• QAUDENDACN: Auditing end action
• QAUDFRCLVL: Force auditing data
• QAUDLVL: Security auditing level
• QAUDLVL2: Security auditing level extension
• QCRTAUT: Create default public authority
• QCRTOBJAUD: Create object auditing
• QDSPSGNINF: Display signon information

© Copyright IBM Corp. 1995, 2017 4-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
• QFRCCVNRST: Force conversion on restore
• QINACTITV: Inactive job timeout interval
• QINACTMSGQ: Inactive job message queue
• QLMTDEVSSN: Limit device sessions
• QLMTSECOFR: Limit security officer
• QMAXSIGN: Maximum sign-on attempts
• QMAXSGNACN: Action when maximum sign-on attempts exceeded
• QPWDCHGBLK: Block password change
• QPWDEXPITV: Password expiration interval
• QPWDEXPWRN: Password expiration warning
• QPWDLMTAJC: Limit adjacent digits in password
• QPWDLMTCHR: Limit characters in password
• QPWDLMTREP: Limit repeating characters in password
• QPWDLVL: Password level
• QPWDMAXLEN: Maximum password length
• QPWDMINLEN: Minimum password length
• QPWDPOSDIF: Limit password character positions
• QPWDRQDDGT: Require digit in password
• QPWDRQDDIF: Duplicate password control
• QPWDRULES: Password rules
• QPWDVLDPGM: Password validation program
• QRETSVRSEC: Retain server security
• QRMTSIGN: Remote sign-on requests
• QSCANFS: Scan file systems
• QSCANFSCTL: Scan file systems control
• QSECURITY: Security level
• QSHRMEMCTL: Shared memory control
• QSSLCSL: Secure sockets layer cipher specification list
• QSSLCSLCTL: Secure sockets layer cipher control
• QSSLPCL: Secure sockets layer protocols
• QUSEADPAUT: Use adopted authority
• QVFYOBJRST: Verify object on restore

© Copyright IBM Corp. 1995, 2017 4-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\UHODWHGV\VWHPYDOXHV
‡ 3XUSRVH
ƒ 6SHFLI\V\VWHPYDOXHVWKDWUHODWHWRVHFXULW\RQWKHV\VWHP

‡ +RZWRVHW
ƒ WRKSYSVAL *SYSCTL

‡ $XWKRULW\UHTXLUHG
ƒ 8VHUSURILOHPXVWKDYH $//2%-DQG 6(&$'0DXWKRULW\

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-14. Security-related system values

The following information includes descriptions of additional system values that relate to security on
your system.
• QASTLVL: User assistance level
• QATNPGM: Attention program
• QAUTOCFG: Autoconfigure devices
• QAUTORMT: Autoconfigure of remote controllers
• QAUTOVRT: Autoconfigure virtual devices

© Copyright IBM Corp. 1995, 2017 4-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6HFXULW\UHODWHGUHVWRUHV\VWHPYDOXHV
‡ 3XUSRVH
ƒ &RQWUROVKRZDQGZKLFKVHFXULW\UHODWHGREMHFWVDUHUHVWRUHGRQWKHV\VWHP

‡ +RZWRVHW
ƒ WRKSYSVAL *SEC

‡ $XWKRULW\UHTXLUHG
ƒ 8VHUSURILOHPXVWKDYH $//2%-DQG 6(&$'0DXWKRULW\

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-15. Security-related restore system values

The following information includes descriptions of system values that relate to restoring
security-related objects on the system that should be considered when restoring objects as well.
• QVFYOBJRST: Verify object on restore
• QFRCCVNRST: Force conversion on restore
• QALWOBJRST: Allow restoring of security sensitive objects

© Copyright IBM Corp. 1995, 2017 4-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHPYDOXHVWKDWDSSO\WRSDVVZRUGV
‡ 3XUSRVH
ƒ 6SHFLI\V\VWHPYDOXHVWRVHWUHTXLUHPHQWVIRUWKHSDVVZRUGVXVHUVDVVLJQ

‡ +RZWRVHW
ƒ WRKSYSVAL *SEC

‡ $XWKRULW\UHTXLUHG
ƒ 8VHUSURILOHPXVWKDYH $//2%-DQG 6(&$'0DXWKRULW\

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-16. System values that apply to passwords

The system values control passwords:


• QPWDCHGBLK: Block password change (New at V6R1)
• QPWDEXPITV: Expiration interval
• QPWDEXPWRN: Password expiration warning (New at V6R1)
• QPWDLVL: Password level
• QPWDLMTCHR: Restricted characters
• QPWDLMTAJC: Restrict adjacent characters
• QPWDLMTREP: Restrict repeating characters
• QPWDMINLEN: Minimum length
• QPWDMAXLEN: Maximum length
• QPWDRQDDGT: Require digit in password
• QPWDPOSDIF: Character position difference
• QPWDRQDDIF: Required difference
• QRETSVRSEC: Retain server security data
• QPWDRULES: Password rules
• QPWDVLDPGM: Password validation program

© Copyright IBM Corp. 1995, 2017 4-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHPYDOXHVWKDWFRQWURODXGLWLQJ
‡ 3XUSRVH
ƒ 6SHFLI\V\VWHPYDOXHVWRFRQWUROVHFXULW\DXGLWLQJRQWKHV\VWHP

‡ +RZWRVHW
ƒ WRKSYSVAL *SEC

‡ $XWKRULW\UHTXLUHG
ƒ 8VHUSURILOHPXVWKDYH $8',7DXWKRULW\

‡ -RXUQDOHQWU\
ƒ SV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-17. System values that control auditing

These system values control auditing on the system:


• QAUDCTL: Auditing control
• QAUDENDACN: Auditing end action
• QAUDFRCLVL: Force auditing data
• QAUDLVL: Security auditing level
• QAUDLVL2: Security auditing level extension
• QCRTOBJAUD: Create object auditing

© Copyright IBM Corp. 1995, 2017 4-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty
4.3. Topic 3: Using IBM Navigator for i to
configure system values

© Copyright IBM Corp. 1995, 2017 4-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

7RSLF8VLQJ,%01DYLJDWRU
IRULWRFRQILJXUHV\VWHP
YDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-18. Topic 3: Using IBM Navigator for i to configure system values

© Copyright IBM Corp. 1995, 2017 4-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

&RQILJXUDWLRQDQG6HUYLFH6\VWHP9DOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-19. Configuration and Service: System Values

To work with system value using IBM Navigator for i do following steps.
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management click Configuration and Services.
4. Expand System Values.
5. On the main pane, choose system value category to work with and right-click the name and
from pop-up menu choose Properties.
Next few slides you can look around few system values.

© Copyright IBM Corp. 1995, 2017 4-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV$XGLWLQJ

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-20. System Values: Auditing

Use the System page to specify system level auditing activation controls. There are two basic types
of auditing that can be used in combination with each other:
• Auditing of specific actions (action auditing)
• Auditing of access to specific resources (object auditing)
Use the Journaling page to specify the action to take if the system is unable to write audit entries.
Use the New Objects page to specify the default auditing value for newly created objects. The value
you select depends upon your auditing requirements.

© Copyright IBM Corp. 1995, 2017 4-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV'DWHDQG7LPH

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-21. System Values: Date and Time

Use the Date page to specify the current date for your system. The Date page also specifies a leap
year adjustment that ensures that the system date is correct when a leap year occurs.
Use the Time page to specify the settings related to system time.

© Copyright IBM Corp. 1995, 2017 4-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV'HYLFHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-22. System Values: Devices

Use the Automatic Configuration page to specify automatic configuration controls. This page allows
you to specify which objects are automatically configured. Automatic configuration is a function that
names and creates devices and controllers. The objects are also varied on.
Use the Recovery page to specify the action to take when a device error occurs on the workstation.
A device error occurs when the workstation is communicating (input/output) with your system.

© Copyright IBM Corp. 1995, 2017 4-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV,QWHUQDWLRQDOV\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-23. System Values: International system values

Use the Formats page to view or change the system level date format, decimal format, and
currency symbol.
Use the Language/Characters page to view or change general international system values. You
can also specify coded character set information.
Use the Sort Sequence page to view or change the sort sequence table. Sort sequence is the order
in which characters are arranged within the computer to sort, combine, or compare data. The sort
sequence tables sort characters more accurately, in accordance with the cultural requirements of
users. Regardless of the country/region or single-byte coded character set language in use, you
can sort lists.
Use the DBCS page to view or change the coded font point size that is used with the coded font
when transforming a SNA character string (SCS) into an Advanced Function Printing data stream
(AFPDS).
Use the Locale page to view or change the default locale for the system.

© Copyright IBM Corp. 1995, 2017 4-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV-REV RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-24. System Values: Jobs (1 of 3)

Use the Allocation page to specify the amount of storage allocated at restart and the amount of
additional storage. This allows your system to have high performance when running various
functions.
Use the Job Log page to view and change the job log maximum size, how the job log is created,
and what actions to take when the maximum is reached.
Use the Interactive Jobs page to specify the action to take when jobs reach a timeout. You can also
specify how long to give an operation before the job times out. You can specify information for both
inactive jobs and disconnected jobs.

© Copyright IBM Corp. 1995, 2017 4-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV-REV RI

,%0L
)LYHPLQXWHVLQDFWLYH

QCPFMSG
&3,
*MSGF
DSPMSG

INACTMSGQ
6\VWHPYDOXHV 25
* MSGQ
QINACTITV (5)
QINACTMSGQ (INACTMSGQ)
INACTPGM
*PGM
CRTMSGQ INACTMSGQ

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-25. System Values: Jobs (2 of 3)

• Here the alternate way of using QINACTMSGQ is shown: a timeout message can be sent to a
message queue and an operator or a program can take the appropriate action.
• User or program can monitor for message on message queue and take appropriate action.
• Message ID is CPI1126.

© Copyright IBM Corp. 1995, 2017 4-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV-REV RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-26. System Values: Jobs (3 of 3)

Use the Threads page to specify the action to take when a function that might not be threadsafe is
called in a job that is running with multiple threads.
Use the Printer Output page to specify whether printer output (spooled files) is kept with a job or
detached from the job. You can also specify printer output specifications such as the initial and
maximum printer output file sizes.
Use the Cleanup page to specify the maximum time allowed for a job to end immediately.
Use the Other page to specify whether jobs can be interrupted to run user-defined exit programs.

© Copyright IBM Corp. 1995, 2017 4-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV/LEUDU\OLVWV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-27. System Values: Library lists

Use the System page to view or change the system part of the library list. The list can contain as
many as 15 names. When searching for an object in the library list, the system libraries are
searched before any user libraries are searched. A library specified as part of the library list cannot
be deleted or renamed when the system is fully operational.
Use the User page to view or change the user part of the library list. The user library list specifies
the selected libraries for the user part of the library list. The list can contain as many as 25 names.
When searching for an object in the library list, the user libraries are searched after the system
libraries, product library, and current library entries. A library specified as part of the library list
cannot be deleted or renamed when the system is fully operational.
For both system and user library list the libraries must exist in the system disk pool or in a basic
user disk pool.

© Copyright IBM Corp. 1995, 2017 4-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV0HVVDJHVDQG6HUYLFH

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-28. System Values: Messages and Service

Use the General page to view or change message options. These options allow you to control the
number of records in the history log, specify to display status messages, specify the message
queue to use, and accounting information.
Use the Problems page to view or change options related to the problem log and problem reporting.
Use the Remote page to specify whether to allow remote service of a system. This allows you to
service a system from an area other than where the system is located.

© Copyright IBM Corp. 1995, 2017 4-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3DVVZRUG RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-29. System Values: Password (1 of 2)

Use the General page to specify the password level at the next restart. Here you can also specify
time between password changes and if required program to control the validation of new
passwords.
Use the Validation 1 page to specify password restrictions.

Note

If you make changes on the Validation 2 tab, some of the values on this tab will be ignored by the
system.

© Copyright IBM Corp. 1995, 2017 4-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3DVVZRUG RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-30. System Values: Password (2 of 2)

Use the Validation 2 page to specify password restrictions. Changing values on this tab causes
certain corresponding system values on the Validation 1 tab to be ignored by the system.
Use the Expiration page to specify whether a password must be changed at regular intervals.

© Copyright IBM Corp. 1995, 2017 4-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

3DVVZRUGUXOHVIRUFKDQJLQJSDVVZRUG
3DVVZRUGYDOLGDWLRQSURJUDP
1 3DVV
UXOHV

0HVVDJH <

1
QPWDVLDPGM

<
9DOLGDWLRQ
SURJUDP

0HVVDJH 3*0
1
GHWHFWV
HUURU"
3DVVZRUG
FKDQJHG
<
6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-31. Password rules for changing password

You can specify the Password Approval Program (QPWDVLDPGM) to control the validation of new
passwords.
If *REGFAC or a program name is specified in the QPWDVLDPGM system value, the system runs one
or more programs after the new password passes any validation tests you specify in the
password-control system values. You can use the programs to do additional checking of
user-assigned passwords before they are accepted by the system.
The topic “Using a Password Approval Program” in the book IBM i 7.3 Security - Security
Reference discusses the requirements of the password approval program and shows an example.

Note

*REGFAC - The validation program is retrieved from the registration facility, exit point
QIBM_QSY_VLD_PASSWRD, format VLDP0100. More than one validation program can be
specified in the registration facility. Each program is called until one of them indicates that the
password should be rejected or all of them have indicated the password is valid.

© Copyright IBM Corp. 1995, 2017 4-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3HUIRUPDQFH RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-32. System Values: Performance (1 of 2)

Use the General page to specify the adjustment of interactive jobs to maintain high performance
and to turn the dynamic priority scheduling on and off.
Use the Memory Pools page to specify memory pool options. A memory pool is a logical division of
memory (storage) that is reserved for processing a job or group of jobs. You can specify the m.
Use the Communications page to view or change options for communications configuration
recovery, the number of communications arbiter jobs to start, and the number of target display
station pass-through server jobs. memory pool size, when to adjust memory pool and activity
levels, and whether interactive jobs are moved to the base pool at the end of the time slice.

© Copyright IBM Corp. 1995, 2017 4-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3HUIRUPDQFH RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-33. System Values: Performance (2 of 2)

Use the Database page to specify parallel processing configurations, the time limit for the database
query, and the database file statistics to collect.
Use the Library Lists page to specify whether to lock libraries in a user job's library search list.
Use the Affinity page to specify whether secondary threads use the same subset of system
resources as the initial thread. A subset of system resources consists of a set of processors and an
allocation of main memory pool space. A system can have multiple subsets of system resources.
The initial thread is given affinity to a specific subset of system resources.

© Copyright IBM Corp. 1995, 2017 4-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3RZHU&RQWURO RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-34. System Values: Power Control (1 of 2)

Use the General page to select the action to take when power failure occurs and which message
queue should receive notification messages.

© Copyright IBM Corp. 1995, 2017 4-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3RZHU&RQWURO RI

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-35. System Values: Power Control (2 of 2)

Use the General page to specify printer options for your system. You can select a default printer
and formatting options for your system.

© Copyright IBM Corp. 1995, 2017 4-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV3ULQWLQJ

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-36. System Values: Printing

Use the General page to specify printer options for your system. You can select a default printer
and formatting options for your system.

© Copyright IBM Corp. 1995, 2017 4-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV5HVWDUW RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-37. System Values: Restart (1 of 2)

Use the General page to view or change the type of restart to use on your system. The type of
restart and the restart options works together to perform the restart you prefer when a power failure
occurs.
Use the Setup page to view or change which program is used to start the system. This page also
allows you to select the controlling subsystem. The controlling subsystem is the first subsystem to
start whenever you restart the system.

© Copyright IBM Corp. 1995, 2017 4-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV5HVWDUW RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-38. System Values: Restart (2 of 2)

Use the Recovery page to view or change the action to take if an error occurs during restart.
Use the previous page to view information about the previous ending status of a system and the
previous restart.

© Copyright IBM Corp. 1995, 2017 4-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6DYHDQG5HVWRUH RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-39. System Values: Save and Restore (1 of 2)

Use the Signatures page to specify the verification level of signatures before a restore occurs.
Use the Conversion page to specify which objects are converted during the restore process.

© Copyright IBM Corp. 1995, 2017 4-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6DYHDQG5HVWRUH RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-40. System Values: Save and Restore (2 of 2)

Use the Objects page to specify whether objects with security-sensitive attributes can be restored.
Use the Access Paths page to specify whether to save access paths.

© Copyright IBM Corp. 1995, 2017 4-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6HFXULW\ RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-41. System Values: Security (1 of 3)

Use the General page to specify the level of security for your system and additional system security
information.
Use the Public Authority page to specify the default public authority for each newly created object.
For each object, you can define what kind of access is available for any system user who does not
have any other authority to the object. Public authority is an effective means for securing
information and provides good performance.

© Copyright IBM Corp. 1995, 2017 4-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6HFXULW\ RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-42. System Values: Security (2 of 3)

Use the User Domain Objects page to specify where to allow objects to reside that are not
auditable, in addition to the QTEMP library.
Use the Scan page to specify which file systems are scanned using the integrated file system
scan-related exit programs. You can scan for a variety of reasons, depending on how the exit
program is defined. For example, you can scan for a specific text string, file name, or virus. Also, on
the Scan page, you can specify to use the default scan options or select specific scan options.

© Copyright IBM Corp. 1995, 2017 4-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6HFXULW\ RI 

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-43. System Values: Security (3 of 3)

Use the Shared Memory page to specify whether to allow access to shared memory and mapped
memory stream files.
Use the System SSL page to specifies the protocols and the list of cipher suites that are supported
by System SSL.

© Copyright IBM Corp. 1995, 2017 4-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6LJQRQ

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-44. System Values: Signon

Use the General page to view or change how many signon attempts a user is allowed. You can also
specify to display the signon information after the user has signed on. This page also allows you to
restrict user privileges and the number of device sessions.
Use the Remote page to specify how the system handles remote signon requests.

© Copyright IBM Corp. 1995, 2017 4-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6WRUDJH

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-45. System Values: Storage

Use the General page to view or change storage utilization and the action to take when the
maximum usage is reached.

© Copyright IBM Corp. 1995, 2017 4-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV6\VWHPDQG8VHU'HIDXOWV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-46. System Values: System and User Defaults

Use the System page to view your system's identification information.


Use the User page to specify the default values for the users on your system.

© Copyright IBM Corp. 1995, 2017 4-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

6\VWHP9DOXHV1HWZRUN$WWULEXWHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-47. System Values: Network Attributes

Use the Network Attributes page to setup main network attributes.

© Copyright IBM Corp. 1995, 2017 4-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH,QRUGHUWRLPSOHPHQWVHFXULW\RQ\RXUV\VWHP
\RXPXVWLQVWDOODGGLWLRQDOVHFXULW\VRIWZDUHRQ\RXUV\VWHP

 7UXHRUIDOVH,WLVSRVVLEOHWRORFNRXWXVHUVIURPFKDQJLQJ
V\VWHPYDOXHV

 7UXHRUIDOVH2QHRIWKHFRPSRQHQWVDYDLODEOHWRLPSOHPHQW
VHFXULW\RQ\RXUV\VWHPLVV\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-48. Review questions

© Copyright IBM Corp. 1995, 2017 4-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

5HYLHZDQVZHUV
 7UXHRUIDOVH,QRUGHUWRLPSOHPHQWVHFXULW\RQ\RXUV\VWHP
\RXPXVWLQVWDOODGGLWLRQDOVHFXULW\VRIWZDUHRQ\RXUV\VWHP
7KHDQVZHULVIDOVH

 7UXH RUIDOVH,WLVSRVVLEOHWRORFNRXWXVHUVIURPFKDQJLQJ
V\VWHPYDOXHV
7KHDQVZHULVWUXH

 7UXH RUIDOVH2QHRIWKHFRPSRQHQWVDYDLODEOHWRLPSOHPHQW
VHFXULW\RQ\RXUV\VWHPLVV\VWHPYDOXHV
7KHDQVZHULVWUXH

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-49. Review answers

© Copyright IBM Corp. 1995, 2017 4-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 4. Security-related system values

Uempty

8QLWVXPPDU\
‡ /LVWDQGH[SODLQWKHOHYHOVRIVHFXULW\DYDLODEOH
‡ 'HVFULEHWKHFDSDELOLW\LQVHUYLFHWRROVWRORFNRXWXVHUVIURPFKDQJLQJ
V\VWHPYDOXHV
‡ /LVWWKHVWHSVWRPRYHIURPRQHVHFXULW\OHYHOWRDQRWKHU
‡ 'HILQHWKHGLIIHUHQWFDWHJRULHVRIV\VWHPYDOXHVDYDLODEOH
‡ ([SODLQKRZWRXVHVHFXULW\SROLFLHVWRVHWV\VWHPYDOXHV
‡ /LVWWKHFRPPDQGVXVHGWRVHWV\VWHPYDOXHVZKHQXVLQJDQHPXODWLRQ
‡ /LVWWKHVWHSVXVHGLQ,%01DYLJDWRUIRULWRPDQLSXODWHV\VWHPYDOXHV

6HFXULW\UHODWHGV\VWHPYDOXHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 4-50. Unit summary

© Copyright IBM Corp. 1995, 2017 4-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

Unit 5. User security


Estimated time
01:10

Overview
There are three components used to implement security on this system. The operating system
continually checks system values, user profiles, and an object's resource security as it receives
requests from users to determine whether that user will be allowed to access the object in question.
In this unit, we will discuss user profiles and how you use these to customize the capabilities that a
user will have once he or she is signed on to the system.

How you will check your progress


• Review questions
• Exercises

© Copyright IBM Corp. 1995, 2017 5-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

8QLWREMHFWLYHV
‡ ([SODLQWKHSXUSRVHVHUYHGE\XVHUSURILOHV
‡ /LVWWKHVWHSVWRFUHDWHDXVHUSURILOH
‡ ([SODLQWKHSXUSRVHVHUYHGE\JURXSSURILOHV
‡ /LVWWKHVWHSVWRFUHDWHDJURXSSURILOH
‡ /LVWWKHVWHSVWRUHFRYHUDORVWRUIRUJRWWHQSDVVZRUGLQWKH26IRUWKH
VHFXULW\RIILFHSURILOH 46(&2)5
‡ /LVWWKHVWHSVWRUHFRYHUDORVWRUIRUJRWWHQSDVVZRUGLQVHUYLFHWRROVIRU
WKHVHFXULW\RIILFHSURILOH 46(&2)5

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 5-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

6HFXULW\FRPSRQHQWV

3HRSOH 2EMHFWV
XVHUV UHVRXUFHV
,QGLYLGXDO
8VHUSURILOHV
REMHFWV

-REGHVFULSWLRQV /LEUDU\GLUHFWRU\

*URXSSURILOHV $XWKRUL]DWLRQOLVWV

6\VWHPYDOXHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-2. Security components

Three components are used to implement security on this system. The operating system
continually checks system values, user profiles, and objects as it receives requests from users to
determine whether that user is allowed to access the object in question.
In this unit, we discuss user and group profiles and how you use these to customize capabilities
and what authority users have once they are signed on to the system.

© Copyright IBM Corp. 1995, 2017 5-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
5.1. Topic 1: User profiles

© Copyright IBM Corp. 1995, 2017 5-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

7RSLF8VHUSURILOHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-3. Topic 1: User profiles

© Copyright IBM Corp. 1995, 2017 5-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5ROHVVHUYHGE\XVHUSURILOHV
‡ $XVHUSURILOHKDVVHYHUDOUROHVRQWKHV\VWHP
ƒ &RQWUROVKRZWKHXVHUVLJQVRQWKHV\VWHP
ƒ &RQWUROVZKDWWKHXVHULVDOORZHGWRGRDIWHUVLJQLQJRQ
ƒ (VWDEOLVKHVKRZWKHXVHU¶VDFWLRQVDUHDXGLWHG
ƒ 'HVLJQHGWRFXVWRPL]HWKHV\VWHPDQGDGDSWLWWRWKHXVHU
ƒ 8VHGWRLGHQWLI\WKHXVHU¶VMREVDQGSULQWHURXWSXW
ƒ &RQWDLQVLQIRUPDWLRQDERXWWKHREMHFWVRZQHGE\WKHXVHU
ƒ &RQWDLQVLQIRUPDWLRQDERXWSULYDWHDXWKRULWLHVWRREMHFWV
ƒ ,VDPDQDJHPHQWDQGUHFRYHU\WRRO

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-4. Roles served by user profiles

A user profile has several roles on the system:


• It contains security-related information that controls how the user signs on the system, what the
user is allowed to do after signing on, and how the user's actions are audited.
• It contains information that is designed to customize the system and adapt it to the user.
• It is a management and recovery tool for the operating system. The user profile contains
information about the objects owned by the user and all the private authorities to objects.
• The user profile name identifies the user's jobs and printer output.

© Copyright IBM Corp. 1995, 2017 5-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

8VHUSURILOHV
‡ 3XUSRVH
ƒ 8VHGWRGHILQHXVHUVDQGJURXSVRQWKHV\VWHP
‡ +RZWRVHW
ƒ HPXODWLRQ
í WRKUSRPRF&UHDWHFKDQJHDQGGHOHWHSURILOHVRQWKHV\VWHP
í CHGUSRAUD&KDQJHXVHUDXGLWVHWWLQJV
ƒ ,%01DYLJDWRUIRUL8VHUVDQG*URXSV!8VHUV!3URSHUWLHV
‡ $XWKRULW\UHTXLUHG
ƒ 0XVWDWOHDVWKDYH 6(&$'0 DXWKRULW\WRZRUNZLWKSURILOHV
ƒ 0XVWKDYH $8',7DXWKRULW\WRFKDQJHXVHUDXGLWLQJ
‡ -RXUQDOHQWU\
ƒ $'IRUFKDQJHVWRXVHUDXGLWLQJ
ƒ &2IRUFUHDWLRQRIDXVHUSURILOH
ƒ &3IRUFKDQJHVWRXVHUSURILOHV
ƒ '2IRUGHOHWLRQRIDXVHUSURILOH
ƒ =&IRUFKDQJHVWRXVHUSURILOHWKDWDUHQRWUHOHYDQWWRVHFXULW\

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-5. User profiles

© Copyright IBM Corp. 1995, 2017 5-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

8VHUSURILOH

8VHULQIRUPDWLRQ
8VHUSURILOH ‡ 3DVVZRUG
7HOOVWKHV\VWHP
ZKR\RXDUH ‡ 3DVVZRUGH[SLUDWLRQOHYHO
‡ ,QLWLDOPHQXSURJUDP
‡ 8VHUFODVV
‡ 6SHFLDODXWKRULW\

/LVWRIREMHFWV 2EMHFW
RZQHG DXWKRUL]DWLRQV

‡ 6WDWLF
ƒ 8VHULQIRUPDWLRQ
‡ '\QDPLF
ƒ /LVWRIRZQHGREMHFWV
ƒ /LVWRIREMHFWDXWKRUL]DWLRQV
8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-6. User profile

The user profile contains a list of objects owned by the user profile, a list of objects that the user
profile does not own but is otherwise authorized to access, and information about the user: current
library, initial program, initial menu, special authorities, user class, group profile, maximum storage,
and much more.
Every object on the system must have an owner. If an object does not have an owner, it cannot be
used, and the RCLSTG command is typically run or executed in order to assign it to QDFTOWN.
Do not assign all (or nearly all) objects to only one owner profile. Profiles that own many objects
with many private authorities can become very large. To prevent impacts to either performance or
system operations, distribute ownership of objects to multiple profiles.
Avoid applications owned by IBM-supplied user profiles, such as QSECOFR or QPGMR. These
profiles can become difficult to manage because they own a large number of IBM-supplied objects.

© Copyright IBM Corp. 1995, 2017 5-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

$SSHQGL[%'HIDXOWYDOXHVIRUXVHUSURILOHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-7. Appendix B: Default values for user profiles

Refer to the table listed in Appendix B of the IBM i Security - Security Reference 7.3 manual,
SC41-5302-13.
This table shows the default values that are used for all IBM-supplied user profiles and on the
Create User Profile (CRTUSRPRF) command. The parameters are sequenced in the order they
appear on the Create User Profile display.

© Copyright IBM Corp. 1995, 2017 5-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

1HZXVHU

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-8. New user

To create new user profile, use the 5250 user interface and run the work with user profiles
(WRKUSRPRF) command. Use option 1 to create a user profile or run the create user profile
(CRTUSRPRF) command.
Another way is use graphic interface IBM Navigator for i. To create user profile run following:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand User and Groups.
4. Click Users.
5. On the main pane click arrow to open Action menu, on the drop-down menu choose New, then
select User.

© Copyright IBM Corp. 1995, 2017 5-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHDQHZXVHULQWHUIDFH RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-9. Create a new user: 5250 interface (1 of 2)

To create new user profile, you can use 5250 interface running WRKUSRPRF command and option 1
Create or running CRTUSRPRF command.
You can see more parameters when you press function key F10 Additional parameters and then
use PGDWN key to see additional screens with parameters.

© Copyright IBM Corp. 1995, 2017 5-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHDQHZXVHULQWHUIDFH RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-10. Create a new user: 5250 interface (2 of 2)

Going through parameters you can find among others: Job description, Group profile. International
settings like sort sequence CCSID or Language ID. For advanced USER or Group ID.
Parameters for Enterprise Identity Mapping (EIM), or User expiration parameters.
The expiration parameters could be useful for temporary users.
Specifies the date when the user profile expires and is automatically disabled. Use the Display
Expiration Schedule (DSPEXPSCD) command to display a list of all user profiles set to expire. Or,
you can specify the expiration interval (in days) before the user profile is automatically disabled.

© Copyright IBM Corp. 1995, 2017 5-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-11. Create new user: IBM Navigator for i (1 of 3)

To create a new user profile using the IBM Navigator for i GUI, perform the following:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand User and Groups.
4. Click Users.
5. On the main pane click arrow to open Action menu, click New, then select User.

© Copyright IBM Corp. 1995, 2017 5-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-12. Create new user: IBM Navigator for i (2 of 3)

To set up more capabilities for new user profile click Capabilities link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Capabilities.
Privileges tab
Based on their privilege class, users can be given privileges that allow certain actions on system
resources. The Capabilities - Privileges dialog specifies the privileges for a user or for a group (and
the members of the group).
Password tab
Requiring users to change their passwords after a specified length of time reduces the risk of an
unauthorized person accessing the system. The Capabilities - Password dialog specifies the
change interval used for the user's password.

© Copyright IBM Corp. 1995, 2017 5-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-13. Create new user: IBM Navigator for i (3 of 3)

To set up more capabilities for new user profile click Capabilities link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New then select User.
5. Click Capabilities.
Auditing tab
A security auditor inside or outside your organization can use the auditing function that the system
provides to gather information about security-related events that occur on the system. The
Capabilities - Auditing dialog specifies the object auditing values for this user.
System values and values specified for users work together to control action auditing. Which events
you choose to log depends on both your security objectives and your potential exposures. The
Capabilities - Auditing dialog specifies the action auditing values for this user.

© Copyright IBM Corp. 1995, 2017 5-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

Note

You must have either *ALLOBJ or *AUDIT special authority on the My Connections system, or the
central system, to view the Auditing page of the Capabilities dialog.

Authority Collection tab


This panel shows the authority collection information for the selected user. If the user currently has
authority collection information available, the options (parameters) used to start that authority
collection are shown here.

© Copyright IBM Corp. 1995, 2017 5-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

6\VWHPSULYLOHJHV6SHFLDODXWKRULW\63&$87
‡ $OOREMHFWDFFHVV $//2%-
ƒ $FFHVVWRDOOV\VWHPUHVRXUFHV
‡ $XGLWLQJFRQWURO $8',7
ƒ &RQWURODXGLWV\VWHPYDOXHV
‡ -REFRQWURO -2%&7/
ƒ 0DQDJHRXWSXWTXHXHVMRETXHXHVDQGSULQWHUVFKDQJHMREDWWULEXWHVVWRS
VXEV\VWHPV,3/
‡ 6DYHUHVWRUH 6$96<6
ƒ 6DYHUHVWRUHDQGIUHHVWRUDJHIRUDOOV\VWHPREMHFWV
‡ 6HFXULW\DGPLQLVWUDWLRQ 6(&$'0
ƒ &UHDWHFKDQJHGHOHWHXVHUSURILOHVPDQDJHIRUREMHFWVDQGXVHUV
‡ 6SRROFRQWURO 63/&7/
ƒ 0DQDJHDOOXVHUV VSRROHGILOHV
‡ 6\VWHPFRQILJXUDWLRQ ,26<6&)*
ƒ &KDQJHV\VWHPFRQILJXUDWLRQ
‡ 6\VWHPVHUYLFHDFFHVV 6(59,&(
ƒ 'LVSOD\DQGDOWHUVHUYLFHIXQFWLRQ
8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-14. System privileges: Special authority: SPCAUT

© Copyright IBM Corp. 1995, 2017 5-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

3ULYLOHJHFODVVHV
6\VWHP
3ULYLOHJHFODVVHV
SULYLOHJHV
6HFXULW\ 6HFXULW\ 6\VWHP
3URJUDPPHU 8VHU
RIILFHU DGPLQLVWUDWRU RSHUDWRU
$OOREMHFWDFFHVV ;    

$XGLWLQJFRQWURO ;

-REFRQWURO ;  ; 

6DYHUHVWRUH ;  ;  

6HFXULW\
; ;
DGPLQLVWUDWLRQ

6SRROFRQWURO ;

6\VWHP
;
FRQILJXUDWLRQ
6\VWHPVHUYLFH
;
DFFHVV
8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-15. Privilege classes

On the slide you can compare which system privileges are available depending on classes
privileges and security level.

© Copyright IBM Corp. 1995, 2017 5-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL !&DSDELOLWLHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-16. Create new user: IBM Navigator for i > Capabilities

To set up more capabilities for new user profile click Capabilities link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New then select User.
5. Click Capabilities.
Certificates tab
From the Certificates dialog, you can open or delete certificates issued to a user. A certificate binds
a public key to the user that owns the certificate, enabling the certificate owner to be authenticated.
The Certificates list displays the issuer of a certificate, the serial number of the certificate, and the
expiration date of the certificate.
To delete a certificate, select a certificate from the list and click Delete.
To view more information about a certificate, select a certificate from the list and click Details.

© Copyright IBM Corp. 1995, 2017 5-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
Click Digital Certificate Manager to open a website that enables you to manage the certificates
you select.
Unique identifier tab
Specifies the unique identifier assigned to the user. Every user on the system must have a unique
user identification (UID) number.
You can change the UID number. Use a value from 1 to 4,294,967,294.
If you are creating a new user, you can select one of the following:
• Set the UID to a specific number.
• If your system is part of a network, you might need to assign a specific UID number to match
those assigned on other systems in the network. If you specify a UID number, use a number
from 1 to 4,294,967,294.
• Let each server choose a unique number.
• For best results, let each server generate these numbers. This option is available only when
you are creating a new user.

© Copyright IBM Corp. 1995, 2017 5-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL!-REV RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-17. Create new user: IBM Navigator for i > Jobs (1 of 2)

To set up more options for new user profile click Jobs link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Jobs.
General tab
Each piece of work in a system is called a job, and each job has a unique name. Jobs can have
values that determine how they are run on the system. These values can be specified for a user on
the Jobs - General dialog.
Session Startup tab
The Session Startup dialog specifies how this user's display session is set up when the user signs
on the system.

© Copyright IBM Corp. 1995, 2017 5-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL!-REV RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-18. Create new user: IBM Navigator for i > Jobs (2 of 2)

To set up more options for new user profile click Jobs link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Jobs.
Display Session tab
The Jobs - Display Session dialog specifies how this user's display session is set up when signed
on the system.
Output tab
The Output dialog specifies the output options for a user's jobs.
International tab
The Jobs - International dialog specifies the international values to be used for this user's jobs.
Click Advanced to view or change the sort sequence and the character ID control preferences to
be used.

© Copyright IBM Corp. 1995, 2017 5-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

'LVSOD\6HVVLRQ/LPLWFDSDELOLWLHV
‡ 7KH'LVSOD\6HVVLRQ WDEDOORZV\RXWROLPLWXVHUV¶FDSDELOLW\WRFKDQJHWKHLU
LQLWLDOSURJUDPPHQXFXUUHQWOLEUDU\DQGDWWHQWLRQSURJUDPDQGSURKLELWWKHP
IURPUXQQLQJPRVW3RZHU6\VWHPZLWK,%0LFRPPDQGV

/LPLWLQLWLDO
,QLWLDO ,QLWLDO &XUUHQW $WWHQWLRQ ([HFXWH
SURJUDPPHQX
SURJUDP PHQX OLEUDU\ SURJUDP FRPPDQGV
FDSDELOLWLHV

'RQRWOLPLW <HV <HV <HV <HV <HV

/LPLWVRPH
1R <HV 1R 1R <HV
FDSDELOLWLHV

/LPLWFDSDELOLWLHV 1R 1R 1R 1R 1R

1RWH8VHUVFDQVWLOOUXQFRPPDQGVFUHDWHGRUFKDQJHGZLWKSDUDPHWHU
ALWLMTCPB(*YES)

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-19. Display Session: Limit capabilities

© Copyright IBM Corp. 1995, 2017 5-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL!*URXSV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-20. Create new user: IBM Navigator for i > Groups

To set up more options for new user profile, click the Jobs link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Groups.
Group information tab
A user can be a member of a group. A group gives the same authority to all its members. A group
usually consists of people who work in the same department, have similar jobs, and who need to
use the same applications in the same way.
On the Groups - Group information dialog, you can view a list of the groups that include the user as
a member. You can also see the options specified for the user's first selected group.
You can add or remove a user from groups and specify options for the user's first selected group.

© Copyright IBM Corp. 1995, 2017 5-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL!3HUVRQDO RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-21. Create new user: IBM Navigator for i > Personal (1 of 2)

To set up more options for new user profile click Jobs link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Personal.
Name tab
The Name dialog offers you a place to view, add, or change the full name and organization of the
user along with other identifying personal information. This information is optional but can help you
better identify the user.

© Copyright IBM Corp. 1995, 2017 5-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
Location tab
The Location dialog offers you a place to view, add, or change the location and phone numbers of
the user along with other identifying information. This information is optional but can help you better
identify the user.
Mail tab
The Mail dialog offers you a place to view, add, or change how a local user receives mail.

© Copyright IBM Corp. 1995, 2017 5-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&UHDWHQHZXVHU,%01DYLJDWRUIRUL!3HUVRQDO RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-22. Create new user: IBM Navigator for i > Personal (2 of 2)

To set up more options for new user profile, click the Jobs link.
On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane click arrow to open Action menu, click New, then select User.
5. Click Network.
Name tab
The Remote Servers list provides a space for you to add, change, or remove authentication entries
for application servers on your system.
• Server name
▪ Lists the names of the application servers. You can sort the entries in ascending
alphabetical order by clicking once on the Server name heading. If you click the Server
name heading again, it is sorted in descending order. The server name can be up to 200
characters and is case-sensitive. Each server authentication entry must have a unique
server name.

© Copyright IBM Corp. 1995, 2017 5-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
• User name
▪ Lists the name of the user requesting access to the application server. For an existing user,
the user name is the user ID that you have setup on the system. If you add a new user, the
user name is Use user name. You can also type a user name. The user name can be up to
1000 characters.
You can sort the entries in ascending alphabetical order by clicking once on the User name
heading. If you click the User name heading again, it is sorted in descending order. This
field is case-sensitive.
• Password
▪ Lists the remote server password for the user. You can select None or you can type a
password. If the QRETSVRSEC system value is set to 0, you will not be able to type in a
password. The password can be up to 696 characters and is case-sensitive. This is a
required field for a Remote server user.

© Copyright IBM Corp. 1995, 2017 5-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

$SSHQGL[%,%0VXSSOLHGXVHUSURILOHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-23. Appendix B: IBM-supplied user profiles

This table lists each IBM-supplied profile, its purpose, and any values for the profile that are
different from the defaults for IBM-supplied user profiles.
IBM-supplied user profiles includes additional user profiles that are shipped with the licensed
program products. The table includes only some, but not all user profiles for licensed program
products.

© Copyright IBM Corp. 1995, 2017 5-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

8VHUIXQFWLRQV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-24. User functions

On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane right-click the selected user, from the pop-up menu select available function.
Or you can select to use by performing a click the check box next to the user, then click Action,
from the pop-up menu select available function.
Here are few functions.
User Objects: Allows you to work with user objects.
Delete: Allows delete user.
Authority Collection: Allows you to specify the options for the collection of authority information for
the selected user. The options on this panel correspond to the parameters for the STRAUTCOL CL
command.
Send Message: Allows you to send message.

© Copyright IBM Corp. 1995, 2017 5-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
Application Administration: Use the Application dialog to view and customize the applications
available to users and groups. Each application can contain one or more functions.
New: Allows you to create new user based on selected one.
Properties: Specify the properties that describe the user. If this is a new user, specify a unique user
name. Specify a description of the user to help you identify this user in a list of users, the password
for the user (and whether the user must change that password at the next logon), and whether the
user is allowed to sign on the system.

© Copyright IBM Corp. 1995, 2017 5-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&KDQJLQJDXVHUSURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-25. Changing a user profile

To change existing user profile, do the following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane right-click the selected user, then from the pop-up menu select Properties.
Now you can see similar dialog like was show when we discus about user creation.

© Copyright IBM Corp. 1995, 2017 5-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

$SSOLFDWLRQ$GPLQLVWUDWLRQ

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-26. Application Administration

To work with Application Administration do following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane right-click the selected user, from the pop-up menu select Application
Administration.
Use the Application dialog to view and customize the applications available to users and groups.
Each application can contain one or more functions.

© Copyright IBM Corp. 1995, 2017 5-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

'HOHWLQJDXVHUSURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-27. Deleting a user profile

To delete a User, do the following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. Click Users.
4. On the main pane right-click the selected user, from the pop-up menu select Delete.
When deleting a user, you have several decisions to make regarding the user's objects.
Specifies the action to take if the user you are deleting owns objects. Possible choices are:
• Do not delete.
• Select this to cancel the user delete action if the user owns objects.
• Delete objects that user owns.
• Select this to delete the objects that the user owns when the user is deleted.
• Transfer objects to another user.
• Select this to transfer ownership of objects to a different user. The objects are transferred to the
new user regardless of that user's current authority to the objects.

© Copyright IBM Corp. 1995, 2017 5-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

([HUFLVH:RUNLQJZLWKXVHUSURILOHV
‡ &UHDWHDXVHUSURILOH
‡ 2EVHUYHDQGYHULI\WKHSHUPLVVLRQVDVVRFLDWHGZLWKWKLVQHZ
XVHUSURILOH
‡ 7HVWKRZWKHLQLWLDOPHQXDQGOLPLWFDSDELOLWLHVSDUDPHWHUVZRUN
WRFRQWURODQGOLPLWZKDWDXVHULVDOORZHGWRGRDWVLJQRQ
‡ 9HULI\WKDWWKHOLPLWFDSDELOLWLHVVSHFLILHGIRUWKLVXVHUSURILOHDUH
ZRUNLQJDVH[SHFWHG
‡ 0DNHFKDQJHVWRDXVHUSURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-28. Exercise: Working with user profiles

© Copyright IBM Corp. 1995, 2017 5-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
5.2. Topic 2: Group profiles

© Copyright IBM Corp. 1995, 2017 5-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

7RSLF*URXSSURILOHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-29. Topic 2: Group profiles

© Copyright IBM Corp. 1995, 2017 5-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

0RUHIDFWVDERXWJURXSSURILOHV
‡ *URXSSURILOHVDOORZXVHUVZLWKVLPLODUMREVWRVKDUHSHUPLVVLRQVZLWKRXW
KDYLQJWRVKDUHWKHVDPHSDVVZRUG
‡ <RXVKRXOGFKRRVHDQDPLQJFRQYHQWLRQWKDWPDNHVJURXSVHDVLO\
UHFRJQL]DEOH
‡ <RXFDQFUHDWHDJURXSSURILOHZLWKQRSDVVZRUG VLJQRQQRWDOORZHG 
‡ <RXVKRXOGDVVLJQJURXSVLQRUGHURIXVH
‡ 3HUPLVVLRQVDUHDGGHGDWWKHJURXSOHYHO

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-30. More facts about group profiles

© Copyright IBM Corp. 1995, 2017 5-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5ROHVVHUYHGE\JURXSSURILOHV
‡ $JURXSSURILOHKDVVHYHUDOUROHV
ƒ 6HFXULW\WRRO
í ,WSURYLGHVDPHWKRGIRURUJDQL]LQJDXWKRULWLHVDQGVKDULQJWKHPDPRQJXVHUV
í ,WLVXVHGWRGHILQHREMHFWRUVSHFLDODXWKRULWLHVIRUJURXSSURILOHVUDWKHUWKDQIRU
HDFKLQGLYLGXDOXVHUSURILOH
í $XVHUFDQEHDPHPEHURIXSWRJURXSSURILOHV
ƒ &XVWRPL]LQJWRRO
í $JURXSSURILOHFDQEHXVHGDVDSDWWHUQIRUFUHDWLQJLQGLYLGXDOXVHUSURILOHV
í <RXFUHDWHJURXSSURILOHVLQWKHVDPHZD\WKDW\RXFUHDWHLQGLYLGXDOSURILOHV
í 7KHV\VWHPUHFRJQL]HVDJURXSSURILOHZKHQ\RXDGGWKHILUVWPHPEHUWRLW
í 7KHV\VWHPDOVRJHQHUDWHVDJURXSLGHQWLILFDWLRQQXPEHU *,' IRUWKHSURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-31. Roles served by group profiles

© Copyright IBM Corp. 1995, 2017 5-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

1HZ*URXS

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-32. New Group

To create new user group do following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. On the left pane click Create Group.
To create a new group on the system you can base the new group on an existing group (you can
copy attributes of an existing group to the new group).
To copy attributes from an existing group, enter a group name or click Browse... to see a list of
available groups.

© Copyright IBM Corp. 1995, 2017 5-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

1HZ*URXS3URSHUWLHV RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-33. New Group: Properties (1 of 2)

To change new user group Properties, do following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. On the left pane click Groups.
4. Right-click the selected group, from the pop-up menu select Properties.
Specify information about a group. You can specify the group's name, description, and the users
included in the group. From this dialog, you can continue specifying information about the group's
security and network options.
This is the place where you can add or remove user from group.

© Copyright IBM Corp. 1995, 2017 5-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

1HZ*URXS3URSHUWLHV RI

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-34. New Group: Properties (2 of 2)

To change new user group Properties, do following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. On the left pane click Groups.
4. Right-click the selected group, from the pop-up menu select Properties.
5. Click Capabilities to specify privileges. Based on their privilege class, users can be given
privileges that allow certain actions on system resources. The Capabilities - Privileges dialog
specifies the privileges for a user or for a group (and the members of the group).
6. Click Networks - For new groups, you can select one of the following:
▪ Set the UID and GID to specific numbers.
▪ If your system is part of a network, you might need to assign specific UID and GID numbers
to match those assigned on other systems in the network. If you specify UID and GID
numbers, use a number from 1 - 4,294,967,294.

© Copyright IBM Corp. 1995, 2017 5-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
▪ Let each server choose a unique number.
▪ For best results, let each server generate these numbers. This option is available only when
you are creating a new group.

© Copyright IBM Corp. 1995, 2017 5-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

*URXSIXQFWLRQV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-35. Group functions

To work with group functions do following:


On the web browser type [Link] or system name>:2001 and press Enter
key.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand User and Groups.
3. On the left pane click Groups.
4. Right-click the selected group, from the pop-up menu select functions available for group.

© Copyright IBM Corp. 1995, 2017 5-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

'HOHWLQJDJURXS

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-36. Deleting a group

When deleting a group, you must determine what to do if the group is the primary group of objects.
Primary group authority gives a group profile permission to an object. This permission is stored with
the object.
Groups that have system names (typically ones that start with Q like QSECOFR) cannot be
deleted.
Groups that have user members cannot be deleted.
Groups can be deleted if all owned objects and primary group objects are successfully transferred
to the specified group.
Groups can be changed if a new group name is specified to identify where to transfer ownership of
the owned objects.

© Copyright IBM Corp. 1995, 2017 5-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

([HUFLVH:RUNLQJZLWKJURXSSURILOHV
‡ 7HVWWRVHHWKHPHVVDJHVUHFHLYHGZKHQ\RXWU\WRDFFHVVDQ
REMHFWQRWDXWKRUL]HGWR\RXUSURILOH
‡ $GGDXVHUWRDJURXSWRJDLQDFFHVVWRREMHFWVWKDWDUH
VHFXUHGE\WKDWJURXSSURILOH
‡ 7HVW\RXUDFFHVVWRREMHFWVWKDWDUHDXWKRUL]HGWRDJURXS
SURILOH
‡ 9HULI\WKDWVSHFLILFXVHUDVVLJQHGDXWKRULWLHVRYHUULGH
DXWKRULWLHVJDLQHGE\EHORQJLQJWRDJURXSSURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-37. Exercise: Working with group profiles

© Copyright IBM Corp. 1995, 2017 5-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
5.3. Topic 3: Service tools security

© Copyright IBM Corp. 1995, 2017 5-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

7RSLF6HUYLFHWRROVVHFXULW\

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-38. Topic 3: Service tools security

© Copyright IBM Corp. 1995, 2017 5-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

6HUYLFHWRROVXVHU,'DGPLQLVWUDWLRQ
‡ 8VHUVPXVWDXWKHQWLFDWHWKHPVHOYHVWRDFFHVV'67DQG667

‡ 7KHVHUYLFHWRROVXVHU,'VDUHXVHGIRUERWK667DQG'67

‡ )HZLPSRUWDQWWKLQJV
ƒ 3DVVZRUGVDUHFDVHVHQVLWLYHDQGVKLSSHGH[SLUHG
ƒ $OOGHIDXOWSDVVZRUGVDUHVKLSSHGXSSHUFDVH7KLVLQFOXGHV
46(&2)5DQG4659
ƒ ,WLVQRZSRVVLEOHWRFUHDWHDQDGGLWLRQDOFXVWRPL]HGVHUYLFH
WRROVXVHU,'V
ƒ ,WLVUHFRPPHQGHGWKDWLQGLYLGXDOXVHUVRI'67VKRXOGKDYHWKHLU
RZQXVHU,'VDQGVKRXOGPDLQWDLQWKHLURZQSDVVZRUGV
ƒ 7KH,%0VXSSOLHG,'VVKRXOGEHXVHGRQO\LQUDUHFLUFXPVWDQFHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-39. Service tools user ID administration

© Copyright IBM Corp. 1995, 2017 5-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

6\VWHPVHUYLFHWRROV
‡ 6HUYLFHWRROVXVHUSURILOHV
ƒ 3URYLGHEHWWHUFRQWURORIDFFHVVWR667RU'67IXQFWLRQV
‡ 6HUYLFHWRROVGHYLFHSURILOHV
ƒ 3URYLGHDFFHVVWRIXQFWLRQVLQVHUYLFHWRROVGHYLFH,'VXVHGIRU/$1
DWWDFKHG2SHUDWLRQV&RQVROHDQGFOLHQW*8,VXSSRUWHGE\WKHVHUYLFHWRROV
VHUYHU
‡ 6HUYLFHWRROVVHFXULW\GDWD
ƒ 5HVHWRSHUDWLQJV\VWHPGHIDXOWSDVVZRUG
ƒ &KDQJHRSHUDWLQJV\VWHPLQVWDOOVHFXULW\
ƒ 9LHZVHUYLFHWRROVVHFXULW\ORJ
ƒ 6DYHDQGUHVWRUHVHUYLFHWRROVVHFXULW\GDWD
ƒ 0DQDJHSDVVZRUGOHYHO

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-40. System service tools

© Copyright IBM Corp. 1995, 2017 5-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

6HUYLFHWRROVXVHU,'VLQ667

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-41. Service tools user IDs in SST

To work with DST/SST user ID, run STRTSST you must specify DST/SST user ID and password
(case sensitive by default capital letter) Using DST/SST menu (in case on visual is SST menu).
Select option 8 Work with Service tools user ID and Devices to work with service tools user IDs and
Devices. Then, select option 1 Service tools user IDs. Use this option to change, create, delete,
enable, and disable service tools user IDs.

© Copyright IBM Corp. 1995, 2017 5-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

46(&2)5WHUPLQRORJ\
‡ :LWKLQ,%0LWKHUHDUHWZRVHFXULW\RIILFHUXVHUSURILOHV 46(&2)5 
‡ 7KH26XVHUSURILOHV
ƒ &UHDWHGZLWKWKH&UHDWH8VHU3URILOH CRTUSRPRF FRPPDQG
ƒ 8VHGWRVLJQRQWR,%0L
ƒ &RQWDLQVLWVRZQSDVVZRUG
‡ 7KHVHUYLFHWRROVXVHU,'V
ƒ &UHDWHGZLWKLQ'67WKURXJKWKH:RUNZLWK'67(QYLURQPHQWPHQXRSWLRQV
ƒ 8VHGWRVLJQRQWRVHUYLFHWRROV '67RU667
ƒ &RQWDLQVLWVRZQSDVVZRUG ZKLFKLVGLIIHUHQWIURPWKH26SURILOH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-42. QSECOFR terminology

© Copyright IBM Corp. 1995, 2017 5-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

/RVWSDVVZRUGIRU46(&2)5
‡ ,IWKH,%0L46(&2)5 SDVVZRUGLVORVW
ƒ 8VHCHGUSRPRF WRFKDQJHWKHSDVVZRUGIRU46(&2)5 UHTXLUHVWKDW\RXU
XVHU,'KDV $//2%-DQG 6(&$'0 
ƒ 8VH'676HUYLFH7RROV6HFXULW\'DWDRSWLRQ 5HVHWRSHUDWLQJV\VWHP
GHIDXOWSDVVZRUG 7KLVZLOOFKDQJHWKHSDVVZRUGWRWKHGHIDXOWVKLSSHG
YDOXHDWWKHQH[W,3/
‡ ,IWKHVHUYLFHWRROV46(&2)5 SDVVZRUGLVORVWRUGLVDEOHG
ƒ 7KH'67SDVVZRUGLVGLVDEOHGDIWHUWKUHHXQVXFFHVVIXODWWHPSWVWRVLJQRQ
ƒ 6LJQRQWRWKH26ZLWK46(&2)5 DQGLVVXHWKHFRPPDQG
CHGDSTPWD *default
ƒ <RXFDQDOVRXVHDQRWKHUVHUYLFHWRROV,'ZLWKWKHUHTXLUHGDXWKRULW\WRUHVHW
46(&2)5
ƒ 3HUIRUPDVFUDWFKLQVWDOO

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-43. Lost password for QSECOFR

© Copyright IBM Corp. 1995, 2017 5-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&KDQJLQJ'67SDVVZRUGV0DQXDOPRGHSURFHGXUH
‡ ,IWKHV\VWHPLVSRZHUHGRQ
ƒ 3XWWKHV\VWHPLQPDQXDOPRGH
ƒ 6HOHFWRSWLRQ RQWKHFRQWUROSDQHODQGSUHVV(QWHU 
ƒ 6LJQRQWRWKH'67VLJQRQVFUHHQDWWKHV\VWHPFRQVROH
‡ ,IWKHV\VWHPLVSRZHUHGRII
ƒ 3XWWKHNH\ORFNWR0DQXDOSRVLWLRQDQGVWDUWDQDWWHQGHG PDQXDO ,3/
ƒ $WWKH,3/RU,QVWDOOWKH6\VWHPGLVSOD\VHOHFWRSWLRQ 8VH'HGLFDWHG
6HUYLFH7RROV '67 
ƒ 7\SHLQRQHRIWKH'67VHFXULW\XVHU,'VDQGSDVVZRUGV
í QSECOFR
í QSRV
í 11111111
í 22222222

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-44. Changing DST passwords: Manual mode procedure

If you have Hardware Management Console (HMC), you can select logical partition, click the arrow
next to a partition name, and from the pop-up menu select Serviceability > Control Panel
Functions > (21) Activate Dedicated Service Tools.

© Copyright IBM Corp. 1995, 2017 5-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

&KDQJLQJ'67SDVVZRUGV0HQXQDYLJDWLRQ
‡ 2QWKH8VH'HGLFDWHG6HUYLFH7RROV '67 PHQXVHOHFWRSWLRQ
:RUNZLWK'67HQYLURQPHQW 
‡ 2QWKH:RUNZLWK'67(QYLURQPHQW PHQXVHOHFWRSWLRQ 6HUYLFH
WRROVXVHUSURILOHV 
‡ 2QWKH:RUNZLWK6HUYLFH7RROV8VHU3URILOHV PHQXVHOHFWRSWLRQ
&KDQJH3DVVZRUG 
‡ &KDQJHSDVVZRUGVIRUWKHGHIDXOWXVHU,'V
ƒ QSECOFR
ƒ QSRV
ƒ 11111111
ƒ 22222222
‡ 3UHVV) ([LW WROHDYH'67PRGH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-45. Changing DST passwords: Menu navigation

© Copyright IBM Corp. 1995, 2017 5-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

667RSWLRQ$OORZFKDQJHRIVHFXULW\UHODWHGV\VWHP
YDOXHV

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-46. SST option 7: Allow change of security-related system values

Work with System Security provides master control of system security attributes.
• Allow system value security changes.
▪ When set to Yes, CHGSYSVAL can be used to change the following security-related system
values.
QALWJOBITP QCRTOBJAUD QPWDEXPWRN
QALWOBJRST QDEVRCYACN QPWDLMTAJC
QALWUSRDMN QDSCJOBITV QPWDLMTCHR
QAUDCTL QDSPSGNINF QPWDLMTREP
QAUDENACN QFRCCVNRST QPWDLVL
QAUDFRCLVL QINACTMSGQ QPWDMAXLEN
QAUDLVL QLMTDEVSSN QPWDMINLEN
QAUDLVL2 QLMTSECOFR QPWDPOSDIF
QAUTOCFG QMAXSGNACN QPWDRQDDGT
QAUTORMT QMAXSIGN QPWDRQDDIF
QAUTOVRT QPWDCHGBLK QPWDRULES
QCRTAUT QPWDEXPITV QPWDVLDPGM
QRETSVRSEC QSCANFSCTL QSSLCSLCTL
QRMTSIGN QSECURITY QSSLPCL
QRMTSRVATR QSHRMEMCTL QUSEADPAUT
QSCANFS QSSLCSL QVFYOBJRST

© Copyright IBM Corp. 1995, 2017 5-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty
▪ When set to No, CHGSYSVAL does not allow these system values to change and send
message CPF18C0.
• Allow new digital certificates
▪ When set to Yes, the Add Verifier (QYDOADDV) API can add digital certificates. Also
passwords for digital certificate stores can be reset.
• Allow a service tools user ID with a default and expired password to change its own password.
▪ When set to Yes, service tools user IDs that have a default and expired password are
allowed to change their passwords during SST sign-on (selecting F9 on the STRSST
sign-on display) or with the QSYCHGDS API. A default password is a password that is the
same as the service tools user ID.
▪ When set to No, service tools user IDs that have a default and expired password are not
allowed to change their passwords during SST sign-on or with the QSYCHGDS API.
▪ When the CHGDSTPWD PASSWORD(*DEFAULT) command is used, the service tools user
ID QSECOFR meets these restrictions and the password will not be allowed to be changed
from SST or the API.
▪ When service tools user IDs passwords are the default and expired and this option is set to
No, the passwords can be changed from DST. They can also be changed by using the
QSYCHGDS API with a requesting user that has the necessary authority as well as a
password that is not both default and expired.

© Copyright IBM Corp. 1995, 2017 5-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH8VHUSURILOHVDUHRQHRIWKHVHFXULW\
FRPSRQHQWVDYDLODEOHWRLPSOHPHQWVHFXULW\RQWKHV\VWHP

 7KHXVHUSURILOHGRHVQRWFRQWDLQZKLFKRIWKHIROORZLQJ"
D 3DVVZRUG
E 8VHUFODVVLILFDWLRQ
F 6SHFLDODXWKRULWLHVDVVLJQHG
G /LVWRIRZQHGREMHFW
H /LVWRIDXWKRUL]HGREMHFWV
I /LVWLQJRIDOOWKHDXWKRUL]DWLRQOLVWVZKHUHWKHXVHULVLQFOXGHG

 7KH EODQN VSHFLDODXWKRULW\DOORZVDXVHUDFFHVVWRDOO


V\VWHPUHVRXUFHV
D $//2%-
E -2%&7/
F 63/&7/
G 6(&$'0
H 6(59,&(

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-47. Review questions (1 of 3)

© Copyright IBM Corp. 1995, 2017 5-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH8VHUSURILOHVDUHRQHRIWKHVHFXULW\FRPSRQHQWV
DYDLODEOHWRLPSOHPHQWVHFXULW\RQWKHV\VWHP
7KHDQVZHULVWUXH

 7KHXVHUSURILOHGRHVQRWFRQWDLQZKLFKRIWKHIROORZLQJ"
D 3DVVZRUG
E 8VHUFODVVLILFDWLRQ
F 6SHFLDODXWKRULWLHVDVVLJQHG
G /LVWRIRZQHGREMHFW
H /LVWRIDXWKRUL]HGREMHFWV
I /LVWLQJRIDOOWKHDXWKRUL]DWLRQOLVWVZKHUHWKHXVHULVLQFOXGHG
7KHDQVZHULVOLVWLQJRIDOOWKHDXWKRUL]DWLRQOLVWVZKHUHWKHXVHULV
LQFOXGHG

 7KH $//2%- VSHFLDODXWKRULW\DOORZVDXVHUDFFHVVWRDOOV\VWHP


UHVRXUFHV
D $//2%-
E -2%&7/
F 63/&7/
G 6(&$'0
H 6(59,&(
7KHDQVZHULV $//2%-
8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-48. Review answers (1 of 3)

© Copyright IBM Corp. 1995, 2017 5-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH$XVHUSURILOHFDQEHXVHGWRVSHFLI\DQLQLWLDO
SURJUDPWREHFDOOHGZKHQWKHXVHUVLJQVRQWRWKHV\VWHP

 %\VSHFLI\LQJ EODQN \RXFDQNHHSDXVHUIURPFKDQJLQJ


ZKLFKPHQXDQGZKLFKOLEUDU\WKH\ZLOOVLJQRQWRIURPWKH
VLJQRQVFUHHQ
D 'RQRWOLPLWFDSDELOLWLHV
E /LPLWVRPHFDSDELOLWLHV
F /LPLWFDSDELOLWLHV

 7UXHRUIDOVH,GHDOO\JURXSSURILOHVVKRXOGEHFUHDWHGZLWKD
SDVVZRUGRI NONE EHFDXVH\RXVKRXOGQRWVLJQRQWRWKH
V\VWHPXVLQJWKLVJURXS,'

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-49. Review questions (2 of 3)

© Copyright IBM Corp. 1995, 2017 5-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH$XVHUSURILOHFDQEHXVHGWRVSHFLI\DQLQLWLDO
SURJUDPWREHFDOOHGZKHQWKHXVHUVLJQVRQWRWKHV\VWHP
7KHDQVZHULVWUXH

 %\VSHFLI\LQJOLPLWFDSDELOLWLHV\RXFDQNHHSDXVHUIURP
FKDQJLQJZKLFKPHQXDQGZKLFKOLEUDU\WKH\ZLOOVLJQRQWR
IURPWKHVLJQRQVFUHHQ
D 'RQRWOLPLWFDSDELOLWLHV
E /LPLWVRPHFDSDELOLWLHV
F /LPLWFDSDELOLWLHV
7KHDQVZHULVOLPLWFDSDELOLWLHV

 7UXH RUIDOVH,GHDOO\JURXSSURILOHVVKRXOGEHFUHDWHGZLWKD
SDVVZRUGRI NONE EHFDXVH\RXVKRXOGQRWVLJQRQWRWKH
V\VWHPXVLQJWKLVJURXS,'
7KHDQVZHULVWUXH

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-50. Review answers (2 of 3)

© Copyright IBM Corp. 1995, 2017 5-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZTXHVWLRQV RI
 7KHPD[LPXPQXPEHURIJURXSSURILOHVWKDWDXVHUFDQ
EHORQJWRLV"
D 
E 
F 
G NOLIMIT

 7UXHRUIDOVH7KHVDPH46(&2)5 XVHU,'DQGSDVVZRUG
DUHXVHGWRVLJQRQWRWKHRSHUDWLQJV\VWHPDQGWRVHUYLFH
WRROV

 7UXHRUIDOVH,FDQUHFRYHUWKH46(&2)5VHUYLFHWRRO
SURILOHE\VLJQLQJRQZLWKWKH,%0L46(&2)5SURILOHDQG
XVLQJWKHCHGDSTPWD FRPPDQG

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-51. Review questions (3 of 3)

© Copyright IBM Corp. 1995, 2017 5-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

5HYLHZDQVZHUV RI
 7KHPD[LPXPQXPEHURIJURXSSURILOHVWKDWDXVHUFDQ
EHORQJWRLV"
D 
E 
F 
G NOLIMIT
7KHDQVZHULV

 7UXHRUIDOVH7KHVDPH46(&2)5 XVHU,'DQGSDVVZRUG
DUHXVHGWRVLJQRQWRWKHRSHUDWLQJV\VWHPDQGWRVHUYLFH
WRROV
7KHDQVZHULVIDOVH

 7UXH RUIDOVH,FDQUHFRYHUWKH46(&2)5VHUYLFHWRRO
SURILOHE\VLJQLQJRQZLWKWKH,%0L46(&2)5SURILOHDQG
XVLQJWKHCHGDSTPWD FRPPDQG
7KHDQVZHULVWUXH
8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-52. Review answers (3 of 3)

© Copyright IBM Corp. 1995, 2017 5-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 5. User security

Uempty

8QLWVXPPDU\
‡ ([SODLQWKHSXUSRVHVHUYHGE\XVHUSURILOHV
‡ /LVWWKHVWHSVWRFUHDWHDXVHUSURILOH
‡ ([SODLQWKHSXUSRVHVHUYHGE\JURXSSURILOHV
‡ /LVWWKHVWHSVWRFUHDWHDJURXSSURILOH
‡ /LVWWKHVWHSVWRUHFRYHUDORVWRUIRUJRWWHQSDVVZRUGLQWKH26IRUWKH
VHFXULW\RIILFHSURILOH 46(&2)5
‡ /LVWWKHVWHSVWRUHFRYHUDORVWRUIRUJRWWHQSDVVZRUGLQVHUYLFHWRROVIRU
WKHVHFXULW\RIILFHSURILOH 46(&2)5

8VHUVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 5-53. Unit summary

© Copyright IBM Corp. 1995, 2017 5-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

Unit 6. Resource security


Estimated time
01:10

Overview
There are three components used to implement security on this system. The operating system
continually checks system values, user profiles, and an object's resource security as it receives
requests from users to determine whether that user will be allowed to access the object in question.
In this unit, we will discuss resource security and how you can authorize which objects users are
allowed to access and you can customize what actions a user can perform against the data once
an object is accessed.

How you will check your progress


• Review questions
• Exercises

References
SG24-5302-10 System i Security Reference
IBM Publications Center
[Link]
US

© Copyright IBM Corp. 1995, 2017 6-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHZKDWUHVRXUFHVHFXULW\LVDQGKRZLWLVLPSOHPHQWHG
‡ ([SODLQKRZRZQHUVKLSRIDQREMHFWLVHVWDEOLVKHG
‡ ([SODLQWKHSXUSRVHVHUYHGE\WKH4')72:1 XVHUSURILOH
‡ ([SODLQKRZSXEOLFDXWKRULW\LVDVVLJQHGWRDQREMHFW
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQREMHFWPDQDJHPHQWDQGGDWDDXWKRULW\
WKDWFDQEHDVVLJQHGWRDQREMHFW
‡ ([SODLQWKHSXUSRVHVHUYHGE\DQDXWKRUL]DWLRQOLVW
‡ /LVWWKHVWHSVWRVHFXUHDQREMHFWZLWKDQDXWKRUL]DWLRQOLVW
‡ 'HVFULEHWKHVHDUFKRUGHUXVHGE\WKHV\VWHPWRGHWHUPLQHZKHWKHUD
XVHULVDOORZHGWRDFFHVVDQREMHFW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 6-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6HFXULW\FRPSRQHQWV

3HRSOH 2EMHFWV
XVHUV UHVRXUFHV
,QGLYLGXDO
8VHUSURILOHV
REMHFWV

-REGHVFULSWLRQV /LEUDU\GLUHFWRU\

*URXSSURILOHV $XWKRUL]DWLRQOLVWV

6\VWHPYDOXHV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-2. Security components

There are three components used to implement security on this system. The operating system
continually checks system values, user profiles, and objects as it receives requests from users to
determine whether that user is allowed to access the object in question.
In this unit, we discuss user and group profiles and how you use these to customize the capabilities
and what authority users have once they are signed on to the system.

© Copyright IBM Corp. 1995, 2017 6-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.1. Topic 1: Resource security concepts

© Copyright IBM Corp. 1995, 2017 6-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF5HVRXUFHVHFXULW\
FRQFHSWV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-3. Topic 1: Resource security concepts

© Copyright IBM Corp. 1995, 2017 6-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

8VHURZQHGREMHFWV
‡ (DFKREMHFWKDVRQHRZQHU
‡ 7KHXVHUZKRFUHDWHVDQREMHFWLVDVVLJQHGDVWKHRZQHU
‡ 7KHRZQHULQLWLDOO\KDVDOOREMHFWDQGGDWDSHUPLVVLRQ
‡ 7KHDXWKRULW\FDQEHUHPRYHGEXWWKHRZQHUFDQJUDQWDQ\DXWKRULW\
EDFNWRKLPVHOIDWDQ\WLPH
‡ 7KHRZQHUVKLSRIDQREMHFWFDQEHWUDQVIHUUHGWRDQRWKHUXVHU
‡ ,WLVQRWSRVVLEOHWRGHOHWHDXVHUZKRRZQVREMHFWV7ZRVROXWLRQVDUH
RIIHUHG
ƒ 7UDQVIHURZQHUVKLS
ƒ 'HOHWHRZQHGREMHFWV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-4. User-owned objects

© Copyright IBM Corp. 1995, 2017 6-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

3ULPDU\JURXSDXWKRULW\
‡ 3ULPDU\JURXSDXWKRULW\LVVWRUHGLQWKHREMHFWKHDGHU JRRGIRU
SHUIRUPDQFH 
‡ 7KHUHFDQEHRQO\RQHSULPDU\JURXSDXWKRULW\SHUREMHFWXQOLNHUHDO
SULYDWHDXWKRULWLHVZKHUHWKHUHFDQEHPDQ\SHUREMHFW
‡ 7KHREMHFWRZQHUFDQQRWEHWKHSULPDU\JURXSIRUREMHFW
‡ :KHQDVVLJQLQJDSULPDU\JURXS
ƒ 2EMHFWFUHDWHGE\SURILOHZLWK*53$877<3 3*3 
ƒ 8VHWRKOBJPGP RUCHGOBJPGP WRVSHFLI\SULPDU\JURXSREMHFW
ƒ 8VHCHGPGP IRUREMHFWVLQWKHLQWHJUDWHGILOHV\VWHP

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-5. Primary group authority

The name of the primary group profile and the primary group's authority to the object are stored
with the object. Using primary group authority might provide better performance than using private
group authority when checking authority to an object.
A profile must be a group profile (have a GID) to be assigned as the primary group for an object.
The same profile cannot be the owner of the object and its primary group.
You can specify a primary group for an object. The name of the primary group profile and the
primary group's authority to the object are stored with the object. Primary group authority is not
considered private authority.
You can change these authorities either through IBM Navigator for i, or through command
parameters.
The GRPAUTTYP parameter in a user profile can be used to make the user's group the primary
group for the object. Use the CHGOBJPGP or WRKOBJPGP commands to specify the primary group
for an object. You can change the authority the primary group has by using EDTOBJAUT or the
GRTOBJAUT and RVKOBJAUT commands.

© Copyright IBM Corp. 1995, 2017 6-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

4')72:1
‡ 4')72:1 LVDQ,%0VXSSOLHGXVHUSURILOHXVHGZKHQ
ƒ $QREMHFWKDVQRRZQHU
ƒ 7KHREMHFWRZQHUVKLSPLJKWSRVHVHFXULW\H[SRVXUH
‡ 7KHREMHFWRZQHUVKLSLVDVVLJQHGWR4')72:1 LQWKHIROORZLQJFDVHV
ƒ 7KHRZQLQJSURILOHEHFRPHVGDPDJHGDQGLVGHOHWHG7KHRCLSTG
FRPPDQGDVVLJQVRZQHUVKLSRIREMHFWVWR4')72:1
ƒ $QREMHFWLVUHVWRUHGDQGWKHRZQHUSURILOHGRHVQRWH[LVW
ƒ $SURJUDPWKDWQHHGVWREHFUHDWHGDJDLQLVUHVWRUHGEXWSURJUDPFUHDWLRQ
LVQRWVXFFHVVIXO
ƒ 7KHPD[LPXPVWRUDJHOLPLWLVH[FHHGHGIRUWKHXVHUSURILOHWKDWRZQVDQ
DXWKRULW\KROGHUWKDWKDVVDPHQDPHDVWKHILOHEHLQJPRYHGUHQDPHGRU
ZKRVHOLEUDU\LVEHLQJUHQDPHG
‡ &RQVLGHUWKHIROORZLQJUHFRPPHQGDWLRQV
ƒ 4')72:1 VKRXOGQRWQRUPDOO\RZQREMHFWV
ƒ 2ZQHUVKLSFDQEHWUDQVIHUUHGZLWKWKHWRKOBJOWN FRPPDQGE\,%0
1DYLJDWRUIRUL

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-6. QDFTOWN

© Copyright IBM Corp. 1995, 2017 6-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

:KHUHREMHFWSHUPLVVLRQVFRPHIURP
‡ 7RDFFHVVRUXVHDQREMHFW\RXPXVWKDYHWKHDSSURSULDWHDXWKRULW\
7KLVDXWKRULW\FDQFRPHIURP
ƒ $OOREMHFWDFFHVV $//2%- VSHFLDODXWKRULW\
ƒ $SULYDWHRUH[SOLFLWDXWKRULW\WRWKHREMHFW
ƒ $XWKRUL]DWLRQOLVW
ƒ 3ULPDU\JURXSDXWKRULW\
ƒ 3XEOLFDXWKRULW\ 38%/,&
ƒ $GRSWHGDXWKRULW\

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-7. Where object permissions come from

Authority means the type of access allowed to an object. Different operations require different types
of authority.
All objects have public authority. This is the authority you get when you do not have any other
authority to the object. Public authority can be *EXCLUDE, which implies that the public (all user
profiles that do not have *ALLOBJ special authority) is excluded from an object, unless in one or the
other way special authority is granted.

© Copyright IBM Corp. 1995, 2017 6-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

:KHUH 38%/,&DXWKRULW\FRPHVIURP
‡ 'HILQHGE\WKHAUT SDUDPHWHURQWKHCRTxxx FRPPDQG
‡ ,WGHIDXOWVWR*LIBCRTAUT

6\VWHPYDOXHV

QCRTAUT: *CHANGE
/LEUDU\ 3$</,%

CRTAUT: *SYSVAL

2XWSXWTXHXH 0<48(8(

AUT(*LIBCRTAUT)

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-8. Where *PUBLIC authority comes from

Every library has a parameter called CRTAUT (create authority). This parameter determines the
default public authority for any new object that is created in that library. When you create an object,
the AUT parameter on the create command determines the public authority for the object. If the AUT
value on the create command is *LIBCRTAUT, which is the default, the public authority for the
object is set to the CRTAUT value for the library.
The QCRTAUT system value is used to determine the public authority for a newly created object if
the following conditions are met:
• The create authority (CRTAUT) parameter for the library of the new object is set to *SYSVAL.
• The new object is created with public authority (AUT) of *LIBCRTAUT.
The default value for the QCRTAUT system value is *CHANGE. This can introduce a higher authority
level to new objects than actually needed. However, changing this system value to *USE or
*EXCLUDE caused problems for some objects, such as automatically created device descriptions.
Currently, the default value for the AUT parameter is *CHANGE on several CRT commands for line,
controller, and device description. This can solve the problem with public authority of automatically
created configuration objects.

© Copyright IBM Corp. 1995, 2017 6-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6SHFLILFREMHFWSHUPLVVLRQV
‡ 3ULYDWHDQGSXEOLFSHUPLVVLRQVFRQVLVWRIRQHRUPRUHRIWKH
IROORZLQJ
6SHFLILFREMHFWDXWKRULWLHV

([FOXGH

2EMHFWPDQDJHPHQW 'DWDDXWKRULW\

2SHUDWLRQDO 5HDG

0DQDJHPHQW $GG

([LVWHQFH 8SGDWH

$OWHU 'HOHWH

5HIHUHQFH ([HFXWH

$XWKRUL]DWLRQOLVW
5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-9. Specific object permissions

Authority to an object is divided into three categories:


1. Object authority defines what operations can be performed on the object as a whole.
2. Data authority defines what operations can be performed on the contents of the object.
3. Field authority defines what operations can be performed on data fields. Field authorities
(Reference and Update) are supported through the SQL statements GRANT and REVOKE.
You can display these authorities through DSPOBJAUT and EDTOBJAUT.

© Copyright IBM Corp. 1995, 2017 6-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

2EMHFWPDQDJHPHQWSHUPLVVLRQV

3HUPLVVLRQ 'HILQLWLRQ

/RRNDWWKHGHVFULSWLRQRIDQREMHFWDQGXVHWKHREMHFWDVGHWHUPLQHGE\WKH
2SHUDWLRQDO
GDWDDXWKRULWLHVWKHXVHUKDV
OBJOPR
7RRSHQDILOHWKHXVHUPXVWKDYH OBJOPR
$XWKRUL]HXVHUVWRWKHREMHFWPRYHRUUHQDPHWKHREMHFWDQGDGGPHPEHUV
0DQDJHPHQW
WRGDWDEDVHILOHV
OBJMGT
$OOIXQFWLRQVGHILQHGIRU OBJALTER DQG OBJREF

([LVWHQFH &KDQJHRZQHUVKLSDQGGHOHWHWKHREMHFWIUHHVWRUDJHIRUWKHREMHFWDQG
OBJEXIST SHUIRUPVDYHDQGUHVWRUHRSHUDWLRQVIRUWKHREMHFW

$GGFOHDULQLWLDOL]HDQGUHRUJDQL]HPHPEHUVRIGDWDEDVHILOHVDOWHUDQGDGG
$OWHU
DWWULEXWHVWRGDWDEDVHILOHVDGGDQGUHPRYHWULJJHUVDQGFKDQJHDWWULEXWHVRI
OBJALTER
64/SDFNDJHV

5HIHUHQFH
6SHFLI\GDWDEDVHILOHDVWKHSDUHQWLQDUHIHUHQWLDOFRQVWUDLQW
OBJREF

$XWKRUL]DWLRQOLVW
$GGDQGUHPRYHXVHUVDQGWKHLUDXWKRULWLHVIURPDQDXWKRUL]DWLRQOLVW
AUTLMGT

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-10. Object management permissions

Notice that authorization list management authority might not be specified for the public at the time
of creation of the object. For some objects, such as files and programs, public authority might be
controlled by specifying the name of an authorization list.

© Copyright IBM Corp. 1995, 2017 6-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

'DWDSHUPLVVLRQV

3HUPLVVLRQ 'HILQLWLRQ

5HDG
'LVSOD\WKHFRQWHQWVRIDQREMHFWVXFKDVYLHZLQJWKHUHFRUGVLQDILOH
READ

$GG $GGHQWULHVWRDQREMHFWVXFKDVDGGLQJPHVVDJHVWRDPHVVDJHTXHXHRU
ADD UHFRUGVWRDILOH

8SGDWH
&KDQJHHQWULHVLQDQREMHFWVXFKDVFKDQJLQJUHFRUGVLQDILOH
UPD

'HOHWH 5HPRYHHQWULHVIURPDQREMHFWVXFKDVUHPRYLQJPHVVDJHVIURPD
DLT PHVVDJHTXHXHRUGHOHWLQJUHFRUGVIURPDILOH

([HFXWH
5XQDSURJUDPRUVHDUFKDOLEUDU\RUGLUHFWRU\
EXECUTE

([FOXGH
2EMHFWDFFHVVSUHYHQWHG
EXCLUDE

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-11. Data permissions

Exclude is a specific authority. The absence of a specific authority does not mean that the access is
excluded. It means that an authority is found elsewhere, according to the authority checking
process.
Field authorities (Reference and Update) are supported through SQL statements GRANT and
REVOKE. You can display these authorities through DSPOBJAUT and EDTOBJAUT.

© Copyright IBM Corp. 1995, 2017 6-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

&RPPRQO\XVHGSHUPLVVLRQV

2EMHFWFRQWURO 'DWDDXWKRULW\
2SHUDWLRQ 0DQDJHPHQW ([LVWHQFH $OWHU 5HIHUHQFH 5HDG $GG 8SGDWH 'HOHWH ([HFXWH

$OO ; ; ; ; ; ; ; ; ; ;

&KDQJH ; ; ; ; ; ;

8VH ; ; ;

([FOXGH

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-12. Commonly used permissions

Certain sets of object and data authorities are commonly required to perform operations on objects.
You can specify these system-defined sets of authority (*ALL, *CHANGE, *USE) instead of
individually defining the authorities needed for an object.
*EXCLUDE authority is different than having no authority.

© Copyright IBM Corp. 1995, 2017 6-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6SHFLI\LQJVSHFLILFDXWKRULW\IRUREMHFWVLQWKHLQWHJUDWHG
ILOHV\VWHP
‡ 5:;2EMHFWRSHUDWLRQDODXWKRULW\DQGDOOWKHGDWDDXWKRULWLHV
‡ 5;2EMHFWRSHUDWLRQDODXWKRULW\UHDGDQGH[HFXWH
‡ 5:2EMHFWRSHUDWLRQDODXWKRULW\UHDGDGGXSGDWHDQGGHOHWH
‡ :;2EMHFWRSHUDWLRQDODXWKRULW\DGGXSGDWHGHOHWHDQGH[HFXWH
‡ 52EMHFWRSHUDWLRQDODXWKRULW\DQGUHDG
‡ :2EMHFWRSHUDWLRQDODXWKRULW\DGGXSGDWHDQGGHOHWH
‡ ;2EMHFWRSHUDWLRQDODXWKRULW\DQGH[HFXWH
‡ (;&/8'(3UHYHQWVDFFHVVWRREMHFW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-13. Specifying specific authority for objects in the integrated file system

*RWX: The users are given *RWX authority to perform all operations on the object except those
limited to the owner or controlled by object existence, object management, object alter, and object
reference authority. The user can change the object and perform basic functions on the object.
*RWX authority provides object operational authority and all the data authorities.
*RX: The users are given *RX authority to perform basic operations on the object, such as run a
program or display the contents of a file. The user is prevented from changing the object. *RX
authority provides object operational authority and read and execute authorities.
*RW: The users are given *RW authority to view the contents of an object and change the contents
of an object. *RW authority provides object operational authority and data read, add, update, and
delete authorities.
*WX: The users are given *WX authority to change the contents of an object and run a program or
search a library or directory. *WX authority provides object operational authority and data add,
update, delete, and execute authorities.
*R: The users are given *R authority to view the contents of an object. *R authority provides object
operational authority and data read authority.

© Copyright IBM Corp. 1995, 2017 6-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
*W: The users are given *W authority to change the contents of an object. *W authority provides
object operational authority and data add, update, and delete authorities. Provides object
operational authority and data execute authority.
*EXCLUDE: Exclude authority prevents the user from accessing the object.
*AUTL: The public authority of the authorization list specified in the AUTL parameter is used for the
public authority for the object.

© Copyright IBM Corp. 1995, 2017 6-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.2. Topic 2: Defining resource security

© Copyright IBM Corp. 1995, 2017 6-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF'HILQLQJUHVRXUFH
VHFXULW\

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-14. Topic 2: Defining resource security

© Copyright IBM Corp. 1995, 2017 6-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

2EMHFWSHUPLVVLRQ46<6/,%ILOHV\VWHP

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-15. Object permission: [Link] file system

The File Systems function in IBM Navigator for i consists of the Integrated File System (IFS) as well
as IBM i NetServer File Shares. The IFS allows you to work with the files and folders on the Power
System with IBM i. File Shares shows the IBM i NetServer file shares. The IFS allows you open
[Link] up a separate window, which allows you to work with the IBM i objects. Now we review
setting up and editing the file system object permissions.
You can grant or revoke permissions on file system objects to restrict users from accessing them.
You can view or change the current permission settings of a file or folder by right-clicking the
file/folder and selecting Permissions from the context editor.
To work with Permissions using IBM Navigator for i do following:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand File Systems.
4. On the main pane right-click [Link] and from pop-up menu select Open.
5. On the main pane right-click the selected object and from pop-up menu select Permissions.

© Copyright IBM Corp. 1995, 2017 6-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

%DVLFDQG'HWDLOVSHUPLVVLRQGLVSOD\V
%DVLF &RPPRQO\XVHGSHUPLVVLRQV

'HWDLOV 2EMHFWDQGGDWDSHUPLVVLRQ

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-16. Basic and Details permission displays

The Permissions panel is used to:


• Specify individual access authority or permissions
• Specify the authorization list that manages authorities for this object
• Define who is designated as the owner of this object
• Define whether this object authority is controlled through a primary group
• Define the default public authority for newly created objects
• Define the specified object, data and where applicable column authority to this object
On this panel, you can click Add to add a user to the list of who is authorized to this object.
To change view from Basic to Details, you must select Authority View mode and click the Go
button.

© Copyright IBM Corp. 1995, 2017 6-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

3HUPLVVLRQ$GGDQG5HPRYH

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-17. Permission: Add and Remove

This visual shows the IBM Navigator for i permission screens for adding or removing users and the
permission allowed those users.
When you are adding permissions you can specify a user or select one or more from the list. To
remove a user, select user and use the Remove button.

© Copyright IBM Corp. 1995, 2017 6-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

3HUPLVVLRQ&XVWRPL]H

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-18. Permission: Customize

Shown are the screens for specifying detail permission for users and objects. Besides, the
standards of *USE, *CHANGE, *ALL and *EXCLUDE, custom permission is also available.

© Copyright IBM Corp. 1995, 2017 6-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

3HUPLVVLRQ$XWKRUL]DWLRQ/LVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-19. Permission: Authorization List

You can group objects with similar security requirements using an authorization list. An
authorization list, conceptually, contains a list of users and the authority that the users must the
objects secured by the list. The authorization list is explained later in the unit.

© Copyright IBM Corp. 1995, 2017 6-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

&KDQJHRZQHU&KDQJH3ULPDU\*URXS

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-20. Change owner: Change Primary Group

IBM Navigator for i also allows designation of a primary group profile.

© Copyright IBM Corp. 1995, 2017 6-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

3HUPLVVLRQVHDUFKRUGHU
$OOREMHFWDXWKRULW\ 8VHUSURILOH6WRSZKHQDQ\
3ULYDWHDXWKRULW\ DXWKRULW\LVIRXQG
$XWKRUL]DWLRQOLVW

1RQHIRXQG

$OOREMHFWDXWKRULW\ *URXSSURILOHV/LNHXVHUSURILOH
3ULPDU\JURXS 5HSHDWVIRUHDFKJURXSSURILOHDQG
3ULYDWHDXWKRULW\ DFFXPXODWHV6WRSVZKHQVXIILFLHQW
$XWKRUL]DWLRQOLVW DXWKRULW\LVDFFXPXODWHG

1RQHIRXQG
2EMHFW 3XEOLF 7KLVLVXVHGZKHQ
$XWKRUL]DWLRQOLVW QRDXWKRULW\LVIRXQGIRU
XVHURUJURXSV
,QVXIILFLHQW
$GRSWHGSURILOH $GRSWHGSURILOHV7KHVHDUH
$OOREMHFWDXWKRULW\ XVHGZKHQDXWKRULW\LV
3ULYDWHDXWKRULW\ LQVXIILFLHQW
$XWKRUL]DWLRQOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-21. Permission search order

The system goes through a permission search order.

© Copyright IBM Corp. 1995, 2017 6-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.3. Topic 3: Working with authorization lists

© Copyright IBM Corp. 1995, 2017 6-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF:RUNLQJZLWK
DXWKRUL]DWLRQOLVWV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-22. Topic 3: Working with authorization lists

© Copyright IBM Corp. 1995, 2017 6-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRUL]DWLRQOLVW

1DPH$87/
2ZQHU86(5 /,%$ /),/(%

8VHUDXWKRULW\

38%/,& ([FOXGH
86(5 8VH
86(5 &KDQJH 352*'
86(5 $OO 3),/(&
86(5 &KDQJH

38%/,&LVRQDOODXWKRUL]DWLRQOLVWV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-23. Authorization list

A user in an authorization list has the same authority to each of the objects controlled by the
authorization list. Notice that different users can have different authority to these objects.
In order to add or remove objects to an authorization list, or to add or remove users to an
authorizations list, authorization list management rights must be defined for the user profile that is
making these changes.
Setting up an authorization list requires three steps:
1. Creating the authorization list.
2. Adding users to the authorization list.
3. Locating each individual object and specifying that it is secured with the authorization list.

© Copyright IBM Corp. 1995, 2017 6-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

&UHDWHDQDXWKRUL]DWLRQOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-24. Create an authorization list

Authorization lists
The Authorization list function is used to:
• Create, delete, display, or change authorization lists
• Add, change, or remove users from the authorization lists
• Change the owner and primary group of an authorization list
• Display objects secured by the authorization list
This function is equivalent to using the CRTAUTL, DLTAUTL, ADDAUTLE, CHGAUTLE, and
RVMAUTLE commands.
To create a new authorization list, do following:
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand Security and click Authorization lists.
4. On the main pane click Actions menu and from menu items select New and then
Authorization List.
5. Put the name and description and choose public authority and press OK button to create lists.

© Copyright IBM Corp. 1995, 2017 6-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRUL]DWLRQOLVWSHUPLVVLRQV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-25. Authorization list permissions

To work with an authorization list permission, right-click the selected authority list and from pop-up
menu click Permissions.
From this interface, you can review the object location, object type, owner, and primary group and
list the objects secured by the authorization list; add new users or groups to the authorization list; or
change the owner or primary group.
The Basic and Details views display the permissions allowed by the authorization list. The Basic
view displays the user or groups permission to authorization list management authorities. These
authorities are Use, Change, All, and Exclude. The Details view displays the users or groups object
permissions (Operational, Management, Existence, Alter and Reference) and data permissions
(Read, Add, Update, Delete, and Execute).
To work with the authority that user's must the authorization list, you must have authorization list
management 9*AUTLMGT) authority, as well as the specific authorities you are granting.

© Copyright IBM Corp. 1995, 2017 6-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

2EMHFWVHFXUHGE\DQDXWKRUL]DWLRQOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-26. Object secured by an authorization list

You cannot change the Secured Objects list from the Secured Objects button. You can only list the
objects secured by the authorization list. To change the secured objects list, you must modify the
object to be secured to use the desired authorization list.

© Copyright IBM Corp. 1995, 2017 6-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6HFXULQJDQREMHFWZLWKDQDXWKRUL]DWLRQOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-27. Securing an object with an authorization list

Another way to see object secured by authorization list.


1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand File Systems and then click Integrated File
System and in main pane right-click [Link] and open it.
4. Find library and object and right-click the name and from pop-up menu choose Permissions.
5. On the Permission dialog, click the Authorization list and then Objects security.

© Copyright IBM Corp. 1995, 2017 6-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRUL]DWLRQOLVWFRQVLGHUDWLRQV
‡ <RXFDQQRWXVHDQDXWKRUL]DWLRQOLVWWRVSHFLI\DXWKRULW\WRDXVHUSURILOH
‡ <RXFDQQRWXVHDQDXWKRUL]DWLRQOLVWWRVSHFLI\DXWKRULW\WRDQ
DXWKRUL]DWLRQOLVW
‡ $QREMHFWFDQEHVHFXUHGE\RQO\RQHDXWKRUL]DWLRQOLVW
‡ 'HOHWLQJDQREMHFWGRHVQRWDIIHFWWKHOLVWWKDWVHFXUHGLW
‡ $XVHU VOLVWDXWKRULW\DSSOLHVWRDOOREMHFWVVHFXUHGE\WKDWOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-28. Authorization list considerations

© Copyright IBM Corp. 1995, 2017 6-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRUL]DWLRQOLVWYHUVXVJURXSSURILOH

%,// 8VH
),1'(37),/(
:$<1( $OO /,%
*811$58VH '63
)5$1. &KDQJH
2EMHFWV
$XWKRUL]DWLRQOLVW

%,// 8VH
*5283 ),1'(37),/(
:$<1( $OO /,%
&KDQJH '63
*811$5
)5$1. 2EMHFWV

*URXSSURILOH

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-29. Authorization list versus group profile

Authorization lists and group profiles both give multiple users access to multiple objects.

© Copyright IBM Corp. 1995, 2017 6-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

*URXSVDQG$87/VFRPSDUHG

$XWKRUL]DWLRQOLVWV *URXSV

$XWKRUL]DWLRQOLVWVFDQVHFXUH *URXSVFDQVHFXUHPXOWLSOH
PXOWLSOHREMHFWV REMHFWV
$XVHUFDQEHRQPXOWLSOHOLVWV $XVHUFDQEHDPHPEHURIXS
WRJURXSVDVDPD[LPXP
8VHUVFDQKDYHGLIIHUHQW $OOXVHUVLQDJURXSKDYHWKH
DXWKRULW\ VDPHDXWKRULW\
6DPHDXWKRULW\IRUGLIIHUHQW 'LIIHUHQWDXWKRULW\IRUGLIIHUHQW
REMHFWVXVLQJWKHVDPHOLVW REMHFWV
$QREMHFWFDQEHVHFXUHGE\ $QREMHFWFDQEHDXWKRUL]HGWR
RQO\RQHDXWKRUL]DWLRQOLVW PDQ\JURXSV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-30. Groups and AUTLs compared

Authorization lists are best used when users have different authorities to the same objects. Group
profiles are best used when users have the same authorities to the same objects.

© Copyright IBM Corp. 1995, 2017 6-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

([HUFLVH:RUNLQJZLWKDXWKRUL]DWLRQOLVWV
‡ &UHDWHDQDXWKRUL]DWLRQOLVW
‡ $GGDXVHUWRDQDXWKRUL]DWLRQOLVWDQGVSHFLI\ZKDWDXWKRULW\LV
DVVLJQHG
‡ 6HFXUHDQREMHFWZLWKDQDXWKRUL]DWLRQOLVW
‡ 'LVSOD\WKHOLVWRIXVHUVRQDQDXWKRUL]DWLRQOLVW
‡ 'LVSOD\ZKDWREMHFWVDUHVHFXUHGZLWKDQDXWKRUL]DWLRQOLVW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-31. Exercise: Working with authorization lists

© Copyright IBM Corp. 1995, 2017 6-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.4. Topic 4: Column-level authority

© Copyright IBM Corp. 1995, 2017 6-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF&ROXPQOHYHO
DXWKRULW\

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-32. Topic 4: Column-level authority

© Copyright IBM Corp. 1995, 2017 6-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

&ROXPQOHYHOVHFXULW\
*5$1783'$7( CDTLMT 21QCUSTCDT 722/*53

&86180 /671$0 &'7/07

 +(11,1* 

 7<521 

 7+20$6 

2/*531HHGV 2/1R
XSGDWHDFFHVV XSGDWHDFFHVV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-33. Column-level security

Currently, the user OL19GRP has some permission to the file QCUSTCDT.
Using the SQL GRANT command, the user OL19GRP is granted update authority to the credit limit
(CDTLMT) field in the QCUSTCDT file.
On the 5250 command line type: STRSQL and press Enter.
On the SQL command line type: GRANT UPDATE (CDTLMT) ON QCUSTCDT TO OL19GRP.

Note

You must specify library or file must be in library that is in your library list.

© Copyright IBM Corp. 1995, 2017 6-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

*UDQWLQJFROXPQOHYHOSHUPLVVLRQ
‡ 0$1$*(56XSSRVHWKDW2/*53DOUHDG\KDVVSHFLILF 86(DXWKRULW\WR
4&867&'7*UDQW2/*53XSGDWHDXWKRULW\WRCDTLMT
&KHFNWKH8SGDWH ER[RQ
CDTLMT !2/*53URZ

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-34. Granting column-level permission

Column-level security in DB2 universal database (UDB) for IBM i provides an easier and more
flexible way to control access to columns in the database tables. It is a way of using the system
security functions to restrict users from certain columns in a table.
Two authorities are supported:
• Reference is the ability to grant reference authority to certain columns of a table or physical file
such that those columns can be referred as parent keys in a referential constraint. Those
columns that have not been granted reference authority, cannot be referred as parent keys.
• Update is the ability to grant update authority to certain columns of a database file such that
those columns can be updated during database I/O. Those columns that have not been granted
update authority cannot be updated while performing database I/O.
Column-level security support can be defined using the SQL statements GRANT and REVOKE.
There is no native IBM i command to achieve the same function. The CL command DSPOBJAUT is
used to display the column-level authorities defined on a file. Granting column-level authorities to a
user is really giving that user update authority to the table and then restricting the columns that can
be updated in the table.
To be able to update a column, a user must have authority to the columns being updated if column
level authorities exist.

© Copyright IBM Corp. 1995, 2017 6-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

&ROXPQOHYHOVHFXULW\FRQVLGHUDWLRQV
‡ &ROXPQOHYHOVHFXULW\HQIRUFHPHQWSULPDULO\RFFXUVGXULQJWKHXSGDWH
RSHUDWLRQRQWKHILOH
‡ 7KHUHLVQRQHZHQIRUFHPHQWGXULQJRSHQRIWKHILOH
‡ &ROXPQOHYHODXWKRULWLHVDUHVWRUHGLQWKHGDWDEDVHILOHREMHFWDQG
PDQDJHGE\'%8'%
‡ 2EMHFWDXWKRULWLHVDUHVWRUHGLQWKHXVHUSURILOHDQGPDQDJHGE\WKH
V\VWHPVHFXULW\PDQDJHU

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-35. Column-level security considerations

The enforcement of Column-level security is done primarily during the update operation on the file.
The update operation fails when an update is attempted on columns that restrict the update
operation.
There is no new enforcement during open of the file. Implementation gives the user some object
authority when column level authority is granted so normal object level authority processing occurs.
The column level authorities are stored in the database file object, and are managed by DB2 UDB
for IBM i.
Object authorities are stored in the user profile and managed by the system security manager.
Column level authorities still work with all system security components like group profiles and
program-adopted authority.
Column-level authorities cause a small percentage growth in the size of the database file object.
Column-level authorities are no longer needed once a user is given the appropriate object-level
authority. For example, if a user is given update authority to just the first column in a table and later
given an update authority at the table level, the column level authority defined for the first column is
no longer needed, and it is removed. The system eliminates column-level authorities when the user
is granted authority to all of the columns of the table. This is done to avoid an overhead in the
checking of authorities.

© Copyright IBM Corp. 1995, 2017 6-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
Since the column authorities are stored with the file, when you restore the user profile, it will not
restore the column level rights. In a recovery situation, when a file with column level authorities is
restored, there are a couple of options:
• You must grant user authority to one column to have DB2 reactivate all column level authorities
for that user.
• Use RSTAUT CL command as part of the recovery process to have database reactivate column
level authorities.
To be able to grant column-level authorities, the user needs *EXECUTE authority on the library and
*OBJMGT on the table or column, in addition to the data right (Update, Reference) being granted
on the column.

© Copyright IBM Corp. 1995, 2017 6-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.5. Topic 5: Row and Column Access Control
(RCAC)

© Copyright IBM Corp. 1995, 2017 6-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF5RZDQG&ROXPQ
$FFHVV &RQWURO 5&$&

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-36. Topic 5: Row and Column Access Control (RCAC)

© Copyright IBM Corp. 1995, 2017 6-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

:KDWLV5&$&"
‡ $GGLWLRQDOOD\HURIGDWDVHFXULW\ ,%0$GYDQFHG'DWD6HFXULW\IRUL
%RVVRSWLRQ
DYDLODEOHZLWK'% 1R&KDUJH

‡ &RPSOHPHQWDU\WRWDEOH
OHYHOVHFXULW\

‡ 6XEVHWWLQJDFFHVVWRRQO\WKH
UHTXLUHGGDWDIRUDWDVN

‡ &RQWUROVDFFHVVWRDWDEOHDWWKH
URZFROXPQRUERWK

‡ 7ZRVHWVRIUXOHV
ƒ 3HUPLVVLRQVIRUURZV
ƒ 0DVNVIRUFROXPQV

‡ ,%0$GYDQFHG'DWD6HFXULW\IRUL
ƒ 1RFKDUJHIHDWXUH 2SWLRQ
5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-37. What is RCAC?

RCAC (Row and Column Access Control) is an additional layer of security and is complimentary to
table level authorizations already in DB2 for Linux, UNIX, and Windows. RCAC works with
authorizations already in place.
RCAC does have the ability to protect at the table row level, table column level, or both, providing a
masking of result sets to the users based on the protection in place. These are done using rules,
which are created. More further in this presentation.
The image on the slide simply shows at a high, non-specific level, that the SSN column is masked
out (it is in green) and that a number of rows are not returned (in red) based on a row permission
defined.

© Copyright IBM Corp. 1995, 2017 6-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5RZDQG&ROXPQ$FFHVV&RQWUROWHUPV
%DVH7DEOH 7KHWDEOH SK\VLFDOILOH FRQWDLQLQJEXVLQHVVFULWLFDO
GDWD

'HSHQGHQW2EMHFW $Q\REMHFW ILOHVFKHPDIXQFWLRQRURWKHUREMHFW WKH


SHUPLVVLRQRUPDVNUHIHUHQFHV

3HUPLVVLRQ $URZSHUPLVVLRQGHILQHVDURZDFFHVVFRQWUROUXOHIRU
URZVRIDWDEOHE\VHWWLQJDQ64/VHDUFKFRQGLWLRQWKDW
GHVFULEHVWKHVHWRIURZVDXVHUFDQDFFHVV

WRPDQ\ DOORZHGSHUWDEOH
0DVN $FROXPQPDVNGHILQHVDFROXPQDFFHVVFRQWUROUXOH
IRUDVSHFLILFFROXPQLQDWDEOHE\XVLQJ64/&$6(
H[SUHVVLRQWKDWGHVFULEHVZKDWFROXPQYDOXHVDXVHU
LVSHUPLWWHGWRVHHDQGXQGHUZKDWFRQGLWLRQV

RU DOORZHGSHUFROXPQ
58/(7(;7 7KHH[SUHVVLRQWREHXVHGE\WKHSHUPLVVLRQRUPDVN

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-38. Row and Column Access Control terms

RCAC provides a data-centric alternative to achieve data security.


RCAC places access control at the table level around the data itself. SQL rules that are created on
rows and columns are the basis of the implementation of this capability 5770-SS1 IBM Advanced
Data Security for i (Option 47) – Product that needs to be ordered and installed to be able to:
• Create row permissions.
• Create column masks.
• Execute database access over objects that have active RCAC.
RCAC provides access control to a table at the row level, column level, or both. RCAC can be used
to complement the table privileges model. To comply with various government regulations, you
might implement procedures and methods to ensure that information is adequately protected.
Individuals in your organization are permitted access to only the subset of data that is required to
perform their job tasks. For example, government regulations in your area might state that a doctor
is authorized to view the medical records of their own patients, but not of other patients. The same
regulations might also state that, unless a patient gives their consent, a healthcare provider is not
permitted access to patient personal information, such as the patients home phone number. You
can use RCAC to ensure that your users only have access to the data that is required for their work.
For example, RCAC can filter patient information and data to include only that data, which a
particular doctor is authorized to view.

© Copyright IBM Corp. 1995, 2017 6-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5RZDQG&ROXPQ$FFHVV&RQWURO
CREATE MASK SSN_MASK ON EMPLOYEE
FOR COLUMN SSN RETURN
CASE
WHEN (VERIFY_GROUP_FOR_USER(SESSION_USER,'PAYROLL') = 1)
THEN SSN
WHEN (VERIFY_GROUP_FOR_USER(SESSION_USER,'MGR') = 1)
THEN 'XXX-XX-' CONCAT SUBSTR(SSN,8,4)
ELSE NULL
END
ENABLE;
ALTER TABLE EMPLOYEE ACTIVATE COLUMN ACCESS CONTROL;

CREATE PERMISSION PATIENT_TABLE_HMO_PERMISSION


ON HOSPITAL.PATIENT_TABLE
FOR ROWS
WHERE((VERIFY_GROUP_FOR_USER(SESSION_USER,'PCP') = 1 AND
HOSPITAL.PATIENT_TABLE.PCP_ID = SESSION_USER) OR
VERIFY_GROUP_FOR_USER(SESSION_USER,'ACCTGROUP') = 1 OR
VERIFY_GROUP_FOR_USER(SESSION_USER,‘RESGROUP') = 1)
ENFORCED FOR ALL ACCESS
ENABLE;
ALTER TABLE HOSPITAL. PATIENT_TABLE ACTIVATE ROW ACCESS CONTROL;
5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-39. Row and Column Access Control

In the visual there are some examples of mask and permission creation.
IBM Advanced Data Security for i (Boss option 47) - No Charge

© Copyright IBM Corp. 1995, 2017 6-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
6.6. Topic 6: Adopted authority

© Copyright IBM Corp. 1995, 2017 6-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

7RSLF$GRSWHGDXWKRULW\

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-40. Topic 6: Adopted authority

© Copyright IBM Corp. 1995, 2017 6-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\ RI
(YHU\WKLQJ\RXKDYHVKRZQPHGHDOVZLWK
permanent JUDQWVRIDXWKRULW\
,ZRXOGOLNHWRJLYHDXVHUtemporary DFFHVVWR
VHYHUDOREMHFWVZLWKRXWDORWRIJUDQWVDQG
UHYRNHV:KDWFDQ,GR"
<RXQHHGWRXVH
adopted authority

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-41. Adopted authority (1 of 3)

© Copyright IBM Corp. 1995, 2017 6-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\ RI
‡ :KHQDSURJUDPFUHDWHGZLWKUSRPRF(*OWNER)LVUXQREMHFWVDUH
DFFHVVHGZLWKWKHDXWKRULW\RIWKHXVHUUXQQLQJWKHSURJUDPSOXVWKH
SURJUDPRZQHU VDXWKRULW\

‡ $XWKRULW\LVLQHIIHFWDVORQJDVWKHSURJUDPWKDWRULJLQDOO\DGRSWVLVVWLOO
LQWKHVWDFN

‡ 7KLVPHWKRGWHPSRUDULO\JLYHVDXWKRULW\WRREMHFWVWKHXVHUQRUPDOO\
ZRXOGQRWKDYH

‡ %RWKREMHFWDXWKRULWLHVDQGVSHFLDODXWKRULWLHVDUHDGRSWHG

‡ 3URJUDPRZQHU VJURXSVDUHQRWXVHGIRUDGRSWHGDXWKRULW\

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-42. Adopted authority (2 of 3)

© Copyright IBM Corp. 1995, 2017 6-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

'633*0

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-43. DSPPGM

User profile (USRPRF):


Specifies whether the authority checking done while this program is running should include only the
user who is running the program (*USER) or both the user who is running the program and the
program owner (*OWNER). The profiles of the program user or both the program user and the
program owner are used to control which objects can be used by the program, including the
authority the program has for each object. Only the program owner or a user with QSECOFR
authority can change the user profile attribute.
This parameter is ignored if REPLACE (*YES) is specified.
*USER: The program runs under the user profile of the program's user.
*OWNER: The user profiles of both the program owner and the program user are used when the
program is run.
Use adopted authority (USEADPAUT):
Specifies whether program adopted authority from previous programs in the call stack will be used
as a source of authority when this program is running.
*SAME: The use adopted authority attribute does not change.

© Copyright IBM Corp. 1995, 2017 6-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
*YES: Program adopted authority from previous call levels is used when this program is running. If
an authorization list is specified for the QUSEADPAUT system value and the user is not authorized to
that authorization list, *NO is used.
*NO: Program adopted authority from previous call levels is not used when this program is running.
The USEADPAUT value can be changed with the CHGPGM command. It defaults to a value of *YES
when the program is created.
QUSEADPAUT system value:
Defines which users can create programs with the use adopted authority (*USEADPAUT(*YES))
attribute.
QUSEADPAUT defaults to *NONE. All users can create, change, or update programs and service
programs to use adopted authority if the user has the necessary authority to the program or service
program.
QUSEADPAUT can also contain the name of an authorization list. The user's authority is checked
against the authorization list. If the user has at least *USE authority to the named authorization list,
the user can create, change, or update programs or service programs with the USEADPAUT(*NO)
attribute. This authority cannot come from the adopted authority.

© Copyright IBM Corp. 1995, 2017 6-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\ DGRSWLQJDXVHUSURILOH

3*0 3*0
2ZQHU OFCMGR
FILE  FILE1
86535) 2:1(5
OFCMGR CHANGE
86(5 2%-235
PUBLIC  EXCLUDE
(;(&87(

‡ 86(5FDQFDOOPGM1
‡ 86(5KDV &+$1*(DXWKRULW\WRFILE1 ZKLOHUXQQLQJPGM1
‡ *UDQWLQJ 86(DXWKRULW\WRPGM1 LQFOXGHV 2%-235DQG (;(&87(

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-44. Adopted authority (adopting a user profile)

All of the owner's authority is adopted by a user while PGM1 is in the user's program invocation
stack.

Attention

A user should not be allowed to adopt the authority of QSECOFR and be able to get to a command
line unless such is intended.
Adopted authority is added with any specific authority the user already must an object or objects.

© Copyright IBM Corp. 1995, 2017 6-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\H[DPSOH
&DOOVWDFN $XWKRULWLHVGXULQJ
SURJUDPH[HFXWLRQ
3*0
2ZQHUOFCMGR 8VHUSOXVOFCMGR
8VHUSURILOH OWNER

3*0 8VHUSOXVOFCMGR
2ZQHUQSECOFR SOXVQSECOFR
8VHUSURILOH OWNER

3*0
2ZQHUQPGMR 8VHUSOXVOFCMGR
8VHUSURILOH USER SOXVQSECOFR

3*0
2ZQHUOFCMGR 8VHUSOXVOFCMGR
8VHUSURILOH OWNER
8VHDGRSWHG$87 NO

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-45. Adopted authority example

In addition to the above flowchart, consider special authority:


Although it is not part of the above authority checking process, a user can be authorized to perform
a function through a special authority. The special authority could come from the user profile or
adopted profiles.

© Copyright IBM Corp. 1995, 2017 6-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\ RI
6HFXULW\FRQVLGHUDWLRQV
&$//PROG1 CHGLIB
&$//PROG1

0+21(67 $&522.

+21(67 &522.

352*

352* 6(&85(
352* ),/(

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-46. Adopted authority (3 of 3)

Since adopted authority is transferred through a call, a person with bad intentions can use these by
manipulating the library list. If a user can change the sequence of libraries on the library list, or add
additional libraries to the list, the user might be able to perform functions that break security
requirements.
• All special and private authorities are adopted.
• Allowing a program to run under the owner's user profile is an intentional release of control,
which might allow unanticipated access to objects.
• If a program is created again using REPLACE(*YES) from a CRTxxxPGM command, the new
copy of the program uses the value for the USRPRF and USEADPAUT parameters from the
replaced program.
• The adopt function is additive for all programs in the program stack. For example, if a primary
program adopts the owner's authority, any secondary programs that are created with
USRPRF(*USER) still operate under the owner's authority of the primary program.
• A program using adopted authority operates under the owner's authority in addition to the user's
authority. If the user has authority and the program owner is excluded, access is allowed.
• If a program that uses adopted authority submits a job, that submitted job does not have the
adopted authority of the submitting program.

© Copyright IBM Corp. 1995, 2017 6-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty
• If the job is running with program-adopted authority and the owner of the program is a member
of a group profile, the authority of the owner's group profile is not used.
• The adopted authority is not used if one of the following events occur:
▪ System Request key pressed
▪ ATTN key pressed, including TFRGRPJOB
▪ Break message handling program takes control
▪ DEBUG facilities take control of the job

© Copyright IBM Corp. 1995, 2017 6-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\FRQVLGHUDWLRQV RI
‡ $GRSWHGDXWKRULW\LVadded WRWKHXVHU VDXWKRULW\

‡ $GRSWHGSURILOH VVSHFLDODQGSULYDWHDXWKRULWLHVDUHXVHG

‡ $GRSWHGSURILOH VJURXSLVQRWXVHG

‡ 3XEOLFDXWKRULW\WKDWDGRSWHGSURILOHZRXOGKDYHLVQRWXVHG

‡ 3URJUDPLQWHUUXSWLRQVVXVSHQGDGRSWLRQ
ƒ 'HEXJ
ƒ TFRGRPJOB
ƒ 6\VWHPUHTXHVW
ƒ %UHDNPHVVDJHSURJUDP

‡ $XGLWDSPPGMADP, DSPPGM, DSPSRVPGM

‡ 3URJUDPVDOZD\VFUHDWHGZLWKUSEADPAUT(*YES)
5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-47. Adopted authority considerations (1 of 2)

© Copyright IBM Corp. 1995, 2017 6-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$GRSWHGDXWKRULW\FRQVLGHUDWLRQV RI
‡ 7KLVSURYLGHVDZD\WRWHPSRUDULO\JUDQWDXVHUDXWKRULW\

‡ 6KRXOGSHUIRUPRQO\WKHIXQFWLRQWKHXVHUGRHVQRWKDYHDXWKRULW\WRGR
DQGUHWXUQ

‡ 3URSDJDWLQJDXWKRULW\GRZQWKHFDOOVWDFNLVGDQJHURXVHVSHFLDOO\ZKHQ
DGRSWLQJDSRZHUIXOSURILOHVXFKDV46(&2)5

‡ <RXVKRXOGOLEUDU\TXDOLI\FDOOVPDGHWRSURJUDPVWKDWDGRSW

‡ <RXVKRXOGVHFXUHSURJUDPVWKDWDGRSW

‡ 7KLVSURYLGHVWKHDELOLW\WRUHVWULFWGLUHFWREMHFWDFFHVVEXWDOORZDFFHVV
WKURXJKDSSOLFDWLRQV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-48. Adopted authority considerations (2 of 2)

© Copyright IBM Corp. 1995, 2017 6-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRULW\FKHFNLQJ RI
6XIILFLHQW
)DVWSDWKIRUREMHFWDXWKRULW\
$XWKRUL]HG
,QVXIILFLHQW
8VHU¶VDXWKRULW\ ([LWWKLVER[LPPHGLDWHO\ZKHQany
DXWKRULW\LVIRXQG
,QVXIILFLHQW $//2%-" 6XIILFLHQW
,VRZQHUDQGKDVVRPHDXWKRULW\"
)DVWSDWKIRUXVHUDXWKRULW\" $XWKRUL]HG
3ULYDWHDXWKRULW\"
$XWKRUL]DWLRQOLVW"
1RDXWKRULW\IRXQG
*URXS¶VDXWKRULW\ ([LWWKLVER[LPPHGLDWHO\IRUthis JURXS
ZKHQDQ\DXWKRULW\LVIRXQG
,QVXIILFLHQW 6XIILFLHQW
$//2%-"
,VRZQHUDQGKDVVRPHDXWKRULW\"$'',7,9( $XWKRUL]HG
3ULPDU\JURXS LIJURXSLVSULPDU\JURXS $XWKRULW\"$'',7,9(
3ULYDWHDXWKRULW\" $'',7,9(
$XWKRUL]DWLRQOLVW" $'',7,9(

5HSHDWDERYHLIPRUHJURXSV
1RDXWKRULW\IRXQG
3XEOLFDXWKRULW\ 6XIILFLHQW
,I 38%/,& $87/JHWSXEOLFIURPDXWKRUL]DWLRQOLVW
$XWKRUL]HG
2WKHUZLVHXVHSXEOLFDXWKRULW\VWRUHGZLWKREMHFW
,QVXIILFLHQW
$GRSW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-49. Authority checking (1 of 2)

When a user attempts to perform an operation on an object, the system verifies that the user has
adequate authority for the operation. The system first checks authority to the library or directory
path that contains the object. If the authority to the library or directory path is adequate, the system
checks authority to the object itself. In the case of database files, authority checking is done at the
time the file is opened, not when each individual operation to the file is performed.
During the authority-checking process, when any authority is found (even if it is not adequate for
the requested operation), authority checking stops, and access is granted or denied. The adopted
authority function is the exception to this rule. Adopted authority can override any specific (and
inadequate) authority found.

© Copyright IBM Corp. 1995, 2017 6-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

$XWKRULW\FKHFNLQJ RI
$GRSW

1R
'RHVSURJUDPDGRSW"

<HV
3URJUDP2:1(5 6$87+25,7<([LW
WKLVER[LPPHGLDWHO\ZKHQany DXWKRULW\LVIRXQG
$//2%-" 6XIILFLHQW
$XWKRUL]HG
,VRZQHUDQGKDVVRPHDXWKRULW\"$'',7,9(
,QVXIILFLHQW
<HV &XUUHQWSURJUDPUSEADPAUT(*YES)
0RUHSURJUDPVLQVWDFN"1H[WSURJUDP
1R
1R
'RHVSURJUDPDGRSW"
<HV
3URJUDP2:1(5 6$87+25,7<([LWWKLV
ER[LPPHGLDWHO\ZKHQany DXWKRULW\LVIRXQG
3ULYDWHDQGSULPDU\JURXSDXWKRULW\"$'',7,9( 6XIILFLHQW
$XWKRUL]HG
$XWKRUL]DWLRQOLVW"$'',7,9(
,QVXIILFLHQW

&XUUHQWSURJUDPUSEADPAUT(*YES)
<HV
0RUHSURJUDPVLQVWDFN"1H[WSURJUDP
1R
$FFHVVGHQLHG

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-50. Authority checking (2 of 2)

Adopted authority could override specific, inadequate authority, if used.

© Copyright IBM Corp. 1995, 2017 6-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

)DVWSDWKIRUREMHFWDXWKRULW\
‡ 8VLQJLQIRUPDWLRQVWRUHGZLWKWKHREMHFWDXWKRUL]HDFFHVVLIDOORIWKH
IROORZLQJDUHWUXH
ƒ 1RSULYDWHDXWKRULWLHV
ƒ 1RWVHFXUHGE\DQDXWKRUL]DWLRQOLVW
ƒ 2ZQHUDXWKRULW\VXIILFLHQW
ƒ 3ULPDU\JURXS LIRQHH[LVWV DXWKRULW\VXIILFLHQW
ƒ 3XEOLFDXWKRULW\VXIILFLHQW
‡ 2WKHUZLVHUHWXUQWRFDOOLQJIORZFKDUWZLWK,QVXIILFLHQW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-51. Fast path for object authority

© Copyright IBM Corp. 1995, 2017 6-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6HFXULW\H[DPSOH RI
'(37 *AUTL/,67$
2ZQHGREMHFWV;=3*0 $11 ALL
; ALL &$7+< EXCLUDE
= ALL '(37 USE
3*0 ALL PUBLIC USE

&$7+< '$9,' $11 %,//


; USE = USE ; ALL
*URXS'(37 *URXS'(37

3*0 3*0 3*0


1HHGV CHANGE WR; 1HHGV CHANGE WR< 1HHGV CHANGE WR=
USRPRF USER USRPRF USER USRPRF USER
PUBLIC USE PUBLIC USE PUBLIC USE
2ZQHU'(37

)LOH; )LOH< )LOH=


*PUBLIC USE $XWK/LVW/,67$ PUBLIC CHANGE
2ZQHU'(37 PUBLIC AUTL 2ZQHU'(37

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-52. Security example (1 of 3)

This class exercise depicts a security example with several users, group profiles, objects, and
authorization lists. You are to answer questions about users and their access to programs and
objects and how the system would allow or not allow users to access objects.

© Copyright IBM Corp. 1995, 2017 6-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6HFXULW\H[DPSOH RI
D ,VWKHXVHUDXWKRUL]HGWRUXQWKHSURJUDPDQGDFFHVVWKHILOHZLWKRXWD
VHFXULW\PHVVDJH"
E :KDWDXWKRULW\GLGWKHXVHUJHWIRUILOHV;<DQG="
F )URPZKHUHGLGWKHXVHUJHWKLVKHUDXWKRULW\"
G +RZZRXOGWKHIROORZLQJFKDQJHWKHWDEOH
ƒ CHGPGM PGM(PGM3) USRPRF(*OWNER)

G3*0=
3*0 ; 3*0 < 3*0 =
USRPRF(*OWNER)

D BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB


$QQ E BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB
F BBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBB

D BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB


%LOO E BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB
F BBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBB

D BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB


&DWK\ E BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB
F BBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBB

D BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB


'DYLG E BBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBBBB
F BBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBBB BBBBBBBBBBBBBBB

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-53. Security example (2 of 3)

These are questions for the class exercise:


A) Is the user authorized to run the program and access the file without a security message?
B) What authority did the user get for Files X, Y and Z?
C) From where did the user get their authority?
D) If PGM3 is changed to use adopted authority, how would authority be affected?

© Copyright IBM Corp. 1995, 2017 6-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

6HFXULW\H[DPSOH RI
D ,VWKHXVHUDXWKRUL]HGWRUXQWKHSURJUDPZLWKRXWDVHFXULW\PHVVDJH"
E :KDWDXWKRULW\GLGWKHXVHUJHWIRUILOHV;<DQG="
F )URPZKHUHGLGWKHXVHUJHWKLVKHUDXWKRULW\"
G +RZZRXOGWKHIROORZLQJFKDQJHWKHWDEOH
ƒ CHGPGM PGM(PGM3) USRPRF(*OWNER)

G3*0=
3*0 ; 3*0 < 3*0 =
USRPRF(*OWNER)

D <HV <HV <HV


$QQ E ALL ALL CHANGE 6DPH
F 8VHU3ULYDWH 8VHU AUTL PUBLIC2EMHFW

D 1R 1R <HV
%LOO E USE USE CHANGE 6DPH
F PUBLIC2EMHFW PUBLIC-*AUTL PUBLIC2EMHFW

D 1R 1R <HV
&DWK\ E USE EXCLUDE ALL 6DPH
F 8VHU3ULYDWH 8VHU AUTL *URXS6SHFLILF

D <HV 1R 1R <HV
'DYLG E ALL USE USE ALL
F *URXS6SHFLILF *URXS AUTL 8VHU3ULYDWH $GRSWHG'(37

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-54. Security example (3 of 3)

Here are the answers to the questions in the class exercise.


Ann PGM1 - X A) Yes, B) *ALL, C) User-Private
Ann PGM2 - Y A) Yes, B) *ALL, C) User- Autl
Ann PGM3 - Z A) Yes, B) *CHANGE, C) Public - Object, D) Same
Bill PGM1 - X A) No, B) *USE, C) Public-Object
Bill PGM2 - Y A) No, B) *USE, C) Public-Autl
Bill PGM3 - Z A) Yes, B) *CHANGE, C) Public-Object, D) Same
Cathy PGM1 - X A) No, B) *USE, C) User-Private
Cathy PGM2 - Y A) No, B) *Exclude, C) User- Autl
Cathy PGM3 - Z A) Yes, B) *ALL, C) Group-Specific, D) Same
David PGM1 - X A) Yes, B) *ALL, C) Group-Specific
David PGM2 - Y A) No, B) *USE, C) Group-Autl
David PGM3 - Z A) No, B) *USE, C) User-Private, D) *Yes, *ALL, Adopted DEPT03

© Copyright IBM Corp. 1995, 2017 6-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

([HUFLVH:RUNLQJZLWKREMHFWDXWKRULW\DQGDGRSWHG
DXWKRULW\
‡ $VVLJQSHUPLVVLRQWRREMHFWV
‡ $VVLJQDXWKRULW\WRDSURILOHE\UHIHUHQFLQJDQRWKHUSURILOH
‡ 3HUIRUPWKHQHFHVVDU\VWHSVWRGHOHWHDXVHUSURILOH

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-55. Exercise: Working with object authority and adopted authority

© Copyright IBM Corp. 1995, 2017 6-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH$QREMHFWFDQEHRZQHGE\PXOWLSOHXVHUVRQ
WKHV\VWHP
 7UXHRUIDOVH7KHQDPHRIWKHSULPDU\JURXSDQGLWV
DXWKRULW\WRWKHREMHFWDUHVWRUHGLQWKHREMHFWKHDGHU
 :KHQDQREMHFWGRHVQRWKDYHDQRZQHUVSHFLILHGLWJHWV
DVVLJQHGWRWKH EODQN XVHUSURILOH
D 86(5
E 6(&2)5
F 6<6235
G 4')72:1

 7UXHRUIDOVH7KH4&57$87 V\VWHPYDOXHLVXVHGWR
GHWHUPLQHWKHSXEOLFDXWKRULW\IRUDQHZO\FUHDWHGREMHFW
 7UXHRUIDOVH5HDGDGGDQGXSGDWHDUHDXWKRULWLHVWKDWFDQ
EHVSHFLILHGWRWKHREMHFWPDQDJHPHQWDXWKRULW\IRUD
VSHFLILFREMHFW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-56. Review questions (1 of 3)

© Copyright IBM Corp. 1995, 2017 6-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH$QREMHFWFDQEHRZQHGE\PXOWLSOHXVHUVRQWKHV\VWHP
7KHDQVZHULVIDOVH

 7UXH RUIDOVH7KHQDPHRIWKHSULPDU\JURXSDQGLWVDXWKRULW\WRWKH
REMHFWDUHVWRUHGLQWKHREMHFWKHDGHU
7KHDQVZHULVWUXH

 :KHQDQREMHFWGRHVQRWKDYHDQRZQHUVSHFLILHGLWJHWVDVVLJQHGWR
WKH4')72:1 XVHUSURILOH
D 86(5
E 6(&2)5
F 6<6235
G 4')72:1
7KHDQVZHULV4')72:1

 7UXH RUIDOVH7KH4&57$87V\VWHPYDOXHLVXVHGWRGHWHUPLQHWKH
SXEOLFDXWKRULW\IRUDQHZO\FUHDWHGREMHFW
7KHDQVZHULVWUXH

 7UXHRUIDOVH5HDGDGGDQGXSGDWHDUHDXWKRULWLHVWKDWFDQEH
VSHFLILHGWRWKHREMHFWPDQDJHPHQWDXWKRULW\IRUDVSHFLILFREMHFW
7KHDQVZHULVIDOVH
5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-57. Review answers (1 of 3)

© Copyright IBM Corp. 1995, 2017 6-68


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH2%-2352%-0*7DQG2%-(;,67DUH
DXWKRULWLHVWKDWFDQEHVSHFLILHGWRWKHGDWDDXWKRULW\IRUD
VSHFLILFREMHFW

 7KHYHU\ILUVWWKLQJWKDWDV\VWHPFKHFNVZKHQGHWHUPLQLQJLI
DXVHULVDOORZHGWRDFFHVVDQREMHFWLV
D *URXSDXWKRULW\
E $XWKRUL]DWLRQOLVW
F 3ULYDWHDXWKRULWLHV
G $OOREMHFWDFFHVV

 7KHPD[LPXPQXPEHURIDXWKRUL]DWLRQOLVWVWKDWDXVHUFDQ
EHVSHFLILHGLQLV
D 
E 
F 
G 1RPD[LPXP

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-58. Review questions (2 of 3)

© Copyright IBM Corp. 1995, 2017 6-69


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH2%-2352%-0*7DQG2%-(;,67DUHDXWKRULWLHVWKDW
FDQEHVSHFLILHGWRWKHGDWDDXWKRULW\IRUDVSHFLILFREMHFW
7KHDQVZHULVIDOVH

 7KHYHU\ILUVWWKLQJWKDWDV\VWHPFKHFNVZKHQGHWHUPLQLQJLIDXVHULV
DOORZHGWRDFFHVVDQREMHFWLV
D*URXSDXWKRULW\
E$XWKRUL]DWLRQOLVW
F3ULYDWHDXWKRULWLHV
G$OOREMHFWDFFHVV
7KHDQVZHULVDOOREMHFWDFFHVV

 7KHPD[LPXPQXPEHURIDXWKRUL]DWLRQOLVWVWKDWDXVHUFDQEH
VSHFLILHGLQLV
D
E
F
G1RPD[LPXP
7KHDQVZHULVQRPD[LPXP

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-59. Review answers (2 of 3)

© Copyright IBM Corp. 1995, 2017 6-70


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZTXHVWLRQV RI
 %ODQN DXWKRULW\LVDQDXWKRULW\WKDWFDQEHDVVLJQHGWRDQ
REMHFWWHPSRUDULO\
D 8VHU
E 2EMHFW
F 5HVRXUFH
G $GRSWHG

 7UXHRUIDOVH$SSOLFDWLRQVWKDWXWLOL]HFDOOVWRSURJUDPVWKDW
DGRSWDXWKRULW\VKRXOGOLEUDU\TXDOLI\WKRVHFDOOV

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-60. Review questions (3 of 3)

© Copyright IBM Corp. 1995, 2017 6-71


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

5HYLHZDQVZHUV RI
 $GRSWHG DXWKRULW\LVDQDXWKRULW\WKDWFDQEHDVVLJQHGWRDQ
REMHFWWHPSRUDULO\
D 8VHU
E 2EMHFW
F 5HVRXUFH
G $GRSWHG
7KHDQVZHULVDGRSWHG

 7UXH RUIDOVH$SSOLFDWLRQVWKDWXWLOL]HFDOOVWRSURJUDPVWKDW


DGRSWDXWKRULW\VKRXOGOLEUDU\TXDOLI\WKRVHFDOOV
7KHDQVZHULVWUXH

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-61. Review answers (3 of 3)

© Copyright IBM Corp. 1995, 2017 6-72


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 6. Resource security

Uempty

8QLWVXPPDU\
‡ 'HVFULEHZKDWUHVRXUFHVHFXULW\LVDQGKRZLWLVLPSOHPHQWHG
‡ ([SODLQKRZRZQHUVKLSRIDQREMHFWLVHVWDEOLVKHG
‡ ([SODLQWKHSXUSRVHVHUYHGE\WKH4')72:1 XVHUSURILOH
‡ ([SODLQKRZSXEOLFDXWKRULW\LVDVVLJQHGWRDQREMHFW
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQREMHFWPDQDJHPHQWDQGGDWDDXWKRULW\
WKDWFDQEHDVVLJQHGWRDQREMHFW
‡ ([SODLQWKHSXUSRVHVHUYHGE\DQDXWKRUL]DWLRQOLVW
‡ /LVWWKHVWHSVWRVHFXUHDQREMHFWZLWKDQDXWKRUL]DWLRQOLVW
‡ 'HVFULEHWKHVHDUFKRUGHUXVHGE\WKHV\VWHPWRGHWHUPLQHLIDXVHULV
DOORZHGWRDFFHVVDQREMHFW

5HVRXUFHVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 6-62. Unit summary

© Copyright IBM Corp. 1995, 2017 6-73


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

Unit 7. Security auditing


Estimated time
00:30

Overview
Auditing system activity is an important part of system security. Security auditing can help detect
system misuse and intrusions. You can use specific systems values to control auditing on the i5/OS
operating system.
In this unit, we will describe the different types of security auditing and the steps specifically
required to implement security auditing on your system.

How you will check your progress


• Review questions

References
SG24-5302-10 System i Security Reference
IBM Publications Center
[Link]
US

© Copyright IBM Corp. 1995, 2017 7-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

8QLWREMHFWLYHV
‡ /LVWDQGGLVFXVVWKHW\SHVRIVHFXULW\UHODWHGDFWLYLWLHVWKDW\RXFDQ
PRQLWRURQ\RXUV\VWHP
‡ /LVWWKHGLIIHUHQWOHYHOVRIVHFXULW\DXGLWLQJWKDW\RXFDQLPSOHPHQW
‡ ([SODLQZK\LPSOHPHQWLQJDXGLWLQJLVDQRQJRLQJSURFHVV
‡ /LVWDQGFRQILJXUHWKHFRPPDQGVDQGV\VWHPYDOXHVXVHGWRLPSOHPHQW
VHFXULW\DXGLWLQJ
‡ ([SODLQWKHVWHSVUHTXLUHGWRLPSOHPHQWWKHGLIIHUHQWW\SHVRIVHFXULW\
DXGLWLQJ

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 7-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLW:K\DQGKRZ"
‡ :K\"
ƒ .HHSV\VWHPDWSODQQHGVHFXULW\OHYHO
‡ +RZ"
ƒ ,PSOHPHQWDWDQ\VHFXULW\OHYHORU
ƒ 8VHV\VWHPIXQFWLRQV
í DSPUSRPRF
í DSPOBJAUT
í DSPPGMADP

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-2. Audit: Why and how?

People audit their system security for several reasons:


• To evaluate whether the security plan is complete
• To make sure that the planned security controls are in place and working
• To make sure that system security is keeping pace with changes to the system environment
• To prepare for a future event, such as installing a new application, moving to a higher security
level, or setting up a communications network

© Copyright IBM Corp. 1995, 2017 7-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWLQJ6RPHHYHQWVWRPRQLWRU
‡ 6DYHUHVWRUHLQIRUPDWLRQ

‡ $XWKRUL]DWLRQIDLOXUHV

‡ 5HIHUHQFHVWRREMHFWVWKURXJKLQWHUIDFHVQRWVXSSRUWHG

‡ 'HOHWHGREMHFWV

‡ 6HFXULW\UHODWHGIXQFWLRQV

‡ $FWLRQDXGLWLQJLQIRUPDWLRQ

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-3. Auditing: Some events to monitor

All events can be journaled, or you can select the ones you want.
Your journal receiver should not be deleted from the system until the information is saved to tape
media.

© Copyright IBM Corp. 1995, 2017 7-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

/HYHOVRIDXGLWLQJ
‡ 7KHOHYHOVRIDXGLWLQJWKDWFDQEHLPSOHPHQWHGLQFOXGH

ƒ 6\VWHPZLGHDXGLWLQJ

ƒ $XGLWLQJE\VSHFLILFXVHU

ƒ $XGLWLQJE\VSHFLILFREMHFW

ƒ $XGLWLQJE\QHWZRUNLQWUXVLRQ

ƒ &RPELQDWLRQRIWKHDERYH

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-4. Levels of auditing

The security audit journal is the primary source of auditing information on the events that occur on
the system.
Intrusion detection was added as an auditable event. Intrusion detection involves gathering
information about unauthorized access, attempts, and attacks coming in over the TCP/IP network.
Security administrators can analyze the auditing records that intrusion detection provides in order
to secure the IBM i network from these types of attacks.

© Copyright IBM Corp. 1995, 2017 7-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

([DPLQH\RXUVWUDWHJ\
‡ 6HFXULW\VWUDWHJLHVWHQGWREHFRPHOHVVHIIHFWLYHRYHUWLPH6RPHRIWKH
WKLQJVWKDWFDQFKDQJHDUH
ƒ 2SHUDWLQJV\VWHPXSGDWHV
ƒ 1HZSURGXFWV
ƒ 3URFHGXUDOFKDQJHV
ƒ 1HZXVHUSURILOHV
ƒ &KDQJLQJUROHV
ƒ 7HUPLQDWLRQVDQGUHVLJQDWLRQV
ƒ 1HZDQGFKDQJHGREMHFWV
ƒ 'HOHWHGREMHFWV
ƒ &KDQJHVWRV\VWHPYDOXHVDQGQHWZRUNDWWULEXWHV

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-5. Examine your strategy

© Copyright IBM Corp. 1995, 2017 7-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$QHIIHFWLYHVWUDWHJ\
‡ 8VHGWRGHILQHVHFXULW\UHTXLUHPHQWV

‡ (QGRUVHGE\PDQDJHPHQW

‡ &RPPXQLFDWHGWRHPSOR\HHV

‡ (QIRUFHDEOH

‡ 3HULRGLFDOO\UHH[DPLQHG

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-6. An effective strategy

© Copyright IBM Corp. 1995, 2017 7-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

(YHQWPRQLWRULQJ
‡ 7RROVXVHGWRPRQLWRUHYHQWV
ƒ +LVWRU\ORJ QHST
ƒ 6HFXULW\DXGLWMRXUQDO
ƒ &ULWLFDOGDWDEDVHILOHV-RXUQDO

‡ (YHQWV\RXPLJKWZDQWWRPRQLWRULQFOXGH
ƒ ,QYDOLGVLJQRQDWWHPSWV
ƒ $XWKRULW\IDLOXUHV
ƒ $FFHVVRIRUFKDQJHVWRFULWLFDOILOHV

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-7. Event monitoring

© Copyright IBM Corp. 1995, 2017 7-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

8VLQJWKHKLVWRU\ORJ
‡ 7KHKLVWRU\ORJLVXVHGWRPRQLWRUIRU
ƒ 6WDUWDQGFRPSOHWLRQRIMREV
ƒ 'HYLFHVWDWXVPHVVDJHV
ƒ 6\VWHPRSHUDWRUPHVVDJHVDQGUHVSRQVHV
ƒ )DLOHGVLJQRQDWWHPSWV

‡ 7RGLVSOD\WKHFRQWHQWV
ƒ DSPLOG LOG(QHST)

‡ 7RGLVSOD\DVSHFLILFPHVVDJHUDQJH
ƒ DSPLOG LOG(QHST) MSGID(CPF2200)

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-8. Using the history log

Security messages are in the range 2200 to 22FF. They have prefixes CPI, CDF, CPD, and CPA.
However, logging information to the audit journal provides better system performance and more
complete information about these security-related events than the QHST log. The QHST log should
not be considered a complete source of securing violations. Use the security audit functions
instead.

© Copyright IBM Corp. 1995, 2017 7-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

6WHSVWRLPSOHPHQWDXGLWLQJ
CRTJRNRCV JRNRCV(SECRCV1) LIB(USRLIB)

CRTJRN JRN(QSYS/QAUDJRN) JRNRCV(SECRCV1)

CHGSYSVAL SYSVAL(QAUDLVL QAUDLVL2)


VALUE(*NONE)
RURQHRUVRPHRIWKHYDOXHVRQWKHQH[WSDJH

CHGSYSVAL SYSVAL(QAUDCTL)
VALUE(*NONE) (*OBJAUD *AUDLVL *NOQTEMP)

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-9. Steps to implement auditing

The journal QAUDJRN must exist in library QSYS in order to change this system value to a value
other than *NONE. The journal QAUDJRN cannot be deleted or moved from the QSYS library until
the system value is changed to *NONE.
• QAUDLVL: Security auditing level controls the level of auditing on the system. The system
audits functions that can affect security. QAUDLVL default value is *NONE. Choose the values
you want to journal. These values apply to all users of the system.
The QAUDLVL2 system value also specifies which actions are audited for all users of the
system and is used when more than 16 auditing values are needed. The AUDLVL parameter in
the user profile determines which actions are audited for a specific user. The values for the
AUDLVL parameter apply in addition to the values for the QAUDLVL and QAUDLVL2 system
values.
• QAUDCTL: Audit control. This system value contains the on and off switches for object and
user level auditing. This system value activates auditing on the system that is selected by the
Change Object Audit (CHGOBJAUD) and Change User Audit (CHGUSRAUD) commands and the
QAUDLVL system value.
A change to this system value takes effect immediately. The shipped value is *NONE. To turn
on auditing, specify either *OBJAUD or *AUDLVL. If auditing is active, specify *NONE to turn
auditing off.

© Copyright IBM Corp. 1995, 2017 7-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty
• One or more of the following values can be specified. If you specify *NONE, that must be the
only specified value:
▪ *NONE: No auditing of objects (Change Object Audit (CHGOBJAUD) command) or of user
actions (Change User Audit (CHGUSRAUD) command, AUDLVL keyword) is done on the
system. In addition, no auditing controlled by the QAUDLVL system value is done.
▪ *NOQTEMP: No auditing of most objects in QTEMP is done. You must specify *NOQTEMP
with either *OBJAUD or *AUDLVL. You cannot specify *NOQTEMP by itself.
▪ *OBJAUD: Auditing is performed for objects that were selected using the CHGOBJAUD,
CHGDLOAUD, or CHGAUD commands.
▪ *AUDLVL: Auditing is performed for any functions selected on the QAUDLVL system value
and on the AUDLVL parameter of individual user profiles. The audit level for a user is
specified using the Change User Audit (CHGUSRAUD) command.

© Copyright IBM Corp. 1995, 2017 7-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

9DOXHVIRUWKH4$8'/9/DQG4$8'/9/
*NONE *NETFAIL *SECCFG
*NOTAVL *NETSCK *SECDIRSRV
*AUDLVL2 *NETSECURE *SECIPC
*ATNEVT *NETTELSVR *SECNAS
*AUTFAIL *NETUDP *SECRUN
*CREATE *OBJMGT *SECSCKD
*DELETE *OFCSRV *SECURITY
*JOBBAS *OPTICAL *SECVFY
*JOBCHGUSR *PGMADP *SECVLDL
*JOBDTA *PGMFAIL *SERVICE
*NETBAS *PRTDTA *SPLFDTA
*NETCLU *PTFOBJ *SYSMGT
*NETCMN *PTFOPR
6HFXULW\DXGLWLQJ *SAVRST ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-10. Values for the QAUDLVL and QAUDLVL2

*NONE: No events controlled by the QAUDLVL or QAUDLVL2 system values are logged. Events are
logged for individual users based on the AUDLVL values of user profiles.
*NOTAVL: This value is displayed to indicate that the system value is not available to the user
because the user does not have either *AUDIT or *ALLOBJ special authority. The system value
cannot be set to this value.
*AUDLVL2: Both QAUDLVL and QAUDLVL2 system values are used to determine the security
actions to be audited.
*ATNEVT: Attention events are logged.
*AUTFAIL: Authority failure events are logged.
*CREATE: Object create operations are logged.
*DELETE: Object delete operations are logged.
*JOBBAS: Job base functions are audited.
*JOBCHGUSR: Changes to a thread's active user profile or its group profiles are audited.
*JOBDTA: Actions that affect a job are logged. *JOBDTA is composed of two values, *JOBBAS and
*JOBCHGUSR, which enables you to better customize your auditing. If both of the values are
specified, you get the same auditing as if just *JOBDTA is specified.

© Copyright IBM Corp. 1995, 2017 7-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty
*NETBAS: Network base functions are audited.
*NETCLU: Cluster and cluster resource group operations are audited.
*NETCMN: Network and communication functions are audited.
*NETFAIL: Network failures are audited.
*NETSCK: Socket tasks are audited.
*NETSECURE: Secure network connections are audited.
*NETTELSVR: Telnet Server connections are audited.
*NETUDP: User Datagram Protocol (UDP) traffic is audited.
*OBJMGT: Object move and rename operations are logged.
*OFCSRV: Changes to the system distribution directory and office mail actions are logged.
*OPTICAL: Use of Optical Volumes is logged.
*PGMADP: Obtaining authority from a program that adopts authority is logged.
*PGMFAIL: System integrity violations are logged.
*PRTDTA: Printing a spooled file, sending output directly to a printer, and sending output to a
remote printer are logged.
*PTFOBJ: Changes to PTF objects are logged.
*PTFOPR: PTF operations are logged.
*SAVRST: Save and restore operations are logged.
*SECCFG: Security configuration is audited.
*SECDIRSRV: Changes or updates when doing directory service functions are audited.
*SECIPC: Changes to interprocess communications are audited.
*SECNAS: Network authentication service actions are audited.
*SECRUN: Security runtime functions are audited.
*SECSCKD: Socket descriptors are audited.
*SECURITY: Security-related functions are logged. *SECURITY is composed of several values to
enable you to better customize your auditing.
*SECVFY: Use of verification functions are audited.
*SECVLDL: Changes to validation list objects are audited.
*SERVICE: Using service tools is logged.
*SPLFDTA: Actions performed on spooled files are logged.
*SYSMGT: Use of systems management functions is logged.

© Copyright IBM Corp. 1995, 2017 7-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWLQJVHWXS RI

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-11. Auditing setup (1 of 3)

IBM Navigator for i also allows you to view or change the auditing policy for the system.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand Configuration and Service.
3. Click System Values.
4. On the main pane right-click the Auditing and choose Properties.

© Copyright IBM Corp. 1995, 2017 7-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWLQJVHWXS RI

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-12. Auditing setup (2 of 3)

Use the System page to specify system level auditing activation controls. There are two basic types
of auditing that can be used in combination with each other:
• Auditing of specific actions (action auditing)
• Auditing of access to specific resources (object auditing)

© Copyright IBM Corp. 1995, 2017 7-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWLQJVHWXS RI

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-13. Auditing setup (3 of 3)

Use the Journaling page to specify the action to take if the system is unable to write audit entries.
Audit journal error action
Specifies the action to take in the event that the system is not able to write audit entries and
auditing is active. If the security policy for your system requires that no processing occur without
auditing, then you must set this value to Shut down the system. For most systems, Notify, then
continue is the recommended value. This system value only applies to auditing entries sent by the
operating system to the security audit journal (QAUDJRN).
Possible values are:
Notify, then continue
• A message is sent to the system operator's message queue once per hour until auditing is
successfully activated.
Shut down the system
• The system ends if the attempt to send the audit data to the security audit journal fails. When
the system is powered on again, the system is in the restricted state. The Default auditing for
newly created objects system value is set to None to turn auditing off. On the next restart, the

© Copyright IBM Corp. 1995, 2017 7-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty
user who signs on the system must have at least Audit (*AUDIT) and All Object (*ALLOBJ)
special authority.
Maximum journal entries before writing to auxiliary storage
Specifies the number of journal entries written to the security auditing journal before the journal
entry data moves to auxiliary storage. This system value also indicates the amount of auditing data
that could be lost if the system ends abnormally. If auditing entries are moved to auxiliary storage
frequently, system performance can decrease.
Possible values are:
System determines maximum entries
• The system writes the journal entries to auxiliary storage only when the system, based on
internal processing, determines the journal entries should be written. Using this option provides
the best auditing performance, but it could also cause the most auditing data loss if the system
ends abnormally.
Maximum entries (1-100)
• The number of auditing journal entries written to the security auditing journal before the auditing
data is written to auxiliary storage. Possible values are 1 - 100. Small values decrease the
system performance. If your system requires that no entries can be lost after the operating
system ends abnormally, specify 1.
Use the New Objects page to specify the default auditing value for newly created objects. The value
you select depends upon your auditing requirements.
Default auditing for newly created objects
Specifies the default object auditing value of newly created objects. The object auditing value of an
object determines whether an auditing entry is sent to the system auditing journal in the QSYS
library when the object is used or changed. The auditing entry is sent to the auditing journal only if
auditing is currently active on the system. To start auditing, select Activate action auditing on the
System page.
Possible values are:
None
• No auditing entries are sent for the object when it is used or changed.
User settings
• Auditing entries are sent for the object when it is used or changed by a user who is currently
being audited. If the user who uses or changes this object is not being audited, no auditing
entries are sent.
Changes to objects
• Auditing entries are sent for the object when it is changed.
All access of objects
• Auditing entries are sent for the object when it is used or changed.

© Copyright IBM Corp. 1995, 2017 7-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWMRXUQDOHQWULHV
-RXUQDO (QWU\
2SHUDWLRQGHVFULSWLRQ
FRGH W\SH
7 $) $OODXWKRULW\IDLOXUHV
7 &$ &KDQJHVWRREMHFWDXWKRULW\ DXWKRUL]DWLRQOLVWRUREMHFW
7 &3 &UHDWHFKDQJHGHOHWHGLVSOD\UHVWRUHRIXVHUSURILOHV
7 '2 $OOGHOHWHRSHUDWLRQVRQWKHV\VWHP
7 '6 '67VHFXULW\RIILFHUSDVVZRUGUHVHW
7 -' &KDQJHVWRWKHUSER SDUDPHWHURIDMREGHVFULSWLRQ
7 1$ &KDQJHVWRQHWZRUNDWWULEXWHV
7 2: &KDQJHVWRREMHFWRZQHUVKLS
&KDQJHVWRSURJUDPV CHGPGM WKDWZLOOQRZDGRSWWKHRZQHU V
7 3$
DXWKRULW\
7 3: 3DVVZRUGVXVHGWKDWDUHQRWYDOLG
7 5$ 5HVWRUHRIREMHFWVZKHQDXWKRULW\FKDQJHV
7 5- 5HVWRUHRIMREGHVFULSWLRQVWKDWFRQWDLQXVHUSURILOHQDPHV
7 52 5HVWRUHRIREMHFWVZKHQRZQHUVKLSLQIRUPDWLRQFKDQJHV
7 53 5HVWRUHRISURJUDPVWKDWDGRSWWKHLURZQHU VDXWKRULW\
7 58 5HVWRUHRIDXWKRULW\IRUXVHUSURILOHV
7 6( &KDQJHVWRVXEV\VWHPURXWLQJ
7 69 &KDQJHVWRV\VWHPYDOXH
8 8VHUVSHFLILHGXVHUFUHDWHGHQWU\
6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-14. Audit journal entries

System-detected entries are written automatically to the receiver.


User entries are written by issuing the SNDJRNE command.
For a complete list of all of the Audit journal (QAUDJRN) entry types, refer to the IBM i 7.3 Security
- Security Reference manual (SC41-5302-13, Appendix F, Table 161) in the IBM Knowledge
Center. Appendix F details all of the journal entry types and formats.
You can download this publication from the following website:
[Link]
or using the Security tab at the IBM Knowledge Center website:
[Link]

© Copyright IBM Corp. 1995, 2017 7-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$XGLWUHODWHGILOHVDQGPHVVDJHV

3K\VLFDOILOH -RXUQDOHQWU\
0HVVDJH,' 'HVFULSWLRQ
QDPH FRGH

&3 $XWKRULW\YLRODWLRQ
&3 'RPDLQYLRODWLRQ
QASYAFJE $) &3 6XEPLWMREYLRODWLRQ
&3 'HIDXOWVLJQRQ
&3 &5&IDLOXUH
&3 3DVVZRUGQRWYDOLG
QASYPWJE 3:
&3 8VHU,'QRWYDOLG
QASYPWJE &$ &3 $XWKRULW\FKDQJH
QASYOWJE ': &3 2ZQHUVKLSFKDQJH
QASYPAJE 3$ &3 &KDQJHSURJUDPWRDGRSW
QASYSVJE 69 &3 6\VWHPYDOXHFKDQJH
QASYNAJE 1$ &3 1HWZRUNDWWULEXWHFKDQJHV
QASYRPJE 1$ &3 5HVWRUHRISURJUDPVWKDWDGRSW
QASYRJJE 5- &3 5HVWRUHRIMREGHVFULSWLRQWKDWFRQWDLQVDXVHUSURILOHQDPH
QASYROJE 52 &3 5HVWRUHRIREMHFWRZQHUFKDQJHV
QASYRAJE 5$ &3 5HVWRUHRIREMHFWDQGDXWKRULW\FKDQJHV
QASYRUJE 58 &3 5HVWRUHRIDXWKRULW\IRUXVHU
QASYDOJE '2 &3 'HOHWHRIREMHFW
QASYJDJE -' &3 -REGHVFULSWLRQFKDQJHWRVSHFLI\XVHUQDPH
QASYSEJE 5& &3 5RXWLQJHQWU\FKDQJHG
QASYCPJE &3 &3 8VHUSURILOHFKDQJHG
QASYDSJE '6 &3 5HTXHVWWRFKDQJHDST QSECOFR SDVVZRUG

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-15. Audit-related files and messages

Overview of the model database output files that can be used to define the record when you create
an output file with the DSPJRN command.
Complete layouts for the model database outfiles are found in Appendix F, “Layout of audit journal
entries,” on page 591 of the IBM i 7.3 Security – Security reference (SC41-5302-13) guide.

© Copyright IBM Corp. 1995, 2017 7-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$FWLRQDXGLWLQJIRUDVSHFLILFXVHU
‡ 8VHCHGUSRAUD WRVHWWKHAUDLVL IRUDVHOHFWHGXVHUSURILOH
CHGUSRAUD USRPRF(ADM01) AUDLVL(*SAVRST *CMD *DELETE*SPLFDTA)

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-16. Action auditing for a specific user

Values from the user profile parameter AUDLVL, system value QAUDCTL, and system value
QAUDLVL work together to control action auditing.
Example:
CHGUSRAUD USRPRF(ADM01) AUDLVL(*CMD *DELETE)
The Change User Audit (CHGUSRAUD) command allows a user with *AUDIT special authority to set
up or change auditing for a user. The system value QAUDCTL controls turning auditing on and off.
The auditing attributes of a user profile can be displayed with the Display User Profile (DSPUSRPRF)
command.
The changes made by CHGUSRAUD take effect the next time a job is started for this user.
Do not precede an entry with an asterisk unless that entry is a special value that is shown (on the
display itself or in the help information) with an asterisk.

© Copyright IBM Corp. 1995, 2017 7-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

$FWLRQDXGLWLQJIRUDVSHFLILFREMHFW
‡ 9DOXHVIURPWKHXVHUSURILOHSDUDPHWHUOBJAUDV\VWHPYDOXH
QAUDCTLDQGWKHREMHFWZRUNWRJHWKHUWRFRQWUROREMHFWDXGLWLQJ
‡ 8VHCHGOBJAUD WRVSHFLI\DXGLWLQJDFWLRQVRQREMHFWV
ƒ *NONE
ƒ *USRPRF
ƒ *CHANGE
ƒ *ALL

CHGOBJAUD OBJ(ADM01/CUSMSI) OBJTYPE(*FILE) OBJAUD(*USRPRF)

‡ 8VHCHGUSRAUD WRVHWWKHOBJAUD YDOXHVLQVHOHFWHGXVHUSURILOH


ƒ *SAME
ƒ *NONE
ƒ *CHANGE
ƒ *ALL

CHGUSRAUD USRPRF(ADM01) OBJAUD(*CHANGE)

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-17. Action auditing for a specific object

Values from the user profile parameter OBJAUD, system value QAUDCTL, and the object work
together to control object auditing.
In the visual, the Change Object Auditing (CHGOBJAUD) command allows users with *AUDIT
special authority to set up auditing on an object. Users with *AUDIT special authority can turn
auditing on or off for an object regardless of whether they have authority to the object.
The system value QAUDCTL controls turning auditing on and off.
The auditing attribute of an object can be displayed with the Display Object Description (DSPOBJD)
command.

Note

Do not precede an entry with an asterisk unless that entry is a special value that is shown on the
display itself or in the help information with an asterisk (*).

© Copyright IBM Corp. 1995, 2017 7-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

8VHU&DSDELOLWLHV!$XGLWLQJ

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-18. User: Capabilities > Auditing

A security auditor inside or outside your organization can use the auditing function that the system
provides to gather information about security-related events that occur on the system. The
Capabilities panel Auditing dialog specifies the object auditing values for this user.
System values and values specified for users work together to control action auditing. Which events
you choose to log depends on both your security objectives and your potential exposures. The
Capabilities panel Auditing dialog specifies the action auditing values for this user.
Use IBM Navigator for i.
1. Log on with your user name and password.
2. On the left pane under IBM i Management expand Users and Groups.
3. On the left pane click Users.
4. On the main pane right-click the selected user and choose Properties.
5. Then click Capabilities and click Auditing tab.

© Copyright IBM Corp. 1995, 2017 7-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

3ULQWLQJRUYLHZLQJDXGLWMRXUQDOHQWULHV
‡ <RXKDYHWKHIROORZLQJRSWLRQVIRUZRUNLQJZLWKDXGLWMRXUQDOHQWULHV
ƒ 8VHDSPJRN WRYLHZDQGSULQWHQWULHV
ƒ 2XWSXWDSPJRN WRGLVN
í 8VHUSURJUDP
í 48(5<
í 4XHU\PDQDJHU
í 64/
í :HE4XHU\

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-19. Printing or viewing audit journal entries

The Display Journal (DSPJRN) command allows you to convert journal entries (contained in one or
more receivers) into a form suitable for external representation. Output of the command can be
displayed or printed with the job's spooled printer output or directed to a database output file. If the
database output file exists, records can either replace or be added to the current data in the
indicated file member. The system creates the specified database file and member if they do not
exist. Database files created by the system have a standard format. A warning message is sent,
and the records are truncated if any of the entries are longer than the specified maximum record
length of the output files.
The contents of selected entries in the journal receivers might be converted for output. It is also
possible to selectively limit the entries that are displayed. If no journal entries satisfy the selection
or limitation criteria, an escape message is sent indicating that fact.
Gaps might exist in the sequence numbers of the entries converted. These occur because some of
the journal entries represent internal system information. These entries are not converted. It is
possible to show journal entries whose journal sequence numbers are reset in the chain of
receivers being specified.

© Copyright IBM Corp. 1995, 2017 7-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

'63-51WRYLHZDVSHFLILFHQWU\

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-20. DSPJRN to view a specific entry

The Display Journal (DSPJRN) command allows you to view selected journal entries at your
workstation. The journal entry shown is one that you requested on the Display Journal display. The
default is to display entries from only the attached receiver.
If you requested to see more than one journal entry, you can see the next one you requested by
pressing Enter. If you are currently viewing the last requested entry, pressing Enter takes you back
to the Display Journal display. You can go backward through the requested entries by pressing F14.
If you see More... on the lower right side of your display, there is more information to view. Press
Page Down (or Roll Up) to move toward the end of the information. Press Page Up (or Roll Down)
to move toward the beginning of the information. If you see Bottom instead of More..., you are at
the end of the information.

© Copyright IBM Corp. 1995, 2017 7-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

'63-51WRYLHZ!)

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-21. DSPJRN to view > F10

The Display Journal Entry Details display shows only the detail entry data for a specific journal
entry. The journal entry shown is one that you requested on the Display Journal display.
If you requested to see more than one journal entry, you can see the next one you requested by
pressing Enter. If you are currently viewing the last requested entry, pressing Enter takes you back
to the Display Journal display. You can go backward through the requested entries by pressing F14.

© Copyright IBM Corp. 1995, 2017 7-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

2XWSXW'63-51WRGLVN!SULQW
DSPJRN JRN(QSYS/QAUDJRN) +
ENTTYP(AF) +
OUTPUT(*OUTFILE) +
OUTFILFMT(*TYPE5) +
OUTFILE(QTEMP/your_file)

‡ 7KHIRUPDWRIyour_file LVQASYAFJ5
‡ 8VH48(5<RU\RXURZQSURJUDPIRUIXUWKHUDQDO\VLV

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-22. Output DSPJRN to disk > print

Outfile format (OUTFILFMT)


Specifies the format of the journal entries written to the output file specified on the file to receive
output prompt (OUTFILE parameter). This parameter can be specified only if the value *OUTFILE
is specified on the OUTPUT parameter.
The information fields and the format of the information in each journal entry is shown in tables for
this parameter in the command description in the CL reference information at IBM Knowledge
Center for i [Link]
The possible values are:
*TYPE1: The converted entries are formatted to include the minimum information that can be
specified.
*TYPE2: The converted entries include the information returned when OUTFILFMT(*TYPE2) is
specified. Plus the name of the user profile for the job that generated the displayed journal entries
and the name of the system on which the output records were generated.
*TYPE3: The converted journal entries include all the information returned when
OUTFILFMT(*TYPE3) is specified and the null value indicators.

© Copyright IBM Corp. 1995, 2017 7-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty
*TYPE4: The converted entries include the information returned when OUTFILFMT(*TYPE4) is
specified, the journal identifier, the physical file trigger indicator, and the referential constraint
indicator.
*TYPE5: The converted entries include the information returned when OUTFILFMT(*TYPE5) is
specified, the program library, and ASP information (this format is recommended).
File to receive output (OUTFILE): Specifies the name and library of the database file to which the
output of the command is directed. If the output file already exists, the system attempts to use it.
Records can replace or be added to the current data in the file member. If no records are written to
the database file (because of the specified selection values) and *REPLACE is specified on the
OUTMBR parameter, records are cleared from the existing database file. If the file does not exist, this
command creates a database file in the specified library.

© Copyright IBM Corp. 1995, 2017 7-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

&RQVLGHUMRXUQDOLQJFULWLFDOILOHV
‡ 2IIHUVERWK BEFORE DQG AFTER LPDJLQJ

‡ 7UDFNVFKDQJHVE\MREGDWHWLPHDQGXVHUSURILOH

‡ -RXUQDOUHFHLYHUHQWULHVFDQQRWEHPRGLILHGHYHQE\46(&2)5

‡ -RXUQDOUHFHLYHUVFDQEHVDYHG

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-23. Consider journaling critical files

This is not security audit journaling. This is normal database file journaling in which detailed record
images of additions, deletions, and changes to records in a database file are logged to a journal.

© Copyright IBM Corp. 1995, 2017 7-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH6HFXULW\DXGLWLQJLVLPSOHPHQWHGWRNHHSD
V\VWHPDWDSODQQHGVHFXULW\OHYHO

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHOHYHOVRIVHFXULW\
DXGLWLQJWKDWFDQEHLPSOHPHQWHGRQWKHV\VWHP"
D 6\VWHPZLGH
E 6SHFLILFXVHU
F 6SHFLILFREMHFW
G &RQILJXUDWLRQFKDQJHV

 7UXHRUIDOVH$QHIIHFWLYHVHFXULW\VWUDWHJ\GRHVQRWUHTXLUH
WKDWLWEHHQGRUVHGE\PDQDJHPHQW

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-24. Review questions

© Copyright IBM Corp. 1995, 2017 7-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH6HFXULW\DXGLWLQJLVLPSOHPHQWHGWRNHHSD
V\VWHPDWDSODQQHGVHFXULW\OHYHO
7KHDQVZHULVWUXH

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHOHYHOVRIVHFXULW\
DXGLWLQJWKDWFDQEHLPSOHPHQWHGRQWKHV\VWHP"
D 6\VWHPZLGH
E 6SHFLILFXVHU
F 6SHFLILFREMHFW
G &RQILJXUDWLRQFKDQJHV
7KHDQVZHULVFRQILJXUDWLRQFKDQJHV

 7UXHRUIDOVH$QHIIHFWLYHVHFXULW\VWUDWHJ\GRHVQRWUHTXLUH
WKDWLWEHHQGRUVHGE\PDQDJHPHQW
7KHDQVZHULVIDOVH
6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-25. Review answers

© Copyright IBM Corp. 1995, 2017 7-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 7. Security auditing

Uempty

8QLWVXPPDU\
‡ /LVWDQGGLVFXVVWKHW\SHVRIVHFXULW\UHODWHGDFWLYLWLHVWKDW\RXFDQ
PRQLWRURQ\RXUV\VWHP
‡ /LVWWKHGLIIHUHQWOHYHOVRIVHFXULW\DXGLWLQJWKDW\RXFDQLPSOHPHQW
‡ ([SODLQZK\LPSOHPHQWLQJDXGLWLQJLVDQRQJRLQJSURFHVV
‡ /LVWDQGFRQILJXUHWKHFRPPDQGVDQGV\VWHPYDOXHVXVHGWRLPSOHPHQW
VHFXULW\DXGLWLQJ
‡ ([SODLQWKHVWHSVUHTXLUHGWRLPSOHPHQWWKHGLIIHUHQWW\SHVRIVHFXULW\
DXGLWLQJ

6HFXULW\DXGLWLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 7-26. Unit summary

© Copyright IBM Corp. 1995, 2017 7-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

Unit 8. Designing security


Estimated time
01:00

Overview
Security is the prevention of access to objects by unauthorized users. Integrity is the protection of
objects from accidental destruction or alteration. The security aids provided in the operating system
assist the system administrator to control who can use the system, who can use the objects, and
what authority they will have to those objects.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 8-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

8QLWREMHFWLYHV
‡ /LVWVRPHUHFRPPHQGDWLRQVIRUVHFXULW\GHVLJQ
‡ 'LVFXVVWKHFRQFHSWRILPSOHPHQWLQJOLEUDU\VHFXULW\
‡ 'LVFXVVVRPHGHVLJQJXLGHOLQHVWRNHHSLQPLQGZKHQLPSOHPHQWLQJ
PHQXVHFXULW\
‡ 'HVFULEHWKHSURFHVVXVHGE\WKHV\VWHPIRUVLJQRQSURFHVVLQJ
‡ ([SODLQWKHIXQFWLRQVSURYLGHGE\WKH6\VWHP5HTXHVWVFUHHQDQGKRZ
WRVHFXUHWKLVVFUHHQRUWKHVFUHHQRSWLRQV
‡ 'LVFXVVWKHFRQFHSWVRILPSOHPHQWLQJREMHFWVHFXULW\
‡ /LVWDQGGLVFXVVWKHFRPPDQGVXVHGWREDFNXSDQGUHFRYHUVHFXULW\
LQIRUPDWLRQ
‡ 'HVFULEHWKHVHFXULW\WRROVWKDWDUHDYDLODEOHWRDVVLVW\RXZLWKWKH
LPSOHPHQWDWLRQRIVHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 8-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

'HVLJQLQJVHFXULW\
‡ 0RVWSHRSOHXVHDFRPELQDWLRQRIWKHIROORZLQJPHWKRGVWRVHFXUHWKHLU
V\VWHP
ƒ /LEUDU\VHFXULW\
ƒ 0HQXVHFXULW\
ƒ 2EMHFWVHFXULW\
ƒ )LOHVHFXULW\
ƒ $GRSWHGVHFXULW\
ƒ &RPPDQGVHFXULW\
‡ 8VLQJFRPELQDWLRQVRI
ƒ 8VHUV
ƒ *URXSV
ƒ $XWKRUL]DWLRQOLVWV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-2. Designing security

Most users of the Power Systems with IBM i end up using a combination of all of the security
methods that are supported on the i platform.
Use the information covered in this unit (along with the publication mentioned on the following
pages) as a conceptual overview of the steps that need to be taken to secure your system.

© Copyright IBM Corp. 1995, 2017 8-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

2YHUDOOUHFRPPHQGDWLRQIRUVHFXULW\GHVLJQ
‡ .HHSWKHGHVLJQDVVLPSOHDVSRVVLEOH

‡ 8VHUHVRXUFHVHFXULW\DORQJZLWKWKHRWKHUPHWKRGVDYDLODEOHWRSURWHFW
LQIRUPDWLRQ

‡ 6HFXUHRQO\WKRVHREMHFWVWKDWUHTXLUHVHFXULQJ

‡ 0RYHIURPJHQHUDOWRVSHFLILFDXWKRULW\

‡ 'HWHUPLQHZKDWVKRXOGEHWKHGHIDXOW 38%/,&DXWKRULW\DQG
LPSOHPHQWLWZLWKWKHCRTAUT SDUDPHWHU

‡ $YRLGSULYDWHDXWKRULWLHVWKDWDUHOHVVWKDQSXEOLFDXWKRULW\

‡ 8VHDXWKRUL]DWLRQOLVWVWRVHFXUHJURXSREMHFWVZLWKWKHVDPHVHFXULW\
UHTXLUHPHQWV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-3. Overall recommendation for security design

Use resource security along with the methods available, such as limited capabilities in the user
profile and restricting users to a set of menus to protect information.
Secure only those objects that really require security. Analyze a library to determine which objects,
such as data files, are confidential, and secure those objects. Use public authority for other objects,
such as data areas and message queues.
Move from the general to the specific:
• Plan security for libraries and directories. Deal with individual objects only when necessary.
• Plan public authority first, followed by group authority, and individual authority
Make the public authority for new objects in a library (CRTAUT parameter) the same as the public
authority for most of existing objects in the library.
To make auditing easier and improve authority-checking performance, avoid defining private
authority that is less than the public authority for an object.
Use authorization lists to group objects with the same security requirements. Authorization lists are
simpler to manage than individual authorities and help to recover security information.

© Copyright IBM Corp. 1995, 2017 8-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

3ODQQLQJDQGVHWWLQJXSV\VWHPVHFXULW\JXLGH

KWWSVZZZLEPFRPVXSSRUWNQRZOHGJHFHQWHUVVZBLEPBL
‡ 6HFXULW\
ƒ 3ODQQLQJDQGVHWWLQJXSV\VWHPVHFXULW\
í 3ODQQLQJDQGVHWWLQJXSV\VWHPVHFXULW\
KWWSVZZZLEPFRPVXSSRUWNQRZOHGJHFHQWHUHQVVZBLEPBLBU]DPYU]DPYSODQVHFKWP

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-4. Planning and setting up system security guide

The information in this topic collection provides you with detailed information about planning,
setting up, and using your system security. Determining your company's system security is one of
the most basic and most important decisions that you make during the course of building your
security plan. With system security, you need to balance the need to safeguard your valuable
information and the need of users to access that information to successfully make your company
thrive. To strike this balance, you must understand the specific needs and goals of your company's
current direction but also be aware of future needs. Your security plan must protect your resources
but also must be flexible enough to grow as your company grows.
Several tools exist that can aid you in creating, configuring, and managing your system-level
security on your server. It is important to note that security does not end with protecting the server
and managing access to assets that are stored on the system. A complete security implementation
needs to include not only system-level security, but also network-level security and
transaction-level security. This topic focuses on system-level security.
Use this information to develop a personalized plan that fits your company's specific system
security needs. After you complete the planning phase of your system security, you can set up
system security by using the instructions provided in this information.

© Copyright IBM Corp. 1995, 2017 8-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
8.1. Topic 1: Library security

© Copyright IBM Corp. 1995, 2017 8-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

7RSLF/LEUDU\VHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-5. Topic 1: Library security

Many factors affect how you choose to group your application information into libraries and manage
libraries. To access an object, you need authority to the object itself and to the library containing the
object. You can restrict access to an object by restricting the object itself, the library containing the
object, or both.
Planning libraries
A library is like a directory used to locate the objects in the library. *USE authority to a library allows
you to use the directory to find objects in the library. The authority for the object itself determines
how you can use the object. *USE authority to a library is sufficient to perform most operations on
the objects in the library. Using public authority for objects and restricting access to libraries can be
a simple, effective security technique. Putting programs in a separate library from other application
objects can also simplify security planning. This is particularly true if files are shared by more than
one application. You can use authority to the libraries containing application programs to control
who can perform application functions.

© Copyright IBM Corp. 1995, 2017 8-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

/LEUDU\VHFXULW\
‡ /LEUDU\VHFXULW\LVHIIHFWLYHRQO\LIWKHVHUXOHVDUHIROORZHG

ƒ /LEUDULHVFRQWDLQREMHFWVZLWKVLPLODUVHFXULW\UHTXLUHPHQWV

ƒ $FFHVVLVJUDQWHGRUUHVWULFWHGDWWKHOLEUDU\OHYHO

ƒ 7\SLFDOO\XVHUVWKDWKDYHDFFHVVWRWKHOLEUDU\KDYHDFFHVVWRDOOWKHREMHFWV
LQWKHOLEUDU\ WKURXJK 38%/,&DXWKRULW\ 

ƒ 8VHUVDUHQRWDOORZHGWRDGGQHZREMHFWVWRUHVWULFWHGOLEUDULHV

ƒ 6HFXUH\RXUOLEUDU\OLVWVDQGDQ\FRPPDQGVXVHGWRFKDQJHWKHP

ƒ 7KLVPLJKWQRWEHJUDQXODUHQRXJKHVSHFLDOO\IRUVHQVLWLYHREMHFWV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-6. Library security

Changes to programs in the libraries are controlled. That is, application libraries should have public
authority of *USE or *EXCLUDE unless users need to create objects directly into the library.

© Copyright IBM Corp. 1995, 2017 8-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
8.2. Topic 2: Menu security

© Copyright IBM Corp. 1995, 2017 8-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

7RSLF0HQXVHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-7. Topic 2: Menu security

© Copyright IBM Corp. 1995, 2017 8-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

0HQXVHFXULW\'HVLJQJXLGHOLQHV
‡ 'RQRWSURYLGHDFRPPDQGOLQHRQPHQXVGHVLJQHGIRUUHVWULFWHGXVHUV

‡ $YRLGKDYLQJIXQFWLRQVZLWKGLIIHUHQWVHFXULW\UHTXLUHPHQWVRQWKHVDPH
PHQX

‡ 0DNHVXUHWKDWWKHVHWRIPHQXVSURYLGHVDOOWKHQHFHVVDU\OLQNV
EHWZHHQPHQXV

‡ 3URYLGHDFFHVVWRDIHZV\VWHPIXQFWLRQV

‡ 3URYLGHDFFHVVWRGHFLVLRQVXSSRUWWRROVIURPPHQXV

‡ &RQVLGHUFRQWUROOLQJDFFHVVWRWKH6\VWHP5HTXHVWVFUHHQ

‡ )RUXVHUVDOORZHGWRUXQDVLQJOHIXQFWLRQDYRLGPHQXVHQWLUHO\DQG
VSHFLI\DQLQLWLDOSURJUDP

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-8. Menu security: Design guidelines

Here are design guidelines for menu security:


• Do not provide a command line on menus designed for restricted users.
• Avoid having functions with different security requirements on the same menu. For example, if
some application users are allowed to only view information, not change it, provide a menu that
only provides display and print options for those users.
• Make sure that the set of menus provides all the necessary links between menus so the user
does not need a command line to request one.
• Provide access to a few system functions, such as viewing printer output. The ASSIST system
menu gives this capability and can be defined in the user profile as the Attention-key-handling
program. If the user profile has a class of *USER and has limited capabilities, the user cannot
view the output or jobs of other users.
• Provide access to decision-support tools from menus.
• Consider controlling access to the System Request screen or some of the options on this
screen.
• For users who are allowed to run only a single function, avoid menus entirely and specify an
initial program in the user profile. Specify *SIGNOFF as the initial menu.

© Copyright IBM Corp. 1995, 2017 8-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

8VHUSURILOHVHVVLRQVWDUWXS0HQXVHFXULW\
‡ &RQILQHXVHUVWRDPHQXLQWHUIDFH
ƒ ,QLWLDOSURJUDP SURJUDPQDPH
ƒ ,QLWLDOPHQX 6LJQRII

 Or 

ƒ ,QLWLDOSURJUDP 1RLQLWLDOSURJUDP
ƒ ,QLWLDOPHQX PHQXQDPH

ƒ /LPLWLQLWLDOSURJUDP
RUPHQXFDSDELOLWLHV
/LPLWFDSDELOLWLHV

‡ 'RQRWSURYLGHFRPPDQGOLQH

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-9. User profile session startup: Menu security

You can specify the name of a program to call when a user signs on. This program runs before the
initial menu, if any, is displayed. If the Limit capabilities field in the user's profile is *YES or
*PARTIAL, the user cannot specify an initial program on the Sign On display.
You can specify the name of a menu to be shown when the user signs on. The initial menu is
displayed after the user's initial program runs. The initial menu is called only if the user's routing
program is QCMD or QCL.

© Copyright IBM Corp. 1995, 2017 8-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

0HQXVHFXULW\6LJQRQSURFHVVLQJ

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-10. Menu security: Sign-on processing

When you start a job on the system, objects are associated with the job, such as an output queue,
a job description, and the libraries on the library list. Authority for some of these objects is checked
before the job is allowed to start and for other objects after the job starts. Inadequate authority
might cause errors or might cause the job to end.
The system administrator can change the system signon display to add text or company logo to the
display. Care must be taken to make sure the field names or buffer lengths of the display file are not
changed when adding text to the display file. Changing the field names or buffer lengths might
cause signon to fail.
The source for the signon display file is shipped as a member (QDSIGNON or QDSIGNON2) in the
QSYS/QAWTSSRC physical file. QDSIGNON contains the source for the signon screen source
used when system value QPWDLVL is set to 0 or 1. Member QDSIGNON2 contains the signon
screen source used when the system value QPWDLVL is set to 2 or 3.

Note

Look at this information before change QPWDLVL system value.

© Copyright IBM Corp. 1995, 2017 8-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
Password level 2 introduces the use of case-sensitive passwords up to 128 characters in length
(also called passphrases) and provides the maximum ability to revert to QPWDLVL 0 or 1.
Regardless of the password level of the system, password level 2 and 3 passwords are created
whenever a password is changed or a user signs on to the system. Having a level 2 and 3
password created while the system is still at password level 0 or 1 helps prepare for the change to
password level 2 or 3.
Before changing QPWDLVL to 2, the system administrator should use the PRTUSRPRF
TYPE(*PWDLVL) command to locate all of the user profiles that do not have a password that is
usable at password level 2. Depending on the profiles located, the administrator can use one of the
following mechanisms to have a password level 2 and 3 password added to the profiles. Change
the password for the user profile by using the CHGUSRPRF or CHGPWD CL command or the
QSYCHGPW API. This causes the system to change the password that is usable at password
levels 0 and 1and the system also creates two equivalent case-sensitive passwords that are usable
at password levels 2 and 3. An all-uppercase and all-lowercase version of the password is created
for use at password level 2 or 3. For example, changing the password to C4D2RB4Y results in the
system generating C4D2RB4Y and c4d2rb4y password level 2 passwords.
Sign on to the system through a mechanism that presents the password in clear text (does not use
password substitution). If the password is valid and the user profile does not have a password that
is usable at password levels 2 and 3, the system creates two equivalent case-sensitive passwords
that are usable at password levels 2 and 3. An all-uppercase and all-lowercase version of the
password is created for use at password level 2 or 3.
The absence of a password that is usable at password level 2 or 3 can be a problem whenever the
user profile also does not have a password that is usable at password levels 0 and 1 or when the
user tries to sign on through a product that uses password substitution. In these cases, the user will
not be able to sign on when the password level is changed to 2.
If a user profile meets the following description, the system validates the user against the password
level 0 password and creates two password level 2 passwords (as described above) for the user
profile. The user profile does not have a password that is usable at password levels 2 and 3.
The user profile does have a password that is usable at password levels 0 and 1.
The user signs on through a product that sends clear text passwords.
Subsequent signons are validated against the password level 2 passwords.
Any client that uses password substitution will not work correctly at QPWDLVL 2 if the client hasn't
been updated to use the new password (passphrase) substitution scheme. The administrator
should check whether a client that has not been updated to the new password substitution scheme
is required.
The clients that use password substitution include:
• TELNET
• System i Access
• System i Host Servers
• QFileSrv.400
• System i NetServer Print support

© Copyright IBM Corp. 1995, 2017 8-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
• DDM
• DRDA
• SNA LU6.2
It is highly recommended that security data is saved before changing to QPWDLVL 2. This can help
make the transition back to QPWDLVL 0 or 1 easier if that becomes necessary.
Avoid changing password system values, such as QPWDMINLEN, QPWDMAXLEN, and QPWDRULES,
until after you tested QPWDLVL 2. This makes it easier to transition back to QPWDLVL 1 or 0 if
necessary. However, the QPWDVLDPGM system value must specify either *REGFAC or *NONE
before the system allows QPWDLVL to be changed to 2. Therefore, if you use a password
validation program, you might want to write a new one that can be registered for the
QIBM_QSY_VLD_PASSWRD exit point by using the ADDEXITPGM command.
NetServer passwords are still supported at QPWDLVL 2, so any function/service that requires a
NetServer password should still function correctly.
After you are comfortable with running the system at QPWDLVL 2, you can change the password
system values to use longer passwords. However, you need to be aware that longer passwords
have these effects: If passwords greater than 10 characters are specified, the password level 0 and
1 password is cleared. This user profile will not be able to sign on if the system is returned to
password level 0 or 1.
If passwords contain special characters or do not follow the composition rules for simple object
names (excluding case sensitivity), the password level 0 and 1 password is cleared.
If passwords greater than 14 characters are specified, the NetServer password for the user profile
is cleared.
The password system values only apply to the new password level 2 value and do not apply to the
system-generated password level 0 and 1 password or NetServer password values (if generated).

© Copyright IBM Corp. 1995, 2017 8-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6LJQRQSURFHVVLQJ RI
1R
9DOLGXVHUSDVVZRUG" (UURUPHVVDJH
<HV
1R
$XWKRUL]HGWRGHYLFH" (UURUPHVVDJH
<HV
<HV
3URJUDPPHQXOLEH[FHHG (UURUPHVVDJH
FDSDELOLW\"
1R
3URJUDP 1R
INLPGM LQSURILOH"
NH\HG"
<HV
<HV

&DOONH\HG &DOOINLPGM
SURJUDP
$
'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-11. Sign-on processing (1 of 2)

After the user enters a user ID and password, these steps are performed before a job is actually
started on the system:
1. The user profile and password are verified.
2. The user's authority to use the workstation is checked.
3. The system verifies authority for the values in the user profile and in the user's job description
that is used to build the job structure, such as job description, output queue, current library, and
libraries in library list.
After the job is started, these steps are performed before the user sees the first display or menu:
1. If the routing entry for the job specifies a user program, normal authority checking is done for
the program, the program library, and any objects used by the program.
2. If the routing entry specifies the command processor (QCMD):
a. Authority checking is done for the QCMD processor program, the program library, and any
objects used, as described in step 1.
b. The user's authority to the Attention-key-handling program and library is checked.
c. Normal authority checking is done for the initial program (and its associated objects)
specified in the user profile.
d. Normal authority checking is done for the initial menu (and its associated objects) specified
in the user profile.

© Copyright IBM Corp. 1995, 2017 8-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6LJQRQSURFHVVLQJ RI

1R
0HQXNH\HG"
<HV
SIGNOFF LQ <HV
SURILOH" 6LJQRIIXVHU
'LVSOD\
NH\HGPHQX 1R

'LVSOD\
SURILOHPHQX

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-12. Sign-on processing (2 of 2)

If the user has the capability, a keyed menu name overrides the menu name in the user profile.
*SIGNOFF is a valid menu name. It causes the user to be signed off. Menu name might not be
blank.

© Copyright IBM Corp. 1995, 2017 8-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6\VWHP5HTXHVWVFUHHQVHFXULW\

‡ 7RSUHYHQWVSHFLILFXVHUVIURPVHHLQJWKH6\VWHP5HTXHVWVFUHHQVSHFLI\WKH
IROORZLQJ
GRTOBJAUT OBJ(QSYS/QGMNSYSR) OBJTYPE(*PNLGRP)
USER(USERA) AUT(*EXCLUDE)
'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-13. System Request screen security

A user can use the system request function to suspend the current job and display the System
Request screen. The System Request screen allows the user to send and display messages,
transfer to a second job, or end the current job. This might represent a security exposure because
the public authority to the System Request screen is *USE when a system is shipped.
To call up the System Request screen:
1. Press the Sys Req key to show an input line at the bottom of the display. In most currently PC,
Laptops or another devices there is no SysReq key. You can call system request in two ways:
a. Press Shift+ESC key and press Enter.
b. On the “5250 session” window right-click and from pop-up window click SysRq button.
2. Press Enter to show the System Request screen.
Each time the System Request key is pressed, the system automatically changes the current user
profile of the job to the initial user profile of the job. This is done so that the user does not have any
additional authority on the System Request screen or in the Presystem Request Program exit
program. After the System Request function is completed, the current user profile of the job is
returned to the value that it was before the System Request key was pressed.

© Copyright IBM Corp. 1995, 2017 8-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6\VWHP5HTXHVWVFUHHQ$VHFRQGDU\MRE
-RE$ -RE%

6LJQRQ
 3URFHVV
6\VWHP5HTXHVW
6LJQRQ
 3URFHVV
6\VWHP5HTXHVW
5HVXPHSURFHVVLQJ

6\VWHP5HTXHVW
5HVXPHSURFHVVLQJ

6LJQRII
5HVXPHSURFHVVLQJ

6LJQRII

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-14. System Request screen: A secondary job

From the System Request screen, select option 1 to display the signon for a secondary job (Job B
in this example). The original job (Job A in this example) is suspended during the time Job B is
processed.
If the operator presses Sys Req and picks option 1, Job B is suspended and Job A is continued
from the point it was suspended.
Thus, the operator can jump between two jobs, processing one while the other is suspended.
When the operator signs off one job (either one) the other job is given control to continue
processing.

© Copyright IBM Corp. 1995, 2017 8-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

5HVWULFWLQJWKHXVHRI6\VWHP5HTXHVWVFUHHQRSWLRQV
2SWLRQ &RPPDQG
 7UDQVIHU6HFRQGDU\-RE TFRSECJOB
 (QG5HTXHVW ENDRQS
 'LVSOD\-RE DSBJOB
 'LVSOD\0HVVDJH DSPMSG
 6HQG0HVVDJH SNDMSG
 'LVSOD\0HVVDJH DSPMSG
 'LVFRQQHFW-RE DSCJOB
 6LJQ2II SIGNOFF

‡ $Q\RIWKHRSWLRQVFDQEHUHVWULFWHGE\UHPRYLQJSXEOLFDXWKRULW\WRWKH
DVVRFLDWHGFRPPDQG)RUH[DPSOH
GRTOBJAUT OBJ(TFRSECJOB) OBJTYPE(*CMD)
USER(*PUBLIC) AUT(*EXCLUDE)

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-15. Restricting the use of System Request screen options

You can prevent users from selecting specific options from the System Request screen by
restricting the authority to the associated commands.

© Copyright IBM Corp. 1995, 2017 8-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
8.3. Topic 3: Object security

© Copyright IBM Corp. 1995, 2017 8-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

7RSLF2EMHFWVHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-16. Topic 3: Object security

Object security, as a part of resource security, defines which users are allowed to use objects on
the system and what operations they are allowed to perform on those objects. Also, deciding who is
allowed access to what information on your system is an important part of your security policy.

© Copyright IBM Corp. 1995, 2017 8-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

2EMHFWVHFXULW\
‡ $FFHVVLVJUDQWHGRUUHVWULFWHGDWWKHLQGLYLGXDOREMHFWOHYHO

‡ 7KLVLVWKHPRVWVHFXUHPHWKRG

‡ 7KLVPHWKRGSURYLGHVWKHPRVWJUDQXODULW\

‡ ,WFDQDOVREHWKHPRVWFRPSOH[WRVHWXS

‡ ,WFDQKDYHSHUIRUPDQFHLPSDFWVERWKDWUXQWLPHDQGDWEDFNXSDQG
UHVWRUHWLPH

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-17. Object security

© Copyright IBM Corp. 1995, 2017 8-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

&RPPDQGVHFXULW\
‡ &KDQJHWKHDXWKRULW\WRVSHFLILFFRPPDQGV

‡ 8VHUQHHGV 86(DXWKRULW\LQRUGHUWRUXQDFRPPDQG

‡ &KDQJHWKHGHIDXOWYDOXHVIRUFRPPDQGV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-18. Command security

When your system arrives, the ability to use commands is set up to meet the security needs of most
installations. Some commands can be run only by a security officer. Others require a special
authority, such as *SAVSYS. Most commands can be used by anyone on the system. You can
change the authority to commands to meet your security requirements.
For example, you might want to prevent most users on your system from working with
communications. You can set the public authority to *EXCLUDE for all commands that work with
communications objects, such the CHGCTLxxx, CHGLINxxx, and CHGDEVxxx commands.
If you need to control which commands can be run by users, you can use object authority to the
commands themselves. Every command on the system has object type *CMD and can be
authorized to the public or only to specific users. To run a command, the user needs *USE authority
to that command.
Appendix C, in the Security Reference manual lists all the commands that are shipped with the
public authority set to *EXCLUDE.
If you use one or more national language versions of the i5/OS licensed program on your system,
you need to restrict commands in the additional QSYSxxx libraries on your system as well.
Another useful security measure is to change the default values for some commands. The Change
Command Default (CHGCMDDFT) command allows you to do this.

© Copyright IBM Corp. 1995, 2017 8-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

$SSHQGL[&6HFXUHGFRPPDQGV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-19. Appendix C: Secured commands

This section of the Security Reference manual identifies which commands have restricted
authorization (public authority is *EXCLUDE) when your system is shipped. It shows which
IBM-supplied user profiles are authorized to use these restricted commands.
Any commands not listed here are public, which means they can be used by all users. However,
some commands require special authority, such as *SERVICE or *JOBCTL. The special authorities
required for a command are listed in Appendix D of the manual, “Authority required for objects used
by commands”.
If you choose to grant other users or the public *USE authority to these commands, update this
table to indicate which commands are no longer restricted on your system. Using some commands
might require the authority to certain objects on the system as well as to the commands
themselves.
The Security Reference document can be reached at
[Link]

© Copyright IBM Corp. 1995, 2017 8-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6\VWHPGHILQHGDXWKRULWLHVIRUILOHVDQGSURJUDPV
86( &+$1*( $//DXWKRULW\ (;&/8'(
DXWKRULW\ DXWKRULW\ DXWKRULW\
2SHUDWLRQV 9LHZ 9LHZFKDQJH &UHDWHDQGGHOHWHWKH 1RQH
DOORZHGIRU LQIRUPDWLRQLQ DQGGHOHWH ILOH$GGFKDQJHDQG
ILOHV WKHILOH UHFRUGVLQWKH GHOHWHWKHUHFRUGVLQWKH
ILOH ILOH$XWKRUL]HRWKHUVWR
XVHWKHILOH
2SHUDWLRQV &KDQJHRU 'HOHWHRUFOHDU 1RQH $Q\DFFHVVWR
QRW DOORZHG GHOHWHDQ\ WKHHQWLUHILOH WKHILOH
IRUILOHV LQIRUPDWLRQLQ
WKHILOH'HOHWH
WKHILOH
2SHUDWLRQV 5XQWKH &KDQJHWKH &UHDWHFKDQJHDQG 1RQH
DOORZHGIRU SURJUDP GHVFULSWLRQRI GHOHWHWKHSURJUDP
SURJUDPV WKHSURJUDP $XWKRUL]HRWKHUVWRXVH
WKHSURJUDP
2SHUDWLRQV &KDQJHRU &KDQJHRU &KDQJHWKHRZQHURIWKH $Q\DFFHVVWR
QRW DOORZHG GHOHWHWKH GHOHWHWKH SURJUDPLIWKHSURJUDP WKHSURJUDP
IRUSURJUDPV SURJUDP SURJUDP DGRSWVDXWKRULW\
ï (;&/8'(RYHUULGHVDQ\DXWKRULWLHVWKDW\RXJUDQWWRWKHSXEOLFRUWKURXJKDJURXSSURILOH

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-20. System-defined authorities for files and programs

IBM i 7.3. Security - Planning and Setting Up System Security


This page from the Planning and setting up system security section of the IBM i 7.3 Security
Reference (page 17) describes system defined authorities and the operations that can be
performed against file and program objects.

© Copyright IBM Corp. 1995, 2017 8-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6\VWHPGHILQHGDXWKRULWLHVIRUOLEUDULHV
86(DXWKRULW\ &+$1*( $// (;&/8'(
DXWKRULW\ DXWKRULW\ DXWKRULW\

2SHUDWLRQV • )RUREMHFWVLQWKH • )RUREMHFWVLQWKH • (YHU\WKLQJ 1RQH


DOORZHGIRU OLEUDU\DQ\ OLEUDU\DQ\ DOORZHGZLWK
OLEUDULHV RSHUDWLRQDOORZHG RSHUDWLRQDOORZHG FKDQJH
E\WKHDXWKRULW\WR E\WKHDXWKRULW\WR DXWKRULW\
WKHVSHFLILFREMHFW WKHVSHFLILF • 'HOHWHWKH
• )RUWKHOLEUDU\YLHZ REMHFW OLEUDU\
GHVFULSWLYH • $GGQHZREMHFWV • $XWKRUL]H
LQIRUPDWLRQ WRWKHOLEUDU\ RWKHUVWR
• &KDQJHWKH WKHOLEUDU\
OLEUDU\GHVFULSWLRQ

• $GGQHZREMHFWVWR 'HOHWHWKHOLEUDU\ 1RQH $Q\DFFHVVWR


2SHUDWLRQV
WKHOLEUDU\ WKHOLEUDU\
QRW DOORZHG
• &KDQJHWKHOLEUDU\
IRUOLEUDULHV
GHVFULSWLRQ
• 'HOHWHWKHOLEUDU\

ï (;&/8'(RYHUULGHVDQ\DXWKRULWLHVWKDW\RXJUDQWWRWKHSXEOLFRUWKURXJKDJURXSSURILOH
'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-21. System-defined authorities for libraries

IBM i 7.3. Security - Planning and Setting Up System Security


This page from the Planning and setting up system security section of the IBM i 7.3 Security
Reference (page 18) describes system defined authorities and the operations that can be
performed against library objects.

© Copyright IBM Corp. 1995, 2017 8-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

+RZOLEUDU\DXWKRULW\DQGREMHFWDXWKRULW\ZRUNWRJHWKHU

2EMHFWW\SH 2SHUDWLRQV 2EMHFWDXWKRULW\QHHGHG /LEUDU\DXWKRULW\QHHGHG

)LOH &KDQJHGDWD &+$1*( (;(&87(

)LOH 'HOHWHWKHILOH 2%-235 2%-(;,67 (;(&87(

)LOH &UHDWHWKHILOH 1RQH (;(&87( $''

3URJUDP 5XQWKHSURJUDP 86( (;(&87( 2%-235

3URJUDP 5HFRPSLOHWKHSURJUDP 2%-(;,67 2%-0*5 $'' 5($'


5($'

3URJUDP 'HOHWHWKHSURJUDP 2%-(;,67 (;(&87(

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-22. How library authority and object authority work together

IBM i 7.3. Security - Planning and Setting Up System Security


This page from the Planning and setting up system security section of the IBM i 7.3 Security
Reference (page 18) describes how library authorities and object authorities work together to
provide access to the objects.

© Copyright IBM Corp. 1995, 2017 8-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULQJSK\VLFDOYHUVXVORJLFDOILOHV RI

/RJLFDOILOHV

CUSTINFO CUSTCRDT CUSTSLS

1DPH
1DPH 1DPH
$GGUHVV
$GGUHVV $GGUHVV
&UHGLWOLPLW
&UHGLWOLPLW 6DOHV
6DOHV

3K\VLFDO)LOHV± CUSTMAST

1DPH $GGUHVV &UHGLW/LPLW 6DOHV7R'DWH

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-23. Securing physical versus logical files (1 of 2)

Resource security on the system supports field-level security of a file. You can also use logical files
to protect specific fields or records in a file.
A logical file can be used to specify a subset of records that a user can access (by using select and
omit logic). Therefore, specific users can be prevented from accessing certain record types.
A logical file can be used to specify a subset of fields in a record that a user can access. Therefore,
specific users can be prevented from accessing certain fields in a record.
A logical file does not contain any data. It is a particular view of one or more physical files that
contain the data. Providing access to the information defined by a logical file requires data authority
to both the logical file and the associated physical files.
The visual shows an example of a physical file and three different logical files associated with it.

© Copyright IBM Corp. 1995, 2017 8-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULQJSK\VLFDOYHUVXVORJLFDOILOHV RI
‡ 7RXVHORJLFDOILOHVDVDVHFXULW\WRRO

ƒ *UDQWDOOGDWDDXWKRULWLHVWRWKHXQGHUO\LQJSK\VLFDOILOHV

ƒ 5HYRNH 2%-235IURPWKHSK\VLFDOILOHV7KLVSUHYHQWVXVHUVIURP
DFFHVVLQJWKHSK\VLFDOILOHVGLUHFWO\

ƒ *UDQWWKHDSSURSULDWHGDWDDXWKRULWLHVWRORJLFDOILOHV5HYRNHDQ\DXWKRULWLHV
\RXGRQRWZDQW

ƒ *UDQW 2%-235WRWKHORJLFDOILOHV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-24. Securing physical versus logical files (2 of 2)

The IBM i command RVKOBJAUT can be used to revoke the users specific authority for an object.
The IBM i command GRTOBJAUT can be used to grant the users specific authority for an object.

© Copyright IBM Corp. 1995, 2017 8-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

&UHDWH2XWSXW4XHXH6HFXULW\DWWULEXWHVEH\RQGUHVRXUFH
VHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-25. Create Output Queue: Security attributes beyond resource security

In order to make changes to spool files the user must either be the owner of that spool file or have
spool control authority (*SPLCTL) assigned to their user profile.
The optional parameters that can be specified when create an output queue are:
DSPDTA: Specifies whether users who have authority to read the output queue can display the
output data of any spooled file on the queue or only the data in their own files.
*NO (default): Users authorized to use the queue can display, copy, or send the output of their own
files only unless they have some other special authority.
*YES: Any user having the authority to read the queue can display, copy, or send the data of any file
on the queue.
*OWNER: The owner of the file or a user with *SPLCTL special authority can display, copy, or send
the spooled files on the queue.
AUTCHK: Specifies whether the commands that check the requestor's authority to the queue also
check for ownership authority or data authority.
*OWNER (default): The requestor must have ownership authority to the output queue in order to
pass the output queue authorization test. The requestor can have ownership authority by program
that adopts the owner's authority.

© Copyright IBM Corp. 1995, 2017 8-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
*DTAAUT: The requestor must have the appropriate data authority to the output queue (*READ,
*ADD and *DELETE) in order to pass the output queue authority.
OPRCTL: Specifies whether a user who has SPCAUT(*JOBCTL) is allowed to manage or control
the files on this queue.
*YES (default): A user with job control special authority can control the queue and make changes to
the files on the queue.
*NO: This queue and its files cannot be controlled or changed by users with job control special
authority unless they also have some other special authority.

© Copyright IBM Corp. 1995, 2017 8-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

$XWKRULW\UHTXLUHGWRSHUIRUPSULQWLQJIXQFWLRQV
2XWSXWTXHXH 6SHFLDO
3ULQWLQJIXQFWLRQ DSPDTA AUTCHK OPRCTL
DXWKRULW\ DXWKRULW\

$Q\ $Q\ $Q\ *READ 1RQH


$GGVSRROHGILOHVWRTXHXH
$Q\ $Q\ *YES $Q\ JOBCTL

9LHZOLVWRIVSRROHGILOHV $Q\ $Q\ $Q\ *READ 1RQH


WRKOUTQ FRPPDQG  $Q\ $Q\ YES $Q\ JOBCTL

*YES $Q\ $Q\ *READ 1RQH


*NO *DTAAUT $Q\ *CHANGE 1RQH
'LVSOD\FRS\RUVHQGVSRROHGILOHV *NO *Owner $Q\ 2ZQHU 1RQH
DSPSPLF, CPYSPLF, SNDNETSPLF, *YES
SNDTCPSPLF  $Q\ *YES $Q\ *JOBCTL
*NO $Q\ *YES $Q\ *JOBCTL
2ZQHU $Q\ $Q\ $Q\ $Q\

&KDQJHGHOHWHKROGDQGUHOHDVHVSRROHG $Q\ *DTAAUT $Q\ CHANGE 1RQH


ILOH CHGSPLFA, DLTSPLF, HLDSPLF, $Q\ *OWNER $Q\ 2ZQHU 1RQH
RLSSPLF  $Q\ $Q\ YES $Q\ JOBCTL

&KDQJHFOHDUKROGDQGUHOHDVHRXWSXW $Q\ *DTAAUT $Q\ *CHANGE 1RQH


TXHXH CHGOUTQ, CLROUTQ, HLDOUTQ, $Q\ *OWNER $Q\ 2ZQHU 1RQH
RLSOUTQ  $Q\ $Q\ YES $Q\ *JOBCTL

6WDUWDZULWHUIRUWKHTXHXH $Q\ *DTAAUT $Q\ CHANGE 1RQH


STRPRTWTR, STRRMTWTR $Q\ $Q\ *YES $Q\ *JOBCTL

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-26. Authority required to perform printing functions

The table shows what combination of output queue parameters and authority to the output queue is
required to perform print management functions on the system.
For example, in the first block in the visual in order to add a spool file to an output queue the
conditions that must be met are either:
1. The output queue was created with any value specified for the parameters DSPDTA, AUTCHK,
OPRCTL, and the user has *READ authority to that output queue and there is no special
authority required.
2. The output queue was created with any value specified for the parameters DSPDTA and
AUTCHK, and for the parameter OPRCTL it was set to *YES and the user can have any authority
to that output queue and must have the *JOBCTL special authority assigned to their profile.

© Copyright IBM Corp. 1995, 2017 8-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

/LPLWDFFHVVWRSURJUDPIXQFWLRQ
‡ <RXKDYHWKHDELOLW\WRVHFXUH
DSRUWLRQRIDQDSSOLFDWLRQ
SURJUDP

‡ 7KLVLVLPSOHPHQWHGWKURXJK
,%01DYLJDWRUIRUL
$SSOLFDWLRQ$GPLQLVWUDWLRQRU
8VHUVDQG*URXSV

‡ %ORFNVRIDSSOLFDWLRQFRGH
PXVWEHUHJLVWHUHG

‡ $SSOLFDWLRQFRGHFDOOVDQ$3,
WRFKHFNVHFXULW\IRUWKHXVHU
EHIRUHLWFDOOVWKHFRGHEORFN

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-27. Limit access to program function

The limit access to program function allows you to provide security to some portion of an
application program when you do not have a IBM i object to secure. You could accomplish this by
creating an authorization list or other object and checking the authority to the object to control
access to the program function. Now, you can use the limit access to program function to more
easily control access to an application, parts of an application, or functions within a program.
There are two methods that you can use to manage user access to application functions through
IBM Navigator for i. The first way use Users and Groups support (top picture on the visual)
1. On the web browser type [Link] or system name>:2001 and press Enter
key.
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand User and Groups.
4. Click Users.
5. On the main pane right-click the selected user and from pop-up menu choose Application
Administration.

© Copyright IBM Corp. 1995, 2017 8-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
The second way is use Application Administration support (bottom picture).
1. On the web browser type [Link] or system name>:2001 and press Enter
key
2. Log on with your user name and password.
3. On the left pane under IBM i Management expand Security.
4. Click Application Administration.
5. On the main pane make required changes.
If you are an application writer, you can use limit access to program function APIs to do the
following:
• Register a function
• Retrieve information about the function
• Define who can or cannot use the function
• Check to see whether the user is allowed to use the function
This support is not a replacement for resource security. The limit access to program function does
not prevent a user from accessing a resource (such as a file or program) from another interface.
To use this support within an application, the application provider must register the functions when
the application is installed. The registered function corresponds to a code block for specific
functions in the application. When the application is run by the user, the application calls the API
before the application calls the code block. The API calls the check usage API to see whether the
user is allowed to use the function. If the user is allowed to use the registered function, the code
block is run. If the user is not allowed to use the function, the user is prevented from running the
code block.
The system administrator specifies who is allowed or denied access to a function. The
administrator can either use the API to manage the access to program function or use the IBM
Navigator for i Application Administration GUI. The IBM i Knowledge Center provides information
about the limit access to program function APIs at
[Link]

© Copyright IBM Corp. 1995, 2017 8-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

$XWKRULW\WRZRUNVWDWLRQ RI
• QLMTSECOFR PHDQV ALLOBJ DQG SERVICE XVHUVDUHOLPLWHGWRVSHFLILF
GHYLFHV
• QSECOFRQSRVFDQ DOZD\VVLJQRQDWWKHFRQVROH
‡ 7KHQCONSOLE V\VWHPYDOXHLVXVHGWRGHWHUPLQHZKLFKGHYLFHLVFRQVROH
CHANGE
'HWHUPLQHXVHU V RU ,VQSECURITY 1R
DXWKRULW\WR JUHDWHU !"
:RUNVWDWLRQ
<HV
/HVVWKDQ 'RHVXVHUKDYH
CHANGE 1R
ALLOBJ RU
SERVICE"
6LJQRQIDLOV
<HV

,VQLMTSECOFR 1R
"

$
$OORZVLJQRQ

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-28. Authority to workstation (1 of 2)

In certain installations, it can be a security exposure to allow the security officer to sign on any
workstation. QLMTSECOFR makes it easy to control this.
The authority to Workstation actually means: the authority to the Device Description describing the
defined workstation.

© Copyright IBM Corp. 1995, 2017 8-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

$XWKRULW\WRZRUNVWDWLRQ RI
$
/HVVWKDQ CHANGE
7HVWXVHU V
CHANGE RUJUHDWHU
DXWKRULW\WR
ZRUNVWDWLRQ
1RDXWKRULW\
/HVVWKDQ CHANGE
7HVWJURXSV RUJUHDWHU
CHANGE
DXWKRULW\WR
ZRUNVWDWLRQ
1RDXWKRULW\
'RHVXVHUKDYH
<HV
SERVICE EXW
QRW ALLOBJ"
1R
1R 'RHVQSECOFR
KDYH CHANGE
RUJUHDWHU"
<HV
6LJQRQIDLOV $OORZVLJQRQ

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-29. Authority to workstation (2 of 2)

The authority to Workstation actually means: The authority to the Device Description describing the
defined workstation.

© Copyright IBM Corp. 1995, 2017 8-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

'DWDHQFU\SWLRQ
‡ 'LVNHQFU\SWLRQSURWHFWV
ƒ 'DWDWUDQVPLVVLRQWRDQGIURPWKHGLVNGULYH
ƒ 'DWDWUDQVPLVVLRQLQWKHFURVVVLWHPLUURULQJHQYLURQPHQW
ƒ 'DWDLQWKHFDVHRIWKHIWRIWKHGLVNGULYH

‡ '%FROXPQHQFU\SWLRQ VLQFHL
ƒ (QKDQFHGGDWDVHFXULW\

‡ 7DSHHQFU\SWLRQ
ƒ 6RIWZDUH
ƒ +DUGZDUH

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-30. Data encryption

Disk encryption: In order to use disk encryption, you must have 5770-SS1 Option 45 - Encrypted
ASP Enablement installed. The option to enable encryption is available when you create a disk pool
or independent disk pool. If disk encryption is used in a clustering environment, you must set the
master key manually on each system within the device domain. Independent disk pools must be
created using IBM Navigator for i. The character-based interface (5250 emulation) can be also
used for setup ASP and disk encryption setup. Disk encryption can be used to encrypt existing disk
pools or independent disk pools. Starting disk encryption on an existing disk pool might take an
extended amount of time to encrypt the data in the disk pool, potentially affecting system
performance. Reference:
[Link]
Column encryption: To enhance data security, column encryption can be accomplished by using a
new database feature called field procedures. A field procedure is a user-written exit routine to
transform values in a single column. When values in the column are changed, or new values
inserted, the field procedure is invoked for each value, and can transform that value (encode it) in
any way. The encoded value is then stored. When values are retrieved from the column, the field
procedure is invoked for each value, which is encoded, and must decode it back to the original
value. Reference:
[Link]

© Copyright IBM Corp. 1995, 2017 8-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
Tape encryption: Tape encryption provides security and reduces the risk of data being misused.
After a tape is encrypted, data is unreadable to people without a key. Software tape encryption: Use
the products and applications that are described to encrypt your data.
Hardware tape encryption: Hardware tape encryption uses tape devices with data encryption
capabilities and the IBM Security Key Lifecycle Manager to encrypt your data. The IBM i only
supports library managed encryption.
Decrypting your data: There are two methods available to read or restore tape data that was
previously encrypted.
• If the products and applications used for software tape encryption are installed on your partition,
your tape management application can specify the encryption keystore file and record label
information for each file that is to be decrypted.
• Use a decryption data area to specify the encryption keystore file and record label information
to be used to decrypt your tapes. The data area must be named QTADECRYPT and can be
created in either library QTEMP or QUSRSYS. The data area must provide the following
information.
▪ Device name (Decryption will only be run for tapes in this device)
▪ Encryption keystore file name
▪ Encryption keystore library
▪ Encryption record label
More information at:
[Link]

© Copyright IBM Corp. 1995, 2017 8-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
8.4. Topic 4: Security save and restore
considerations

© Copyright IBM Corp. 1995, 2017 8-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

7RSLF6HFXULW\VDYHDQG
UHVWRUHFRQVLGHUDWLRQV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-31. Topic 4: Security save and restore considerations

© Copyright IBM Corp. 1995, 2017 8-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

5HVWULFWLQJVDYHDQGUHVWRUHRSHUDWLRQV
‡ <RXFDQFRQWUROWKHDELOLW\WRVDYHDQGUHVWRUHREMHFWVLQVHYHUDOZD\V
ƒ 5HVWULFWSK\VLFDODFFHVVWRVDYHDQGUHVWRUHGHYLFHV
í 3K\VLFDOWDSHXQLWV
í 2SWLFDOXQLWV

ƒ 5HVWULFWDXWKRULW\WRWKHGHYLFHGHVFULSWLRQVREMHFWVIRUWKHVDYHDQGUHVWRUH
GHYLFHV DQGWKHFRPPDQGVXVHGWRFUHDWHWKHVH 

ƒ 5HVWULFWDXWKRULW\WRXVHWKHVDYHDQGUHVWRUHFRPPDQGV

ƒ 2QO\JLYH 6$96<6VSHFLDODXWKRULW\WRWUXVWHGXVHUV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-32. Restricting save and restore operations

You can restrict the ability to save objects from your system or restore objects to your system.

© Copyright IBM Corp. 1995, 2017 8-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

%DFNXSDQGUHFRYHU\RIVHFXULW\LQIRUPDWLRQ

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-33. Backup and recovery of security information

Saving your security information is just as important as saving your data. In some situations, you
might need to recover user profiles, object authorities, and the data on your system. If you do not
have your security information saved, you might need to manually rebuild user profiles and object
authorities. This can be time-consuming and can lead to errors and security exposures.
This table shows the commands used to save and restore security information.
Security information is stored differently on the save media than it is on your system. When you
save user profiles, the private authority information stored with the user profile is formatted into an
authority table.
An authority table is built and saved for each user profile that has private authorities. This
reformatting and saving of security information can be lengthy if you have many private authorities
on your system.
Visual indexes meaning:
1
The SAVSECDTA, SAVSYS, and RSTUSRPRF commands save and restore ownership, primary
group, primary group authority, and public authority for these object types: User profile (*USRPRF),
Authorization list (*AUTL), and Authority holder (*AUTHLR). 2 The object to save/restore is
QUSEXRGOBJ, type *EXITRG in QUSRSYS library. 3 Private authorities for all objects are saved
with SAVSECDTA. RSTUSRPRF restores the authority information needed to restore the private

© Copyright IBM Corp. 1995, 2017 8-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
authorities. The private authorities are restored with RSTAUT. Private authorities for individual
objects can be saved with the SAV, SAVLIB, SAVOBJ, and SAVCHGOBJ commands. Private
authorities for individual objects can be restored with the RST, RSTLIB, and RSTOBJ commands if
they were saved with the save command.

© Copyright IBM Corp. 1995, 2017 8-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

$XWKRULW\LQIRUPDWLRQVDYHGZLWKDQREMHFW
‡ 3XEOLFDXWKRULW\
‡ 2ZQHUQDPH
‡ 2ZQHU¶VDXWKRULW\WRREMHFW
‡ 3ULPDU\JURXSQDPH
‡ 3ULPDU\JURXS¶VDXWKRULW\WRREMHFW
‡ $XWKRUL]DWLRQOLVWQDPH
‡ )LHOGOHYHODXWKRULWLHV
‡ 2EMHFWDXGLWLQJYDOXH
‡ :KHWKHUDQ\SULYDWHDXWKRULW\H[LVWV
‡ :KHWKHUDQ\SULYDWHDXWKRULW\LVOHVVWKDQSXEOLF
‡ 3ULYDWHDXWKRULWLHVIRUWKHREMHFWLIPVTAUT(*YES) LVVSHFLILHGRQWKH
SAVxxx FRPPDQG

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-34. Authority information saved with an object

© Copyright IBM Corp. 1995, 2017 8-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

2WKHUDXWKRULW\LQIRUPDWLRQWKDWLVVDYHG
‡ $XWKRULW\LQIRUPDWLRQVDYHGZLWKDXWKRUL]DWLRQOLVW
ƒ 1RUPDODXWKRULW\LQIRUPDWLRQVWRUHGZLWKDQ\REMHFWVXFKDVWKHSXEOLFDXWKRULW\
RZQHUDQGSULPDU\JURXS
‡ $XWKRULW\LQIRUPDWLRQVDYHGZLWKXVHUSURILOH
ƒ 8VHUSURILOHDWWULEXWHVVKRZQRQWKH&UHDWH8VHU3URILOHGLVSOD\
ƒ 2WKHUDSSOLFDWLRQLQIRUPDWLRQDVVRFLDWHGZLWKWKHXVHUSURILOHIRUH[DPSOH
í 6HUYHUDXWKHQWLFDWLRQHQWULHV
í 8VHUDSSOLFDWLRQLQIRUPDWLRQHQWULHVWKDWDUHDGGHGXVLQJWKH8SGDWH8VHU
$SSOLFDWLRQ,QIRUPDWLRQ 4V\8SGDWH8VHU$SSOLFDWLRQ,QIR $3,
‡ $XWKRULW\WDEOHVDYHGDVVRFLDWHGZLWKXVHUSURILOH
ƒ 2QHUHFRUGIRUHDFKSULYDWHDXWKRULW\RIWKHXVHUSURILOHLQFOXGLQJXVDJHVHWWLQJV
IRUUHJLVWHUHGIXQFWLRQV
‡ )XQFWLRQUHJLVWUDWLRQLQIRUPDWLRQVDYHGZLWKQUSEXRGOBJ REMHFW
ƒ 7KHIXQFWLRQUHJLVWUDWLRQLQIRUPDWLRQVDYHGE\VDYLQJWKHQUSEXRGOBJ *EXITRG
REMHFWLQQUSRSYS

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-35. Other authority information that is saved

© Copyright IBM Corp. 1995, 2017 8-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

5HVWRULQJSURJUDPVZLWKUHVWULFWHGLQVWUXFWLRQV
‡ 9DOLGDWLRQYDOXHVWRUHGZLWKSURJUDPDQGFKHFNHGZKHQUHVWRUHG
‡ 5HVWRUHDFWLRQVIRULQYDOLGSURJUDPV
ƒ 5HFUHDWHSURJUDP
ƒ (QWU\LQQAUDJRN
ƒ 0HVVDJHLQMREORJ
ƒ 2ZQHUVKLSWR4')72:1
ƒ 5HYRNHDXWKRULW\
• QSECURITY RU DQGALWOBJDIF DIIHFWUHVWRUHDFWLRQV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-36. Restoring programs with restricted instructions

© Copyright IBM Corp. 1995, 2017 8-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
8.5. Topic 5: Security Tools

© Copyright IBM Corp. 1995, 2017 8-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

7RSLF6HFXULW\7RROV

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-37. Topic 5: Security Tools

© Copyright IBM Corp. 1995, 2017 8-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULW\7RROV RI
‡ $GGLWLRQDO,%0L FRPPDQGVWRKHOS\RXPDQDJHVHFXULW\
ƒ $YDLODEOHWKURXJK
í ,QGLYLGXDOFRPPDQG
í 6(&722/6 PHQX FRPPDQGVUXQLQWHUDFWLYHO\
í 6(&%$7&+ PHQX UHSRUWFRPPDQGVVXEPLWWHGRUVFKHGXOHG
ƒ :RUNZLWKSURILOHV 6(&722/6
í 'LVDEOHXVHUVGXULQJVSHFLILHGSHULRGV
í 'HOHWHRUGLVDEOHDXVHURQDVSHFLILFGDWH
í 'LVDEOHSURILOHDIWHUFHUWDLQLQDFWLYLW\SHULRG
í $QDO\]HSURILOHIRUGHIDXOWSDVVZRUGV
ƒ :RUNZLWKDXGLWLQJ 6(&722/6
í 2QHVWHSVHWXS
í 'LVSOD\DXGLWLQJV\VWHPYDOXHV
ƒ 6HFXULW\UHSRUWV 6(&722/6DQG6(&%$7&+

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-38. Security tools

The SECTOOLS (Security Tools) menu, the SECBATCH (Submit or Schedule Security Reports to
Batch) menu, the Configure System Security (CFGSYSSEC) and Revoke Public Authority
(RVKPUBAUT) commands are four security tools you can use to configure your system security.
Two menus are available for security tools:
a. The SECTOOLS (Security Tools) menu to run commands interactively.
b. The SECBATCH (Submit or Schedule Security Reports to Batch) menu to run the report
commands in batch. The SECBATCH menu has two parts. The first part of the menu uses
the Submit Job (SBMJOB) command to submit reports for immediate processing in batch.
The second part of the menu uses the Add Job Schedule Entry (ADDJOBSCDE) command. You use
it to schedule security reports to be run regularly at a specified day and time.

© Copyright IBM Corp. 1995, 2017 8-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULW\7RROV RI

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-39. Security Tools (1 of 4)

The Security Tools (SECTOOLS) menu simplifies the management and control of the security on
your system.
Option 1. Analyze default passwords (ANZDFTPWD)
Select this option to print a report containing all the user profiles on the system that have a default
password and to optionally take an action against those profiles.
Option 2. Display active profile list (DSPACTPRFL)
Select this option to display a list of user profiles that are always considered active and are not
disabled by the Analyze Profile Activity (ANZPRFACT) command. The list of user profiles is
maintained by using the Change Active Profile List (CHGACTPRFL) command.
Option 3. Change active profile list (CHACTPRFL)
Select this option to add or remove user profiles from the list of profiles that are always considered
active. The profiles in this list are never disabled by the Analyze Profile Activity (ANZPRFACT)
command.
The current list of active user profiles can be displayed using the Display Active Profile List
(DSPACTPRFL) command.

© Copyright IBM Corp. 1995, 2017 8-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
Option 4. Analyze profile activity (ANZPRFACT)
Select this option to disable user profiles that have been inactive for the specified number of days.
User profiles can be excluded from this processing by using the Change Active Profile List
(CHGACTPRFL) command to maintain a list of profiles that will always be considered active.
The current list of active user profiles can be displayed using the Display Active Profile List
(DSPACTPRFL) command.
Option 5. Display activation schedule (DSPACTSCD)
Select this option to display a list of user profiles, the enable time, disable time, and the days on
which the enable and disable jobs are submitted. The profile activation schedules are managed
using the Change Activation Schedule Entry (CHGACTSCDE) command.
Option 6. Change activation schedule entry (CHGACTSCDE)
Select this option to manage a scheduled job that activates a user profile for a period of time on
specific days.
The current profile activation schedule can be displayed using the Display Activation Schedule
(DSPACTSCD) command.
Option 7. Display expiration schedule (DSPEXPSCD)
Select this option to display a list of user profiles, the expiration date, and the expiration action to be
taken (disable or delete the profile). The profile expiration schedules are managed using the
Change Expiration Schedule Entry (CHGEXPSCDE) command.
Option 8. Change expiration schedule entry (CHGEXPSCDE)
Select this option to manage a scheduled job that changes a user profile to expire on a certain date
and to take an action against the expired user profile (disable or delete).
The current profile expiration schedule can be displayed using the Display Expiration Schedule
(DSPEXPSCD) command.
Option 9. Print profile internals (PRTPRFINT)
Select this option to print a report of internal information on the number of entries in a user profile
(*USRPRF) object. The number of entries in a profile determines its size. The Print Profile Internals
(PRTPRFINT) command determines how full a user profile (*USRPRF) object is based on the
number of entries it contains. For more details, refer to the help for the PRTPRFINT.

© Copyright IBM Corp. 1995, 2017 8-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULW\7RROV RI

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-40. Security Tools (2 of 4)

Option 10. Change security auditing (CHGSECAUD)


Select this option to change the current settings of the system values that control what is being
audited on the system. Current audit information can be displayed using the Display Security
Auditing (DSPSECAUD) command.
Option 11. Display security auditing (DSPSECAUD)
Select this option to display the current information about the security audit journal and the current
settings for the system values that control what is being audited on the system.
Option 12. Copy audit journal entries
Select this option to copy security audit journal entries from the security audit journal (QAUDJRN)
into one or more outfiles reports.
Option 20. Submit or schedule security reports (SECBATCH)
Select this option to submit one or more security reports to a job queue to be run later as a batch
job or to schedule batch jobs to submit security reports at regular intervals
Option 21. Adopting objects (PRTADPOBJ)
Select this option to print a report of the objects that adopt the special and private authorities of a
specified user profile.

© Copyright IBM Corp. 1995, 2017 8-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty
Option 22. Audit journal entries (DSPAUDJRNE)
Select this option to generate a security journal audit report. The report is based on specified audit
entry types and specified user profiles and can be limited to specific dates and times. The report
can optionally be displayed or printed.
Option 23. Authorization list authorities (PRTPVTAUT)
Select this option to print a report containing all authorization lists on the system and the users that
are authorized to each authorization list.
Option 24. Command authority (PRTPUBAUT)
Select this option to print a list of commands (*CMD) in a library that does not have public authority
of *EXCLUDE.
Option 25. Command private authority (PRTPVTAUT)
Select this option to print a report containing all commands in a specified library and the users that
are authorized to each command.
Option 26. Communications security (PRTCMNSEC)
Select this option to print a report containing security information about the communications
configuration on the system.

© Copyright IBM Corp. 1995, 2017 8-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULW\7RROV RI

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-41. Security Tools (3 of 4)

Option 27. Directory private authority (PRTPVTAUT)


Select this option to print a report containing all directories on the system and the users that are
authorized to each directory.
Option 28. Document authority (PRTPUBAUT)
Select this option to print a list of documents (*DOC) in a folder that do not have public authority of
*EXCLUDE.
Option 29. Document private authority (PRTPVTAUT)
Select this option to print a report containing all documents in a specified folder and the users that
are authorized to each document.
Option 30. File authority (PRTPUBAUT)
Select this option to print a list of files (*FILE) in a library that does not have public authority of
*EXCLUDE.
Option 31. File private authority (PRTPVTAUT)
Select this option to print a report containing all files in a specified library and the users that are
authorized to each file.

© Copyright IBM Corp. 1995, 2017 8-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

Option 32. Folder authority (PRTPUBAUT)


Select this option to print a list of folders (*FLR) on the system that does not have public authority of
*EXCLUDE.
Option 33. Folder private authority (PRTPVTAUT)
Select this option to print a report containing all folders on the system and the users that are
authorized to each folder.
Option 34. Job description authority (PRTJOBDAUT)
Select this option to print a list of job descriptions in a specified library that do not have public
authority of *EXCLUDE, and that also have a user name specified in the job description.
Option 35. Library authority (PRTPUBAUT)
Select this option to print a list of libraries (*LIB) on the system that does not have public authority of
*EXCLUDE. You can also choose to print a list of specified object types within the listed libraries
that do not have public authority of *EXCLUDE.
Option 36. Library private authority (PRTPVTAUT)
Select this option to print a report containing all libraries on the system and the users that are
authorized to each library.
Option 37. Object authority (PRTPUBAUT)
Select this option to print a list of specified object types that do not have public authority of
*EXCLUDE.
Option 38. Private authority (PRTPVTAUT)
Select this option to print a list of specified object types and the private authorities for each object.
Option 39. Program authority (PRTPUBAUT)
Select this option to print a list of programs (*PGM) in a library that does not have public authority of
*EXCLUDE. Only programs that a user can call and do not have public authority of *EXCLUDE, are
included in this list.
Option 40. Program private authority (PRTPVTAUT)
Select this option to print a report containing all programs in a specified library and the users that
are authorized to each program.

© Copyright IBM Corp. 1995, 2017 8-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

6HFXULW\7RROV RI

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-42. Security Tools (4 of 4)

Option 41. User profile authority (PRTPUBAUT)


Select this option to print a list of user profiles on the system that do not have public authority of
*EXCLUDE.
Option 42. User profile private authority (PRTPVTAUT)
Select this option to print a report containing all user profiles on the system and the users that are
authorized to each user profile.
Option 43. Job and output queue authority (PRTQAUT)
Select this option to generate a report containing output queue and job queue authority information
for objects in a specified library.
Option 44. Subsystem authority (PRTSBSDAUT)
Select this option to print a list of subsystem descriptions in a library that contain a default user in a
communications entry.
Option 45. System security attributes (PRTSYSSECA)
Select this option to print a report containing security-related system values and network attributes
to a spooled file. The report includes the current values and the recommended values.

© Copyright IBM Corp. 1995, 2017 8-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

Option 46. Trigger programs (PRTTRGPGM)


Select this option to print a list of programs that have been defined as trigger programs for the
physical files in a specified library.
Option 47. User objects (PRTUSROBJ)
Select this option to print a list of objects in a specified library that are not created by IBM.
Option 48. User profile information (PRTUSRPRF)
Select this option to print a report containing information about all the user profiles on the system.
You can specify to include authority information, environment information, password information, or
*ALL information about selected user profiles.
Option 60. Configure system security (CFGSYSSEC)
Select this option to activate the security features on your system. This option does the following:
• Turn on security auditing
• Change system values
• Modify system-supplied user profiles
Only select this option if you know what features are being activated.
To determine what security features are activated, issue the Retrieve CL Source (RTVCLSRC)
command against the program QSECCFGS and examine the source file created.
Option 61. Revoke public authority to objects (RVKPUBAUT)
Select this option to limit the use of commands and programs on your system. This option changes
the public authority of certain commands and programs to *EXCLUDE. Only select this option if you
know what commands and programs have their public authority changed.
To determine what command and program authorities are changed, issue the Retrieve CL Source
(RTVCLSRC) command against the program QSECRVKP and examine the source file created.
Option 62. Check object authority (CHKOBJITG)
Select this option to check all objects owned by a specified user profile to determine whether any
objects have been altered, thereby creating an integrity violation. If an integrity violation has
occurred, the object name, library, object type, object owner, and type of failure are logged to a
specified database file
At the next page we only find: Option 80. Related security tasks (SECURITY)
Select this option to use additional commands related to security on your system. This directs you
to the IBM i Security menu.

© Copyright IBM Corp. 1995, 2017 8-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH,WLVUHFRPPHQGHGWKDW\RXRQO\VHFXUHWKRVHREMHFWV
WKDWUHTXLUHVHFXULQJ

 7UXHRUIDOVH$FFHVVWRREMHFWVFDQQRWEHVSHFLILHGDWWKHOLEUDU\
OHYHO

 7UXHRUIDOVH,WLVSRVVLEOHWRFRQWUROZKHWKHUDXVHUKDVDFFHVVWR
DFRPPDQGOLQH

 7UXHRUIDOVH<RXFDQQRWOLPLWDFFHVVWRWKH6\VWHP5HTXHVW
VFUHHQ

 7UXHRUIDOVH<RXFDQGHILQH$63HQFU\SWLRQWKURXJK
LQWHUIDFH

 7KHPRVWJUDQXODUVHFXULW\WKDW\RXFDQVSHFLI\LV
D /LEUDU\
E 8VHU
F 2EMHFW
G 3URJUDPOHYHO

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-43. Review questions

© Copyright IBM Corp. 1995, 2017 8-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH,WLVUHFRPPHQGHGWKDW\RXRQO\VHFXUHWKRVHREMHFWVWKDWUHTXLUH
VHFXULQJ
7KHDQVZHULVWUXH

 7UXHRUIDOVH$FFHVVWRREMHFWVFDQQRWEHVSHFLILHGDWWKHOLEUDU\OHYHO
7KHDQVZHULVIDOVH

 7UXH RUIDOVH,WLVSRVVLEOHWRFRQWUROZKHWKHUDXVHUKDVDFFHVVWRDFRPPDQGOLQH
7KHDQVZHULVWUXH

 7UXHRUIDOVH<RXFDQQRWOLPLWDFFHVVWRWKH6\VWHP5HTXHVWVFUHHQ
7KHDQVZHULVIDOVH

 7UXH RUIDOVH<RXFDQGHILQH$63HQFU\SWLRQWKURXJKLQWHUIDFH
7KHDQVZHULVWUXH

 7KHPRVWJUDQXODUVHFXULW\WKDW\RXFDQVSHFLI\LV
D /LEUDU\
E 8VHU
F 2EMHFW
G 3URJUDPOHYHO
7KHDQVZHULVREMHFW
'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-44. Review answers

© Copyright IBM Corp. 1995, 2017 8-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 8. Designing security

Uempty

8QLWVXPPDU\
‡ /LVWVRPHUHFRPPHQGDWLRQVIRUVHFXULW\GHVLJQ
‡ 'LVFXVVWKHFRQFHSWRILPSOHPHQWLQJOLEUDU\VHFXULW\
‡ 'LVFXVVVRPHGHVLJQJXLGHOLQHVWRNHHSLQPLQGZKHQLPSOHPHQWLQJ
PHQXVHFXULW\
‡ 'HVFULEHWKHSURFHVVXVHGE\WKHV\VWHPIRUVLJQRQSURFHVVLQJ
‡ ([SODLQWKHIXQFWLRQVSURYLGHGE\WKH6\VWHP5HTXHVWVFUHHQDQGKRZ
WRVHFXUHWKLVVFUHHQRUWKHVFUHHQRSWLRQV
‡ 'LVFXVVWKHFRQFHSWVRILPSOHPHQWLQJREMHFWVHFXULW\
‡ /LVWDQGGLVFXVVWKHFRPPDQGVXVHGWREDFNXSDQGUHFRYHUVHFXULW\
LQIRUPDWLRQ
‡ 'HVFULEHWKHVHFXULW\WRROVWKDWDUHDYDLODEOHWRDVVLVW\RXZLWKWKH
LPSOHPHQWDWLRQRIVHFXULW\

'HVLJQLQJVHFXULW\ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 8-45. Unit summary

© Copyright IBM Corp. 1995, 2017 8-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

Unit 9. IBM Power Systems with IBM i:


Availability overview
Estimated time
02:00

Overview
This overview is designed to emphasize the importance of a good recovery plan by reviewing the
potential for failures that can occur on a system and the hardware and software availability
features.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 9-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8QLWREMHFWLYHV
‡ ([SODLQWKHFRQFHSWRIDYDLODELOLW\
‡ 'HVFULEHWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXU
‡ 'HVFULEHKDUGZDUHDQGVRIWZDUHDYDLODELOLW\IHDWXUHV
‡ ([SODLQWKHFRQFHSWRIORJLFDOSDUWLWLRQLQJ /3$5
‡ ([SODLQWKHFRQFHSWRIDYDLODELOLW\
‡ 'HVFULEHWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXU
‡ 'HVFULEHKDUGZDUHDQGVRIWZDUHDYDLODELOLW\IHDWXUHV
‡ ([SODLQWKHFRQFHSWRIORJLFDOSDUWLWLRQLQJ /3$5
‡ /LVWVRPHRIWKHUHDVRQVWRLPSOHPHQWORJLFDOSDUWLWLRQV
‡ ([SODLQWKHIXQFWLRQVVHUYHGE\D+DUGZDUH0DQDJHPHQW&RQVROH +0&
‡ ([SODLQWKHFRQFHSWRIFOXVWHULQJ
‡ ([SODLQ3RZHU+$6\VWHP0LUURU
‡ /LVWWKHGLIIHUHQWW\SHVRI3RZHU+$VROXWLRQV
‡ 'HVFULEHWKHFRQVHTXHQFHVIRUDFRPSDQ\LIWKH6\VWHP,%0LDUHQRWDYDLODEOH
WRSHUIRUPQRUPDOEXVLQHVV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 9-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
9.1. Topic 1: Availability concepts and overview

© Copyright IBM Corp. 1995, 2017 9-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLF$YDLODELOLW\FRQFHSWV
DQGRYHUYLHZ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-2. Topic 1: Availability concepts and overview

© Copyright IBM Corp. 1995, 2017 9-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

$YDLODELOLW\FRQFHSWV
‡ &RQFHSWVWRNQRZDQGXQGHUVWDQGWKDWDUHDVVRFLDWHGZLWKDYDLODELOLW\
ƒ %XVLQHVVFRQWLQXLW\
ƒ 'LVDVWHUUHFRYHU\
ƒ +LJKDYDLODELOLW\
ƒ %DFNXSZLQGRZ
ƒ $QXQSODQQHGRXWDJH
ƒ +LJKDYDLODELOLW\VROXWLRQV
ƒ $FOXVWHU

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-3. Availability concepts

Before you plan for the availability of your system, it is important for you to understand some of the
concepts associated with availability. Businesses and their IT operations that support them must
determine which solutions and technologies address their business needs. In the case of business
continuity requirements, detailed business continuity requirements must be developed and
documented, the solution types must be identified, and the solution choices must be evaluated.
Business continuity is the capability of a business to withstand outages, which are times when the
IBM Power System with IBM i is unavailable, and to operate important services normally and
without interruption in accordance with predefined service-level agreements. To achieve a given
level of business continuity, a collection of services, software, hardware, and procedures must be
selected, described in a documented plan, implemented, and practiced regularly. The business
continuity solution must address the data, the operational environment, the applications, the
application hosting environment, and the user interface. All must be available to deliver a good,
complete business continuity solution. Your business continuity plan includes disaster recovery
(DR) and high availability (HA).
Disaster recovery provides a plan in the event of a complete outage at the production site of your
business, such as during a natural disaster. Disaster recovery provides a set of resources, plans,
services, and procedures used to recover important applications and to resume normal operations
from a remote site. This disaster recovery plan includes a stated disaster recovery goal (for
example, resume operations within 8 hours) and addresses acceptable levels of degradation.

© Copyright IBM Corp. 1995, 2017 9-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
High availability is another major aspect of business continuity goals for many customers. High
availability is the ability to withstand all outages (planned, unplanned, and disasters) and to provide
continuous processing for all important applications. The ultimate goal is for the outage time to be
less than .001% of the total service time. The differences between high availability and disaster
recovery typically include more demanding recovery time objectives (seconds to minutes) and more
demanding recovery point objectives (zero user disruption).
Availability is measured in terms of outages, which are periods of time when the IBM Power System
with IBM i is not available to users. During a planned outage (also called a scheduled outage), you
deliberately make your system unavailable to users. You might use a scheduled outage to run
batch work, back up your system, or apply fixes.
Backup window is the amount of time that your system can be unavailable to users while you
perform your backup operations. Your backup window is a scheduled outage that typically occurs in
the night or on a weekend when your system has less traffic.
An unplanned outage, also called an unscheduled outage, is typically caused by a failure. You can
recover from some unplanned outages (such as disk failure, system failure, power failure, program
failure, or human error) if you have an adequate backup strategy. However, an unplanned outage
that causes a complete system loss, such as a tornado or fire, requires you to have a detailed
disaster recovery plan in place in order to recover.
High availability solutions can provide fully automated failover to a backup system to ensure
continuous operation for users and applications. These HA solutions must provide an immediate
recovery point and ensure that the time of recovery is faster than a non-HA solution. Unlike with
disaster recovery, where entire systems experience an outage, high availability solutions can be
customized to individual critical resources within a system; for example, a specific application
instance. High availability solutions are based on cluster technology. You can use clusters to avoid
the impacts of both planned and unplanned outages. Even though you still have an outage, the
business function is not impacted by the outage.
A cluster is a collection of interconnected complete systems used as a single, unified resource. The
cluster provides a coordinated, distributed process across the systems to deliver the solution. This
results in higher levels of availability, some horizontal growth, and simpler administration across the
enterprise. Cluster resource services detect outage conditions and coordinate automatic movement
of critical resources to a backup system.

© Copyright IBM Corp. 1995, 2017 9-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

(VWLPDWLQJWKHYDOXHRIDYDLODELOLW\
‡ 7RHVWLPDWHWKHYDOXHRI\RXULQIRUPDWLRQVHUYLFHV
IROORZWKHVHVWHSV
ƒ 'HYHORSDOLVWRIWKHPDMRUVHUYLFHVDQGVROXWLRQVWKDW\RXUV\VWHPSURYLGHV
ƒ $VVHVVKRZPXFKLWFRVWVZKHQWKHVHVHUYLFHVDUHXQDYDLODEOH
ƒ /RRNDWGLUHFWFRVWVYHUVXVLQGLUHFWFRVWV
ƒ &RQVLGHUWDQJLEOHFRVWVYHUVXVLQWDQJLEOHFRVWV
ƒ $QDO\]HIL[HGFRVWVYHUVXVYDULDEOHFRVWV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-4. Estimating the value of availability

To estimate the value of your information services, follow these steps:


• Develop a list of the major services and solutions that your system provides. Your system exists
so that users and solutions can accomplish tasks that are critical to the operation of your
business. The systems provide solutions to a business function. If the IBM Power System with
IBM i is unavailable, the business function cannot be completed or is significantly degraded to
the point of causing the business lost revenue or increased expenses.
• Assess how much it costs you when these services are unavailable. Each application or service
has a direct effect on business functions. You need to determine how these business functions
would be affected and what would be the overall cost to your business if these services were
unavailable.
• Look at direct costs versus indirect costs. Direct costs are losses that can be traced directly to a
system being unavailable. Indirect costs are those that are incurred by another department or
function as a result of an outage.
• Consider tangible costs versus intangible costs. Tangible costs can be measured in currency.
However, there are other costs that are not measured with money, such as market share, lost
opportunity, and good will.

© Copyright IBM Corp. 1995, 2017 9-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Analyze fixed costs versus variable costs. Fixed costs are those that result from a failure and
are the same, regardless of the length of the outage. Variable costs are those that vary, based
on the length of the outage.

© Copyright IBM Corp. 1995, 2017 9-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

:KDWLVDQDFFHSWDEOHGRZQWLPH"

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-5. What is an acceptable downtime?

After understanding availability at a basic level, it is important to assess your individual availability
needs. Higher availability is more costly than a lower-level availability. You must balance your
needs and services with the overall cost of implementing and maintaining these availability
solutions.
You want to be sure that you have analyzed your business needs thoroughly in order to decide
what level of availability you can afford to maintain. To decide what level of availability you need,
consider the following questions:
• Do you have any applications that require 100% availability? In most cases, you can achieve a
high level of availability by implementing sound processes and systems management practices.
The closer you need to be to continuous availability, the more of an investment you must make.
Before you make that kind of investment, you should be sure that you require that level of
availability.
Along with knowing how much downtime is acceptable to you, you need to consider how that
downtime might occur. For example, you might think that 99% availability is acceptable if the
downtime is a series of shorter outages that are distributed over the course of one year. But you
might think differently about 99% availability if the downtime is actually a single outage that lasts
three days.

© Copyright IBM Corp. 1995, 2017 9-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
You also need to consider when a downtime is acceptable and when it is not. For example, your
average annual downtime goal per year might be 9 hours. If that downtime were to occur during
critical business hours, it might have an adverse effect on the bottom line revenue for your
company.
It used to be that customers and Business Partners accessed your business from 9 AM to 5 PM, so
it was realistic to expect that your system only had to be available during those hours. However, the
Internet and a diverse global marketplace have changed that expectation; customers and business
associates might expect to have access to your company’s data at any time of the day or night.
Your working hours might be hours or even days different from your global Business Partner or
customer. You must determine what your customer expectations are, and what is realistic regarding
those expectations, as you determine what level of availability you maintain.

© Copyright IBM Corp. 1995, 2017 9-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7\SHVRIRXWDJHV

$SSOLFDWLRQIDLOXUH 2SHUDWRUHUURUV

+DUGZDUHSRZHURSHUDWLQJ
V\VWHPGLVDVWHU

,%03RZHU6\VWHPZLWK,%0L[
1RWLPHIRUGRZQWLPH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-6. Types of outages

Availability is measured in terms of outages, which are periods of time when the server is not
available to users.
During a planned outage (also called a scheduled outage), you deliberately make your system
unavailable to users. You might use a scheduled outage to run batch work, back up your server, or
apply fixes.
An unplanned outage (also called an unscheduled outage) is usually caused by a failure. You can
recover from some unplanned outages (such as disk failure, system failure, power failure, program
failure, or human error) if you have an adequate backup strategy. However, an unplanned outage
that causes a complete system loss, such as a tornado or fire, requires you to have a detailed
disaster recovery plan in place in order to recover.
Your backup window is the amount of time that your server can be unavailable to users while you
perform your backup operations. Your backup window is a scheduled outage that usually occurs in
the night or on a weekend when your server has less traffic.
There are several levels of availability. These levels differ in the type and duration of outages that
they tolerate. These levels are as follows:

© Copyright IBM Corp. 1995, 2017 9-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Highly available: The server delivers an acceptable or agreed-upon level of service during its
scheduled period of operation. The goal is to have the server available when the customer
needs it.
• High availability: The server delivers an acceptable or agreed-upon level of service during its
scheduled period of operation. The goal is to have no unplanned outages; there might be some
planned outages.
• Continuous operations: The server delivers an acceptable or agreed-upon level of service 24
hours per day, 365 days per year. The goal is for the server to operate without any planned
outages there might be some unplanned outages.
• Continuous availability: The server delivers an acceptable or agreed-upon level of service 24
hours a day, 365 days a year. The goal is to have no planned or unplanned outages.

© Copyright IBM Corp. 1995, 2017 9-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

)DLOXUHW\SHV RI
‡ 'LVNIDLOXUH
ƒ 8VXDOO\GDWDRQIDLOHGXQLWORVW
ƒ 5HFRYHUDQ$63RIIDLOHGXQLW
‡ 6\VWHPIDLOXUH KDUGZDUHIDLOXUHRWKHUWKDQGLVN
ƒ 8VXDOO\FDXVHVDEQRUPDOHQG
ƒ 3RVVLEOHSUREOHPV
í )LOHVSDUWLDOO\XSGDWHG
í $FFHVVSDWKVLQFRPSOHWH
í 'DPDJHWRREMHFWVLQXVH
í 5HODWLRQVKLSVEHWZHHQILOHVPLJKWEHSDUWLDOO\YDOLGDWHG
ƒ /RQJ,3/

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-7. Failure types (1 of 2)

Disk failure
If a disk unit on your system fails, in most cases the data on that disk unit is destroyed. This
requires recovering all data in the auxiliary storage pool (ASP) that contains the failed unit.
The single-level storage architecture makes the IBM Power System with IBM i a very productive
system to program and to manage. However, the architecture makes recovering from a disk failure
more difficult. The system spreads information across all the disk units in an ASP to provide good
performance and storage management. If a unit in an ASP is lost, you cannot determine what data
was on that unit because objects are spread across the ASP. You must recover all the data in the
ASP.
Independent disk pools (also called independent auxiliary storage pools) enable you to prevent
unplanned outages because the data on them is isolated from the rest of your server. If an
independent disk pool fails, your server can continue to operate.
The disk protection tools, mirrored protection, and device parity protection are designed to reduce
the recovery time if a disk unit fails or in some cases, to eliminate the need for the recovery of data.
System failure
subsystems, fails. Some system failures, such as processor problems, cause your system to stop
without warning. This is called an abnormal end.

© Copyright IBM Corp. 1995, 2017 9-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
When your system ends abnormally, the following problems can occur:
• Files might be partially updated.
• Access paths for files might be incomplete.
• Objects that are in use might be damaged.
• Relationships between files might be partially validated.
Long IPL
When you restart (IPL) your system after the failed component is repaired, the system analyzes the
possible damage, rebuilds or recovers access paths, tries to verify file relationships, and attempts
to synchronize files to transaction boundaries. The first IPL after the system ends abnormally can
take a long time.

© Copyright IBM Corp. 1995, 2017 9-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

)DLOXUHW\SHV RI
‡ 3RZHUIDLOXUH
ƒ &DQFDXVHDEQRUPDOHQG
ƒ 6DPHSUREOHPVDVV\VWHPIDLOXUH
‡ 3URJUDPRUXVHUHUURU
ƒ ,QFRUUHFW GDPDJHG GDWD
ƒ &RUUHFWGDWDRUUHVWRUHILOHV
‡ &RPSOHWHV\VWHPORVV
ƒ 1DWXUDOGLVDVWHUVVXFKDVILUHDQGIORRG

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-8. Failure types (2 of 2)

Power failure
Loss of power also causes your system to end abnormally. You might experience the same types of
problems that occur with a system failure. Power Systems are equipped with a feature called
System Power Control Network. This feature provides a function called Continuously Powered
Main Store. If your system has this feature, a battery provides sufficient power to shut down the
system and maintain the contents of memory for up to for a varied amount of time (for example, one
day) after a power loss. In many cases, this can significantly reduce the amount of time the system
requires to perform an initial program load (IPL) after a power loss.
Program or user error
Sometimes programs are not adequately tested before they are put into production, or a condition
occurs that was not anticipated by the software developers. A program error can cause incorrect
information in some of your data files.
People using the system can make mistakes, too. An operator might run a month-end program
twice. A data entry person might enter the same batch of orders twice. A System Manager might
delete a file by mistake.
When these types of errors occur, you need to correct or restore the data that has been damaged.

© Copyright IBM Corp. 1995, 2017 9-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Complete system loss
A fire, flood, or other natural disaster could destroy your entire system. To rebuild your entire
system, you should have a complete set of save tapes and documentation stored offsite at a
secure, accessible location.

© Copyright IBM Corp. 1995, 2017 9-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LKDUGZDUHIHDWXUHV RI
‡ 3RZHUVXEV\VWHP
ƒ 5HGXQGDQWSRZHUVXSSOLHV
ƒ 'XDOOLQHFRUGV
ƒ 5HGXQGDQWFRROLQJIDQV
ƒ 'HGLFDWHG836PRQLWRULQJLQWHUIDFH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-9. IBM Power Systems with IBM i hardware features (1 of 5)

Power subsystem
• Redundant power supplies
Cooling fans are options available for IBM Power Systems with IBM i. Some models of the
system can be ordered with dual line cords.
These features allow power to be supplied from more than one source, with one power source
acting as a backup in the event of a disruption to the alternate power source.
• Dedicated UPS interface
The IBM Power System with IBM i provides a program interface to monitor and manage the
switch to a UPS source in the event of a power outage. The system sends a message (that can
be monitored for) when it detects power loss. A power handling program can monitor for
power-related messages and manage the switchover to a UPS.

© Copyright IBM Corp. 1995, 2017 9-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LKDUGZDUHIHDWXUHV RI
‡ 'LVNVXEV\VWHP
ƒ ,QWHUQDO
í 5$,'5$,'SURWHFWLRQ
í 0LUURULQJSURWHFWLRQ
í &RQFXUUHQWPDLQWHQDQFH
í $GGGLVNFRQFXUUHQWO\
ƒ ([WHUQDO H[WHUQDOVWRUDJH
í 13,913RUW,'9LUWXDOL]DWLRQ
í Y6&6, 9LUWXDO6&6,

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-10. IBM Power Systems with IBM i hardware features (2 of 5)

Disk subsystem
Internal:
• RAID-5
Device parity protection (RAID-5) is a hardware availability function that protects data from loss
due to a disk unit failure or because of damage to a disk. The overall goal of device parity
protection is to provide high availability and to protect data. To protect data, the disk controller
calculates and saves a parity value for each bit of data. Conceptually, the disk controller
computes the parity value from the data at the same location on each of the other disk units in
the device parity set. When a disk failure occurs, the parity value and values of the bits in the
corresponding locations on the other disks are used to reconstruct the data. The system
continues to run while the data is reconstructed.
• RAID-6
If more than two disk units fail, you must restore the data from the backup media. Logically, the
capacity of two disk units is dedicated to storing parity data in a parity set. However, in practice
the parity data is spread among multiple disk units. The minimum number of disk units in a
parity set is 4. The maximum number of disk units in a parity set is 18. When a RAID-6 parity set
is started, all of the disk units contain parity. Restoring data to a disk pool that has disk units with

© Copyright IBM Corp. 1995, 2017 9-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
device parity protection may take longer than a disk pool that contains only unprotected disk the
stripes of parity data in a RAID set. These features enhance performance and functionality.
• Mirrored protection
Mirrored protection is an availability function that protects data from being lost due to failure or
because of damage to a disk-related component. Data is protected because the system keeps
two copies of data on two separate disk units. When a disk-related component fails, the system
continues to operate without interruption. The mirrored copy of the data is used until the failed
component is repaired. Mirroring can be extended to include mirroring the disk controllers and
the buses that the disk units are attached to so the disk subsystem can continue to function
even if a disk, controller or a bus fails.
• Concurrent maintenance
The IBM Power System with IBM i disk subsystem allows maintenance to be performed on a
disk drive that is part of a mirrored pair or a RAID set while the system remains operational.
Disks can be added concurrently, meaning disk capacity can be increased without disruption to
system operations. Because the system manages storage automatically, newly added drives
are immediately available for use. There is no requirement to partition the drives or move data
to them in order for the system to utilize the drives. The system manages all space as one
virtual address. Other than configuring the disks as new hardware devices, special setup is not
required to make a new disk operational.
External:
NPIV N-Port ID Virtualization or vSCSI - Virtual SCSI for both technology are provided multipathing
to access to the disks in two or more ways. Even one physical/virtual adapter or port VIOS (Virtual
I/O Server, SAN Fabric, SAN switch failed disks still be accessible using another disks paths.

© Copyright IBM Corp. 1995, 2017 9-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LKDUGZDUHIHDWXUHV RI
‡ ,2VXEV\VWHP
ƒ +RWSOXJJDEOH3&,HFDUGV
ƒ )DQRXWPRGXOHV
ƒ '\QDPLFKDUGZDUHUHVRXUFHUHDOORFDWLRQ 9DU\FPG
ƒ 6SOLWEDFNSODQH
ƒ 9LUWXDO,23UHVHW

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-11. IBM Power Systems with IBM i hardware features (3 of 5)

I/O subsystem
• Hot pluggable PCI cards
Hot plugging is made possible by the existence of a power control to individual cards slots. PCI
can be added, removed, or replaced while the system remains active.
• Dynamic hardware resource reallocation
Each hardware device on the IBM Power System with IBM i has a device description
associated with it.
The description contains the name of the specific hardware component that the hardware
resource is associated with. If a hardware device fails and there is a backup device for it
installed in the system, the device description can be modified to point to the backup device. It
can then be substituted for the failing device.
• Fan-out modules in PCIe Gen3 I/O Drawer (Concurrent maintained)
• Split backplane - The POWER8 servers feature hot-plug SFF-3 HDD/SDD bays and in some
configurations, additional 1.8" SSD-only bays. SFF-3 is a new disk carrier design that’s used
only with POWER8 servers. Each of the disk backplane options provides integrated SAS
controller support for JBOD, RAID 0 (striping), RAID 10 (striping and mirroring), and RAID5/6

© Copyright IBM Corp. 1995, 2017 9-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
(parity). The SAS controllers for the internal disk bays plug into dedicated slots and don’t
consume any of the general-purpose PCIe slots. There are three disk backplane options:
▪ Base: 12 disk bays and 1 DVD bay connected to a single SAS controller. All 12 bays must
be assigned to a single LPAR or VIOS. Note that this feature is not currently available for
purchase by itself.
▪ Split-Bus: 12 disk bays and 1 DVD bay connected to a two SAS controllers. The disk bays
are split into two strings of six bays, each with its own SAS controller. This allows each
string of six bays to be assigned to separate LPARs or VIOS. The split-bus option is the
ideal choice for dual-VIOS designs. Note that the DVD drive is assigned to one of the SAS
controllers associated with one set of six disk bays. The split-bus backplane option is
ordered as combination of two feature codes: (1) The base 12 disk bay backplane, and (2)
split-bus additional SAS controller.
▪ RAID Cache: Eight disk bays (2U) or 18 disk bays (4U) cross connected to two SAS
controllers with write cache. All of the disk bays and the DVD bay must be assigned to a
single LPAR or VIOS. For systems with two DCMs installed, additional 1.8-inch SSD-only
bays are included: six SSD-only bays for 2U servers and eight SSD-only bays for 4U
servers.

Note

Not all Power8 servers support split backplane for IBM i.

• Virtual IOP reset the IBM Power System with IBM i I/O architecture uses intelligent virtual I/O
processors (vIOPs) to control hardware adapters. In case of a failure in one of these adapters, it
can be reset (or IPLed) with the system VARY command or SST reset virtual IOP. This avoids
the need to IPL the system to recover from an I /O error.

© Copyright IBM Corp. 1995, 2017 9-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LKDUGZDUHIHDWXUHV RI
‡ 0HPRU\
ƒ &KLSNLOOWHFKQRORJ\
ƒ (UURUGHWHFWLRQDQGFRUUHFWLRQ
ƒ 0HPRU\VFUXEELQJ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-12. IBM Power Systems with IBM i hardware features (4 of 5)

Memory
IBM Power Systems with IBM i utilizes memory that represents Chip Kill technology. If a segment of
memory fails, the IBM Power System with IBM i simply makes unavailable the range of addresses,
including the defective address or addresses. A message is sent to the system operator and the
hardware error logs are updated with data related to the failure.
Therefore, the system can remain active should a part of main storage fail. Maintenance can be
deferred, which allows the system to tolerate memory failures without bringing the system down.
The system also performs a background scrub of memory to detect and correct single- and
double-bit errors.

© Copyright IBM Corp. 1995, 2017 9-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LKDUGZDUHIHDWXUHV RI
‡ +DUGZDUHVHUYLFH
ƒ $XWRPDWLFIDLOXUHQRWLILFDWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-13. IBM Power Systems with IBM i hardware features (5 of 5)

Hardware service
• Automatic failure notification
With IBM Power Systems with IBM i running Service Director, the system phones home to a
service machine when it detects key hardware component failures. A customer can optionally
choose to have a repair engineer dispatched automatically when a hardware failure is logged.
There are many cases recorded where a service engineer comes to a customer’s premises in
response to a hardware problem detected by Electronic Service Agent, and the customer is not
even aware of the problem because the system was able to continue operations.

© Copyright IBM Corp. 1995, 2017 9-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ -RXUQDOLQJ
í 7DEOHV ILOHV
í 'DWDDUHDV
í 'DWDTXHXHV
í ,)6 VWUHDPILOHV
í 5HPRWHMRXUQDOLQJ
í 60$33
ƒ &RPPLWPHQWFRQWURO

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-14. IBM Power Systems with IBM i software features (1 of 6)

Journaling
IBM Power Systems with IBM i journaling was initially introduced to record changes made to
database files. In the event of a system outage, the journal is used to reconstruct the file based on
changes recorded in the journal receiver.
IBM Power Systems with IBM i journaling has evolved over time, as has the style of computing that
the system supports. Journaling support is enhanced to include byte stream files (Integrated File
System files), data areas, and data queues.
With remote journaling, journal receiver entries are replicated to a backup or remote system.
Remote journaling can be set up to run in synchronous or asynchronous mode. When remote
journaling is synchronous, a database update for the source IBM Power Systems with IBM i is not
completed until the target system makes the journal entry in its receiver. Remote journaling can be
used along with database replication for high availability.
Commitment control
Some applications involve multistep transactions to update the database. It is imperative that you
complete all steps within the transaction before you commit the database update. The IBM Power
System with IBM i provides commitment control for this transaction environment. Commitment
control is an application-level function that defines the transaction boundary. It is used along with

© Copyright IBM Corp. 1995, 2017 9-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
database journaling. In the event of a system failure, commitment control uses journal entries to roll
back an entire transaction. Therefore, a partial update to database files is avoided. An example of
the need for commitment control is a financial application that moves funds between accounts. In
order for the transaction to be considered complete, the debit and credit of the accounts involved
must both be reflected in the database.

© Copyright IBM Corp. 1995, 2017 9-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ $63VL$63V
ƒ +60
ƒ $XWRPDWHGVWRUDJHPDQDJHPHQW
ƒ 2QOLQHGLVNEDODQFLQJ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-15. IBM Power Systems with IBM i software features (2 of 6)

Auxiliary storage pools (ASPs)


IBM Power Systems with IBM i single-level storage treats all storage as one large virtual address
space (this includes main store memory as well as disk). There is no concept of a disk volume or
data set partition. However, the system provides the capability to separate this contiguous address
space into smaller disk pools to make system backup and recovery faster and to provide
Hierarchical Storage Management facilities. These pools are called auxiliary storage pools.
Conceptually, each ASP on the IBM Power System with IBM i is a separate pool of disk units for
single-level storage. The system spreads data across the disk units within an ASP. If a disk failure
occurs, you need to recover only the data in the ASP that contains the failed unit. The user of ASPs
can reduce system backup time. To do this, create an ASP to include individual applications and
data. A single ASP can then be backed up without impacting business operations while other
applications that operate from different ASPs stay online.
The independent ASPs (IASPs) take the concept of ASPs further by making the ASP available
between systems in a cluster.
Hierarchical storage management
Hierarchical storage management (HSM) is a set of APIs supplied with IBM i. The IBM i Backup
Recovery Media Services (BRMS) licensed program offers an HSM component. BRMS provides

© Copyright IBM Corp. 1995, 2017 9-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
automated backup and recovery support for database and IFS files. It also provides automation for
system recovery. HSM moves data across a hierarchy of storage, allowing data that is not heavily
used to move to less costly storage. Retrieval of the data is transparent to users and programs.
When the object is referenced, BRMS retrieves it for the user or program. HSM also helps reduce
system back up time, as seldom used data is moved out of the system ASP and can be saved
outside the backup window used for daily saves of critical business data.
Automated storage management
The IBM i has long been known for its low cost of ownership. A contributing factor is that the IBM i
server does not need a database administrator (DBA) to track storage utilization and worry about
moving data around to balance or enhance disk subsystem performance.
Automated storage management is also an availability feature in that the database does not need
to be made unavailable to perform this type of maintenance. IBM i storage management
automatically spreads data across all available disk arms to balance disk arm utilization. It also
automatically allocates additional storage as files, libraries, and other objects grow. There is no
need to take the database or a file offline to extend its size.
Online disk balancing
If a large number of disk drives are added at once, run the Start ASP Balance (STRASPBAL) CL
command to redistribute data across the disk arms and rebalance arm utilization. There is no need
to partition data sets or to move data between volumes as required with other databases to balance
performance.
You need to select the method of balancing that you want to use:
• Capacity balancing
• Usage balancing
• Hierarchical storage management (HSM) balancing
Before using usage balancing or HSM balancing, you must run the Trace ASP Balance
(TRCASPBAL) command. This command starts a trace function that collects statistics on the data in
the ASPs that you want to balance. Data that is used often is referred to as high use or hot data.
Data that is not used often is referred to as low use or cold data.

© Copyright IBM Corp. 1995, 2017 9-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ 6DYHZKLOHDFWLYH
ƒ 6DYHFKDQJHGREMHFWV
ƒ 3DUDOOHOVDYHDQGUHVWRUH
í 0XOWLSOHREMHFW
í 0XOWLSOHWDSHGULYHV
ƒ %506%DFNXSDQGUHFRYHU\DQGWDSHDXWRPDWLRQ
ƒ 2QOLQH'RPLQREDFNXS

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-16. IBM Power Systems with IBM i software features (3 of 6)

Save and restore


IBM i provides a very comprehensive set of save and restore capabilities. These capabilities
include:
Save-while-active
Save-while-active provides a means to save an object to tape while the system remains active. Any
application using a file or library being saved while the IBM Power System with IBM i is active, must
temporarily stop processing before the save can occur. Save-while-active then establishes a
checkpoint image of the object and begins the save to tape while the application resumes
execution.
An advantage to save-while-active is that the entire system does not need to be brought down for
back up. We recommend that you end all subsystems to ensure any database updates are written
from memory to disk before the save is initiated.
Save changed objects
IBM i keeps a description for every object that exists on the system. Within this description, there is
a time stamp that records the last time the object is changed and when it is last backed up. IBM i
save commands use this time stamp to provide the ability to save only objects that have been

© Copyright IBM Corp. 1995, 2017 9-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
changed since the last save to tape. This reduces the amount of data saved and the time required
to perform a system backup.
Parallel save and restore
IBM i allows parallelism within the system save commands. A system with multiple tape drives can
initiate several save commands in parallel. Use the include and omit parameters to direct saves for
specific libraries to different tape drives. Use this same approach to restore system objects using
the restore procedures.
Backup Recovery and Media Services (BRMS)
BRMS provides an automated means to manage tape libraries and to set up system save policies.
Save policies can be set up for daily, weekly, and other schedules to ensure critical enterprise data
is saved to tape media. BRMS tracks which system objects are saved and the date of the save, and
reports objects that are not saved in the operation. BRMS creates a recovery report, which lists the
steps required to restore an IBM Power System with IBM i in the event of an outage where the
system must be recovered from backup media. BRMS uses the parallel save and restore support
provided in IBM i.

© Copyright IBM Corp. 1995, 2017 9-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ 9LUWXDO,3
í 5RXWHIDXOWWROHUDQFH
í ,QERXQGRXWERXQG
í /RDGEDODQFLQJ
ƒ (WKHUFKDQQHO DJJUHJDWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-17. IBM Power Systems with IBM i software features (4 of 6)

TCP/IP
IBM Power Systems with IBM i supports a full-function TCP/IP communications stack. The support
is built into TCP/IP to facilitate high-availability computing in a network environment. A description
of these functions follows.
• Virtual IP
IBM Power Systems with IBM i support for virtual IP allows the system to assign an IP address
without designating it to a physical hardware device. All IP traffic can be routed through this
virtual address. Each virtual address can have more than one physical communications
adapter, system, or both behind it. This way, if a physical card adapter or system fails, traffic can
be rerouted to maintain availability. A client can be transparently rerouted. There is no need to
reestablish or reconfigure the link to the alternate system.
• Etherchannel
IBM i allows you to create aggregation of two or more physical Ethernet adapter and setup one
IP address on the aggregation. This allows you to create faster and redundant connection. In
case of failure of one of the physical adapters, the connection is taken over by another one.
After adapter fixed the communication reestablish to all available adapters.

© Copyright IBM Corp. 1995, 2017 9-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Etherchannel can also be used for load balancing and to direct sessions across
communications adapters in a system; it depends on the protocol (like LACP- Link Aggregation
Control Protocol) and switch configuration. This helps to distribute traffic for workload
management.

© Copyright IBM Corp. 1995, 2017 9-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ 1RLQWHUIDFHVWR26NHUQHO
í +LJKO\YLUXVUHVLVWDQW
í 6HFXULW\DXGLWLQJ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-18. IBM Power Systems with IBM i software features (5 of 6)

• Security
With the well-known instances today of viruses and server hacking to have a secure server that
is not vulnerable to attack is a key component of availability. IBM i has no open interfaces to the
system kernel, which means the IBM Power System with IBM i is highly resistant to hacking and
viruses. The IBM Power System with IBM i provides security auditing and uses system
journaling support to log security entries. System security auditing can log activities with user
profiles, objects on the system, and jobs.

© Copyright IBM Corp. 1995, 2017 9-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

,%03RZHU6\VWHPVZLWK,%0LVRIWZDUHIHDWXUHV RI
‡ ,%0LDQGV\VWHPVRIWZDUHDYDLODELOLW\IHDWXUH
ƒ ,PPHGLDWH37)DSSOLHV
ƒ 1R,3/UHTXLUHG
ƒ 1RUHTXLUHGWRLQVWDOOVHSDUDWHGFRPSRQHQWV GULYHUVDQGRWKHUREMHFWV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-19. IBM Power Systems with IBM i software features (6 of 6)

• System software maintenance


To achieve higher levels of availability when applying PTFs, the IBM Power System with IBM i
adopts a philosophy to applying PTFs immediately (if possible not all PTF’s can be applied in
this way sometimes IPL is required).

© Copyright IBM Corp. 1995, 2017 9-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
9.2. Topic 2: LPAR and HMC concepts and
overview

© Copyright IBM Corp. 1995, 2017 9-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLF/3$5DQG+0&
FRQFHSWVDQGRYHUYLHZ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-20. Topic 2: LPAR and HMC concepts and overview

© Copyright IBM Corp. 1995, 2017 9-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU90YLUWXDOL]DWLRQ
‡ 3RZHU90
ƒ 3RZHU906WDQGDUG(GLWLRQ
ƒ 3RZHU90(QWHUSULVH(GLWLRQ
ƒ 3RZHU90/LQX[(GLWLRQ
‡ 32:(5+\SHUYLVRU
ƒ )LUPZDUHVLWWLQJEHWZHHQKRVWHG2SHUDWLQJ6\VWHPVDQGVHUYHUKDUGZDUH
í &RQWUROVKDUGZDUH,2DQGPDQDJHPHQWIRUSDUWLWLRQV
ƒ $OZD\VLQVWDOOHGDQGDFWLYDWHG
í 5HJDUGOHVVRIFRQILJXUDWLRQ
‡ '\QDPLF/RJLFDO3DUWLWLRQLQJ
‡ 6KDUHGSURFHVVRUSRROV
‡ 0LFURSDUWLWLRQLQJ
‡ ,QWHJUDWHG9LUWXDOL]DWLRQ0DQDJHU
ƒ &RPELQHVSDUWLWLRQPDQDJHPHQWDQG9LUWXDO,26HUYHU 9,26
í 9,26DOORZVVKDULQJRISK\VLFDOUHVRXUFHVDPRQJPXOWLSOHSDUWLWLRQV
ƒ 0DQDJHGIURPDVLQJOHSRLQWRIFRQWURO ,90SDUWLWLRQ
í 'RHVQRWUHTXLUHD+DUGZDUH0DQDJHPHQW&RQVROH +0&

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-21. PowerVM virtualization

PowerVM
PowerVM is a set of comprehensive systems technologies and services designed to enable the
management of resources in a consolidated, logical view. PowerVM is the virtualization solution for
AIX, IBM i, and Linux environments on IBM POWER technology. There are three versions of
PowerVM, suited for various purposes:
The PowerVM Editions hardware feature includes the following editions:
• PowerVM Standard Edition
• PowerVM Enterprise Edition
• IBM PowerVM, Linux Edition
POWER Hypervisor
The POWER Hypervisor is firmware that sits between hosted operating systems and server
hardware. It provides access between the physical hardware resources and the logical partitions
that use them. It also monitors the Service Processor on behalf of the server and all of its partitions

© Copyright IBM Corp. 1995, 2017 9-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Integrated Virtualization Manager
The Integrated Virtualization Manager (IVM) is a hardware management solution (part of the VIOS
product) that enables an administrator to configure a single server using a browser-based, GUI
interface, or a command line interface. The tight relationship between VIOS and IVM enables the
administrator to manage a partitioned system without an HMC.
Micro-Partitioning
Micro-Partitioning technology allows you to allocate fractions of processors to a logical partition. An
LPAR using fractions of processors is also known as a shared processor partition or micro-partition.
Micro-partitions run over a set of processors called a shared-processor pool.
Shared-processor pools
Shared-processor pools allow a system administrator to create a set of micro-partitions with the
purpose of controlling the processor capacity that can be consumed from the physical shared pool.
Micro-partitions are created and then identified as members of either the default shared-processor
pool or a user-defined shared-processor pool. If certain micro-partitions in a shared-processor pool
do not use their capacity entitlement, the unused capacity is ceded and other micro-partitions within
the same shared-processor pool are allocated the additional capacity.
Dynamic Logical Partitioning
Dynamic logical partitioning allows selected resources, such as processors, memory, and I/O
components to be added or deleted from logical partitions while the partitions are executing.
Hardware Management Console
The Hardware Management Console (HMC) is a hardware appliance that you can use to configure
and control one or more managed systems. You can use the HMC to create and manage logical
partitions and activate Capacity Upgrade on Demand. Using service applications, the HMC
communicates with managed systems to detect, consolidate, and send information to service and
support for analysis. The HMC also provides terminal emulation for the logical partitions on your
managed system. You can connect to logical partitions from the HMC itself, or you can set up the
HMC so that you can connect to logical partitions remotely through the HMC.
HMC is also available as a virtual HMC. The virtual HMC (vHMC) offering allows clients to use their
own hardware and server virtualization to host the IBM supplied HMC virtual appliance.

© Copyright IBM Corp. 1995, 2017 9-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU90YLUWXDOL]DWLRQHGLWLRQV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-22. PowerVM virtualization editions

This visual compares the options offered in each PowerVM edition.


Linux editions offer the same options as Enterprise but only for Power System servers dedicated for
Linux not with firmware.

© Copyright IBM Corp. 1995, 2017 9-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

:KDWLVORJLFDOSDUWLWLRQLQJ"

7RLQGHSHQGHQWSDUWLWLRQV

3DUWLWLRQ 3DUWLWLRQ 3DUWLWLRQ

From a single
footprint

‡ 8SWRDPD[LPXPRI/3$5V
‡ 0D[GHSHQGVRQZKLFKPRGHORIWKH32:(5LQVWDOOHG

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-23. What is logical partitioning?

The introduction of faster more powerful processor cores may result in the capacity of a single
processor core to be more than what is required by a single IT organization. Also, an organization
may have the need for multiple independently operating environments to support different
functions. Logical partitioning is a technique for subdividing a single IBM Power System with IBM i
into multiple entities.
• Partition
When a single IBM Power System with IBM i is subdivided into multiple entities, each
functioning under a separate instance of an operating system, those independent operating
environments are called partitions. The system resources are allocated to the partitions.
Applications running on a partitioned system do not have to be redesigned for the partitioned
environment.
On POWER7 and POWER8 based hardware, a primary partition is not required. There is a
service processor (SP) provided which controls the base operations of the IBM Power System
for all partitions (IBM i, AIX Linux). The service processor is powered up immediately when the
IBM Power System is plugged into a power source. A Hardware Management Console (HMC)
is required in order to interface with the service processor for management of all partitions.

© Copyright IBM Corp. 1995, 2017 9-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Independent operating environment
Each partition runs its own operating system that may or may not match operating systems in
other partitions on the same system. Each partition may be started and stopped independently
of other partitions.

© Copyright IBM Corp. 1995, 2017 9-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

$OORFDWLQJUHVRXUFHVRQDQ/3$5V\VWHP

:KROH 'HGLFDWHG 6KDUHGSURFHVVRU 3DUWLDO


SURFHVVRUV
SURFHVVRUV SURFHVVRUV SRRO
/3$5 /3$5 /3$5 /3$5

    

3URFHVVRUV

9LUWXDO
(WKHUQHW 0HPRU\

'\QDPLFUHDOORFDWLRQ

,2DGDSWHUV

&RPPRQUHVRXUFHV

,2GHYLFHV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-24. Allocating resources on an LPAR system

Resources
Resources are the system components that are configured into partitions.
The maximum number of partitions is related to the type of POWER system and the total amount of
resources on the system. If a system has enough resources, the upper limit of the number of
partitions is 1000 on POWER8 system.
Minimum amount of resources
Each IBM i partition must be configured with at least 256 MB of memory, and 0.05 of a physical
processor, and enough I/O devices to provide a load source (boot resources), have access to a
console and have the ability to load code.
Memory
dependent on the model and the total amount of memory on the managed server. A partition may
be as small as 256 MB or as large as all of the installed memory.
Processing units
Processing power is configured in processing units equivalent to 5/100 of a physical processor. A
dedicated processor = 1.00 processing units. A partition can be configured with as little as 0.05
processing unit or as much as the equivalent to all of the available installed physical processors.

© Copyright IBM Corp. 1995, 2017 9-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
I/O slots
I/O resources are allocated to partitions at the slot level. At a minimum, you must configure a
partition with enough I/O resources to include the load source disk (boot resources) and at least
access to a console.
5250 CPW (IBM i partitions only)
Your system has a certain amount of interactive performance based on the type of system and the
number of processors. The 5250 emulation refers to how much the user must interact with (and
respond to prompts from) the computer. You can contrast this with batch where no user intervention
is required. Given the amount of interactive performance on your system, you need to determine
what percentage will be available for each partition. The combined total of all partitions’ settings
cannot exceed 100% - of the available 5250 CPWs.
Virtual devices
Other devices can be configured to be shared between partitions. Each partition may configure
virtual I/O slots that can be configured with a virtual adapter instance. These virtual adapters may
be an Ethernet interface, a SCSI, Fibre Channel, or serial devices.

© Copyright IBM Corp. 1995, 2017 9-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3DUWLWLRQUHVRXUFHV
‡ 7KHUHVRXUFHVWKDWDUHDOORFDWHGWRSDUWLWLRQVDUH
ƒ /RDGVRXUFH,2DQGGLVNXQLW
ƒ ,2VORWV
í ,QFOXGLQJYLUWXDOGHYLFHV
ƒ 3URFHVVLQJXQLWV
ƒ 0HPRU\
ƒ HPXODWLRQ µLQWHUDFWLYH¶ IRU,%0L
ƒ &RQVROH +0&RU/$1

‡ 9LUWXDOUHVRXUFHVWKDWFDQEHVKDUHG
ƒ (WKHUQHW
ƒ 6&6,
ƒ )LEUH&KDQQHO
ƒ 6HULDO

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-25. Partition resources

A partition is the allocation of system resources to create logically separate systems within the
same physical footprint.
A logical partition is when the isolation is implemented with firmware.
• Although a partition might be logical, it can also be physical (resources).
• It provides configuration flexibility.
The POWER Hypervisor is a layer of firmware associated with the service processor of the
hardware. It provides the support necessary for logically partitioning the hardware.
The Power Systems hardware supports one of the following operating systems in each partition:
• IBM i
• AIX
• Linux
• VIOS
The AIX, Linux, and VIOS operating systems interface through Run-Time Abstraction Services
(RTAS), while the IBM i has System License Internal Code (SLIC) and the Technology Independent
Machine Interface (TIMI).

© Copyright IBM Corp. 1995, 2017 9-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU6\VWHPVDQGRSHUDWLQJV\VWHPV

,%0L /LQX[9,26$,;

7,0,
2SHQILUPZDUH
6/,&

32:(5+\SHUYLVRU

3RZHU6\VWHPVKDUGZDUH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-26. Power Systems and operating systems

Introduction to the POWER Hypervisor


Partitions are isolated from each other by firmware (underlying software) part of which is the
POWER Hypervisor.
Virtual memory management by the POWER Hypervisor
There is no program access permitted between partition memory and I/O memory. Software
exceptions and crashes are contained within a partition. The POWER Hypervisor controls the page
tables used by partitions to ensure that a partition only has access to its own physical memory
segments. It uses a physical memory offset value for each partition so that the operating IBM i
instances in each partition can continue to use memory address zero as its starting point.
Virtual console support
The POWER Hypervisor provides input/output streams for a virtual console device that can be
presented on the HMC.

© Copyright IBM Corp. 1995, 2017 9-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Security and isolation between partitions
Besides managing virtual memory, the POWER Hypervisor also ensures that a partition may only
access devices allocated to it. It also clears memory, reinitializes processors, resets processor
registers, and resets I/O devices when devices are allocated to a partition (statically or
dynamically).

© Copyright IBM Corp. 1995, 2017 9-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

32:(5+\SHUYLVRUIXQFWLRQV
‡ 7KH32:(5+\SHUYLVRULVILUPZDUHWKDWSURYLGHV
ƒ 9LUWXDOPHPRU\PDQDJHPHQW
í &RQWUROVLQWHUQDORSHUDWLRQVDQG,2DFFHVV
í 0DQDJHVPHPRU\
ƒ 9LUWXDOKDUGZDUHVXSSRUW3URFHVVRUV(WKHUQHW6&6,)LEUH&KDQQHOVHULDO
ƒ 6HFXULW\DQGLVRODWLRQEHWZHHQSDUWLWLRQV
í 3DUWLWLRQVDUHDOORZHGDFFHVVRQO\WRUHVRXUFHVWKDWDUHDOORFDWHGWRWKHP HQIRUFHG
E\WKH32:(5+\SHUYLVRU 

/3$5 /3$5 /3$5 /3$5


6HFXULW\DQGLVRODWLRQ
EDUULHUVWKH32:(5
32:(5+\SHUYLVRU +\SHUYLVRULV
6\VWHPKDUGZDUH LQGHSHQGHQWRIDQ\26
PHPRU\SURFHVVRUVGHYLFHV
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-27. POWER Hypervisor functions

Software licenses on a partitioned system


Unique software resources exist and operate on hardware that is assigned to each partition. These
software resources include separate copies of Licensed Internal Code, IBM i, and other licensed
operating systems and programs. Additionally, language feature codes, security, user data, most
system values, and software release and fixes also known as program temporary fixes (PTFs)
remain unique for each partition.
If you use shared processors and take advantage of subprocessor allocations, IBM rounds up to
the nearest whole number in calculating the appropriate software licenses and IBM will not charge
you for more software licenses than the total number of physical processors on your server.
Planning through the System Planning Tool (SPT) gives you the required number of licenses
necessary.
If you plan to run different operating systems (for example, Linux and AIX) on the same server, then
you need licenses for each individual operating system and the licenses are based on processing
power. For example, on an eight processor system, you might have licenses for four processors for
IBM i and four processors for AIX. There are license keys to manage licenses. If you reconfigure
your partitions so that, for example, you have 4.5 processors in the partition running IBM i and your
licenses only allow four processors, you receive out of compliance messages. Either contact IBM to

© Copyright IBM Corp. 1995, 2017 9-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
purchase more licenses or reconfigure the partition to use less processing power to stop these
messages.
For third-party software, you need to discuss with the vendor how to license packages on a
partitioned system

© Copyright IBM Corp. 1995, 2017 9-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

6RIWZDUHOLFHQVLQJ
‡ /LFHQVLQJ
ƒ ,VSHURSHUDWLQJV\VWHP
ƒ ,VEDVHGRQSURFHVVLQJSRZHURULVXVHUEDVHGIRUVRPHHQWU\OHYHOVHUYHUV
ƒ ,VDIIHFWHGE\SDUWLDOSURFHVVRUIHDWXUH
‡ 7KLUGSDUW\DSSOLFDWLRQSURYLGHUOLFHQVHVPLJKWGLIIHU

2WKHUVRIWZDUH

2SHUDWLQJV\VWHPV
,%0L/LQX[$,;/

,%0KDUGZDUH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-28. Software licensing

© Copyright IBM Corp. 1995, 2017 9-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

:K\ZRXOG,XVHORJLFDOSDUWLWLRQV"
‡ 0L[HGSURGXFWLRQDQGWHVW
HQYLURQPHQWV
‡ 6HUYHUFRQVROLGDWLRQ
‡ 'LYHUVHZRUNORDGV
‡ 'HSDUWPHQWDOV\VWHPV
6<6 6<6 6<6 6<6
‡ 'LIIHUHQWV\VWHPQDPHV
  

ODQJXDJHVDQGWLPH]RQHV
-DSDQ 86$ %UD]LO 8.
‡ 1HHGWRVXSSRUWLQWHUDFWLYH
DQGHEXVLQHVVLQWHOOLJHQFH 25'

ZRUNORDGV
‡ 0L[HGRSHUDWLQJV\VWHPV
,%0L
ƒ ,%0L GLIIHUHQWYHUVLRQV ,%0L /LQX[ $,;
ƒ $,;
ƒ /LQX[
‡ 6KDUHUHVRXUFHV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-29. Why would I use logical partitions?

Consolidation
Using partitions gives you the ability to reallocate expensive resources and manage them all with
one interface (the HMC). You can reallocate processors, memory, or any I/O adapter (and thus
device) by reconfiguring the partitions or by using dynamic partition operations. All of the resources
are located within one system, potentially reducing the amount of floor space needed.
Applications that were running on different systems with different operating systems can now be
brought on to a single Power System – and less frequently is used resources maybe switched
between partitions to reduce costs.
Therefore, each partition can have its own instance of a supported operating system (AIX, Linux, or
IBM i), and have its own version level, language support, local time, and so on.
Many customers utilize smaller development systems to develop, test, and migrate applications.
These smaller systems may not be the same hardware, have the same software, devices, or
infrastructure as the “real”, production system. These issues can be largely avoided by utilizing a
partition on the same system as the production applications for development and testing. This also
protects the production partition from the activities on the test partition. Once the testing is
complete, the resources used for the development partition can be reallocated to the production
partition.

© Copyright IBM Corp. 1995, 2017 9-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

/3$5DOORZVIRUFRQVROLGDWLRQ
‡ )URPPDQ\VPDOOHUV\VWHPVWRRQH
RUIHZHU VPDOOHUV\VWHPV
ƒ 6PDOOHUIRRWSULQW
ƒ 6DYHRQ,7UHDOHVWDWH
ƒ 5HVRXUFHDOORFDWLRQIOH[LELOLW\ 7DSH

‡ 7LPHVKDUHFRPPRQUHVRXUFHV
ƒ 7DSH
ƒ '9'
ƒ &RPPXQLFDWLRQVDGDSWHUV '9'

‡ *OREDOFRQVROLGDWLRQ
ƒ ,QGHSHQGHQWSDUWLWLRQWLPH]RQHV
ƒ 0XOWLSOHQDWLRQDOODQJXDJHV
‡ 2SHUDWLQJV\VWHPVIOH[LELOLW\ 3DUWLWLRQ3DUWLWLRQ3DUWLWLRQ3DUWLWLRQ
ƒ &KRLFHRIRSHUDWLQJV\VWHP -DSDQ86$$UJHQWLQD8.

ƒ $SSOLFDWLRQVHOHFWLRQIOH[LELOLW\ 5'
2

‡ 6\VWHPVODQGVFDSH
ƒ 'HYHORSPHQWWHVWSURGXFWLRQDQGVRRQ ,%0L$,;,%0L/LQX[


,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-30. LPAR allows for consolidation

Since there is a service processor (SP) which controls the base operations of the IBM Power
System across all partitions, a primary partition is not required. A Hardware Management Console
(HMC) is required in order to interface with the service processor for management of all the
partitions.
Another advantage of partitioning is the ability to balance processor usage between partitions by
using uncapped partitions.

© Copyright IBM Corp. 1995, 2017 9-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&
‡ ,QWHOEDVHG3&DSSOLDQFH
ƒ 5HTXLUHGIRUFRQILJXUDWLRQDQGPDQDJHPHQWRISDUWLWLRQV
ƒ $YDLODEOHIRU32:(532:(532:(5V\VWHPV
‡ 0DLQ+0&DSSOLFDWLRQVDUH
ƒ 6HUYHUDQGSDUWLWLRQPDQDJHPHQW
ƒ /LFHQVHG,QWHUQDO&RGHPDLQWHQDQFH
í +0&FRGHPDLQWHQDQFH
,QGHSHQGHQWRIPDQDJHGV\VWHPRURSHUDWLQJV\VWHPV
í /LFHQVHG,QWHUQDO&RGHXSGDWHIOH[LEOHVHUYLFHSURFHVVRU )63
ƒ +0&PDQDJHPHQW
í +0&XVHUV
í &RQILJXUDWLRQ
ƒ 6HUYLFHDSSOLFDWLRQV
ƒ 6\VWHPPDQDJHUVHFXULW\

5DFNPRXQW
+0& &5
&5
&5
&5

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-31. HMC

The HMC and service processor


The HMC (Hardware Management Console) provides the administrator a GUI method of managing
virtual servers /logical partitions (LPAR LPAR) – available is also command line that allows to run
scripts for management automation.
The Service Processor (SP) in turn provides the interface to the Hypervisor, which is operating
system and virtual server (partition) independent.
The POWER Hypervisor is the interface through which the HMC is able to control the allocation of
appropriate resources necessary for virtual servers (partitions) on a managed system.
The virtual server (partition) configuration information is recorded in the NVRAM on the managed
system.
On the visual presented rack-mount HMC but is still available desktop model 7042-C08.

© Copyright IBM Corp. 1995, 2017 9-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

Y+0& RI
‡ ,%09LUWXDO+0&&RPSOHWH6RIWZDUHRIIHULQJ
ƒ /LFHQVHSOXVVRIWZDUHPDLQWHQDQFH
ƒ 3,' +09

‡ 9LUWXDO+0&5XQV
ƒ 2Q[+DUGZDUH SURYLGHGE\FOLHQW
ƒ 8QGHU.90RU90ZDUHYLUWXDOL]DWLRQ SURYLGHGE\FOLHQW

‡ 1HZY+0&FRPSOHWHVRIWZDUHRIIHULQJ
ƒ $FWLYDWLRQHQJLQH SURYLGHVFRQILJXUDWLRQRQILUVWERRW
ƒ $FFHSWOLFHQVHORFDOHQHWZRUN66+173

‡ 0DQDJHVDQ\32:(5RUODWHU3RZHUVHUYHUV
‡ 9HUVLRQ+0&ILUPZDUH
+0&
‡ &DQEHXVHGZLWKRUZLWKRXWKDUGZDUH+0&V

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-32. vHMC (1 of 2)

© Copyright IBM Corp. 1995, 2017 9-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

Y+0& RI
‡ 1HZ+0&YLUWXDODSSOLDQFH Y+0&
ƒ )RU32:(532:(532:(5VHUYHUV
ƒ 6DPHIXQFWLRQDOLW\DVWUDGLWLRQDO+0& YHUVLRQ
ƒ 5XQVDVYLUWXDOPDFKLQHRQ[VHUYHUXQGHU.90RU90ZDUHYLUWXDOL]DWLRQ
ƒ &DQEHFRPELQHZLWKWUDGLWLRQDO+0&

2QHRUWZR+0&V 2QHY+0&DQGRQH+0& 2QHRUWZRY+0&V

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-33. VHMC (2 of 2)

IBM Virtual HMC requirements:


• x86 64-bit hardware with hardware virtualization assists (Intel VT-x or AMD-V).
• Resources for the HMC virtual appliance VM:
▪ Four CPUs
▪ 8 GB of memory
▪ 160 GB of disk space
▪ 2 network interfaces
• License plus software maintenance (PID – 5765-HMV)
• Virtualization: Either VMware ESXi V5 or Red Hat Enterprise Linux 6.x with KVM

© Copyright IBM Corp. 1995, 2017 9-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&DQGPDQDJHGV\VWHP
*UDSKLFUHSUHVHQWDWLRQRIUHODWLRQVKLSVEHWZHHQ
ƒ +0&
ƒ 6HUYLFHSURFHVVRU
ƒ +\SHUYLVRU

9LUWXDO6HUYHU 3DUWLWLRQV :KHQDFWLYH +0&

+\SHUYLVRU26LQGHSHQGHQW
1RQYRODWLOH5$0

3URFHVVRUV
6HUYLFH
SURFHVVRU 9LUWXDOVHUYHUVFRQVLVWRIGLIIHUHQW
0HPUHJLRQV 9LUWXDO HOHPHQWV ORRNDWFRORUV 
6HUYHU ‡ 3URFHVVRUV
,2VORWV
/3$5 0DQDJHG ‡ 0HPRU\
DOORFDWLRQ
WDEOHV
V\VWHP ‡ ,2VORWV
‡ 6RPHSDUWRI+\SHUYLVRU
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-34. HMC and managed system

On the visual, you can see how HMC fit to the whole picture

© Copyright IBM Corp. 1995, 2017 9-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU6\VWHPVPDQDJHPHQW6XPPDU\
3RZHU6\VWHPV
5DFNPRXQW
$60,RQO\ ,90RQO\ 'HVNWRS+0&
+0&
ƒ 1R/3$5 ƒ (QWU\OHYHO/3$5 ƒ %DVLFGHVNWRS ƒ ³6WDFNDEOH´ZLWK
ƒ /LPLWHG&R' FRQWUROVIURP,90 ZRUOGZLGHVXSSRUW VKDUHGIODW
ƒ %DVLFVHUYLFHIXQFWLRQV EDVHGRQ$,;9,2 ORQJSURGXFWLRQF\FOH SDQHONH\ERDUGGUDZHU
6HUYHU 9,26 ƒ )XOOIXQFWLRQ/3$5 ZHOOVXLWHGIRUFOXVWHUV
ƒ /LPLWHG&R' FRQWUROV ƒ )XOOIXQFWLRQ/3$5
ƒ /LPLWHGVHUYLFH ƒ )XOOVHUYLFHIXQFWLRQV FRQWUROV
IXQFWLRQV ƒ 9LUWXDO26FRQVROHV ƒ )XOOVHUYLFHIXQFWLRQV
ƒ 5HGXQGDQW+0& ƒ 9LUWXDO26FRQVROHV
RSWLRQDO ƒ 5HGXQGDQW+0&
RSWLRQDO

$60,77< %URZVHU
WR WR
)63GLUHFWO\ 9,26
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-35. Power Systems management: Summary

On this summary visual, you can see all available Power Systems management technology
You can use the Integrated Virtualization Manager (IVM), a component of the PowerVM Editions
hardware feature to manage your Virtual I/O Server and client partitions.
• IVM
The Integrated Virtualization Manager (IVM) provides a web-based system management
interface and a command-line interface that you can use to manage some IBM® Power
Systems™ servers and some IBM BladeCenter blade servers that use the IBM Virtual I/O
Server. On the managed system, you can create partitions, manage virtual storage and virtual
Ethernet, and view service information related to the server. The IVM is included with the Virtual
I/O Server, but it is available and usable only on certain platforms, and where no Hardware
Management Console (HMC) is present.
• ASMI
Advanced System Management Interface (ASMI) is a graphical interface that is part of the
service processor firmware. The ASMI manages and communicates with the service processor.
The ASMI is required to set up the service processor and to perform service tasks, such as
reading service processor error logs, reading vital product data, and controlling the system
power.

© Copyright IBM Corp. 1995, 2017 9-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
The ASMI might also be referred to as the service processor menus.
Depending on your configuration, you can access the Advanced System Management Interface
(ASMI) through a web browser, an ASCII terminal, or the Hardware Management Console
(HMC).
If your system is managed by an HMC, you can access the ASMI through the HMC.
If your system is not managed by an HMC, you must connect the server to a terminal or PC and
apply power. You can power the system on and off using the Power button on the control panel
(operator panel) or the ASMI.

© Copyright IBM Corp. 1995, 2017 9-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&VSHFLILFDWLRQ
‡ &5
ƒ *+],QWHO;HRQ3URFHVVRU
ƒ *%WR*%PHPRU\ (0*%IHDWXUHFRGH 
í 0RVWFOLHQWVH[SHFWHGWRXVH*%RU*%IRU+0&
ƒ 2QHRURSWLRQDOO\WZR*%6$7$GLVNGULYHV
í 6HFRQGGULYHDOORZV5$,'PLUURULQJSURWHFWLRQ UHFRPPHQGHGGHIDXOWHG
í 6XSSRUWDQ\WZRRIWKHHLJKWSK\VLFDOKRWSOXJ6))ED\V PD[WZRVXSSRUWHG
ƒ '9'5$0
ƒ )RXULQWHJUDWHG(WKHUQHWSRUWV
ƒ 6L[86%SRUWV
ƒ 2QH3&,HVORW
ƒ 2QHRUWZRSRZHUVXSSOLHV WZRUHFRPPHQGHGIRUKRWSOXJUHGXQGDQF\
ƒ 8 (,$
ƒ /LNH&5GRHVQRWRIIHUDQLQWHUQDORUH[WHUQDOPRGHP RUVXSSRUWRQH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-36. HMC specification

© Copyright IBM Corp. 1995, 2017 9-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&LQWHUIDFHV
&ODVVLFPRGH

(QKDQFHGPRGH

&RPPDQGOLQH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-37. HMC interfaces

You can use local or remote access and interfaces in order to manage your systems.
Note you can also connect to HMC command line local or remotely using SSH (Secure Shell).
For GUI you can choose classic mode or enhanced mode. You can select which software interface
to use when you log in to the HMC. The HMC Classic interface provides access to all traditional
functions of the HMC and the HMC Enhanced interface provides both redesigned and new
virtualization tasks and functions.

© Copyright IBM Corp. 1995, 2017 9-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&LQWHUIDFHVFODVVLFYHUVXVHQKDQFHG

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-38. HMC interfaces classic versus enhanced

On the table you can compare differences between HMC mode

© Copyright IBM Corp. 1995, 2017 9-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+0&XVHULQWHUIDFHVDQGDFFHVV
‡ /RFDO*8, RQ+0&
ƒ 6WDUWVDXWRPDWLFDOO\ZKHQHYHUWKH+0&LVVWDUWHG
ƒ 5HTXLUHVXVHUORJLQSULRUWRDFFHVV
‡ 5HPRWH*8, RQQHWZRUN3&
ƒ 8VHVDZHEEURZVHUWRFRQQHFWWR+0& QRWDOOIXQFWLRQVDYDLODEOH
ƒ &DQEH66/VHFXUHG
‡ &RQVROH
ƒ /RFDO&RQVROH
ƒ 5HPRWHXVHV,%0L$FFHVV&OLHQW6ROXWLRQV &RQVROH
‡ /RFDOFRPPDQGOLQH RQ+0&
ƒ /DXQFKHGIURPDULJKWFOLFNPHQXRSWLRQRQWKH+0&GHVNWRS
ƒ 5HVWULFWHGWRDVHWRIVXSSRUWHG+0&FRPPDQGV
‡ 5HPRWHFRPPDQGOLQH RQQHWZRUN3&
ƒ $FFHVVHGWKURXJKHQFU\SWLRQSURWHFWHG6HFXUH6KHOO 66+
ƒ &DQVHWXSDQGH[FKDQJHNH\ILOHVWRDYRLGSDVVZRUGSURPSWV
í 9HU\XVHIXOIRUDXWRPDWLRQDQGVFULSWLQJZLWKRXWKXPDQLQWHUYHQWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-39. HMC user interfaces and access

© Copyright IBM Corp. 1995, 2017 9-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HPRWHDFFHVVWRWKH+0&

5HPRWHFRQVROH 1HWZRUN
VHVVLRQ
:HEEURZVHU
5HPRWHFRPPDQGOLQH

5HPRWH+0& /RFDO+0&
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-40. Remote access to the HMC

The local HMC is connected to the managed system through the Flexible Service Processor (FSP)
interface. The FSP has second interface to connect remote HMC. Practically when customer has
two servers PROD and HA/DR should have installed two HMC and each console should manage
each server for redundancy.
Remotely you can connect to the HMC using IBM i Access Client Solutions 5250 Console and open
console for selected partition.
You can also open 5250 session under IBM i Access Client Solutions.
Using web browser you can connect to HMC graphic interface.
To manage server and partitions you can connect to HMC using SSH this is useful for any
automation especially when the environment has a lot of partitions. Using SSH you can open
remote console for VIOS.

© Copyright IBM Corp. 1995, 2017 9-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

'\QDPLFSDUWLWLRQLQJ
‡ '\QDPLFSDUWLWLRQLQJ '/3$5 LVWKHDELOLW\WRDGGUHPRYHRUPRYH
UHVRXUFHVEHWZHHQSDUWLWLRQVZLWKRXWUHVWDUWLQJWKHSDUWLWLRQV
‡ 5HVRXUFHV
ƒ 3URFHVVRUVPHPRU\DQG,2VORWVWKDWDUHQRWUHTXLUHG
ƒ 9LUWXDO,2
‡ 6HFXULW\DQGLVRODWLRQEHWZHHQ/3$5VLVQRWFRPSURPLVHG
ƒ $SDUWLWLRQVHHVLWVRZQUHVRXUFHVSOXVRWKHUDYDLODEOHUHVRXUFHV
ƒ 5HVRXUFHVDUHUHVHWZKHQPRYHG
‡ $SSOLFDWLRQVPLJKWRUPLJKWQRWEH'/3$5DZDUH

'/3$5DOORZV\RXWRUHDFWWR
FKDQJLQJUHVRXUFHQHHGV
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-41. Dynamic partitioning

Dynamic partitioning
Dynamic partitioning refers to the fact that you can add, remove resources or switch resources
between partitions without shutting down the partitions. The opposite of dynamic partitioning is
static partitioning, where new configurations are only used when a partition is reactivated.
DLPAR operations do not weaken the security or isolation between LPARs. Partitions only see
resources in its own partition, any potential connectors for additional virtual resources that may
have been configured, and any resources not currently allocated.
Resources are reset when moved from one partition to another. Processors are reinitialized,
memory regions are cleared, and adapter slots are reset.
DLPAR operations
You can add, remove, and move resources between partitions. This can be accomplished from the
HMC application or through HMC command-line commands.
With virtual devices, you may add or delete them, but you cannot move them from one partition to
another. However, you can dynamically change the configuration that specifies what type of virtual
adapter it is.

© Copyright IBM Corp. 1995, 2017 9-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

+RZ'/3$5ZRUNV

+0&
+0&FRPPDQG

3DUWLWLRQ$ 3DUWLWLRQ%

32:(5+\SHUYLVRU
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-42. How DLPAR works

Dynamic Logical Partitioning (DLPAR): A facility in some IBM POWER processors that provide
the ability to logically attach and detach a managed system's resources to and from a logical
partition's operating system without rebooting the system. The following features are available in a
DLPAR:
Capacity on Demand (CoD): A feature of IBM Power Systems servers that you can use to activate
preinstalled but inactive processors when resource requirements change.
Dynamic Processor Deallocation: A feature of IBM Power Systems servers and some SMP
models. The processor is taken offline dynamically when an internal threshold of recoverable errors
is exceeded. DLPAR allows substitution of the inactive processor, for the processor that is
suspected of being defective. This online switch does not affect applications and kernel extensions.
Cross-partition workload management: A feature that is used to manage system resources
across partitions.

© Copyright IBM Corp. 1995, 2017 9-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3URFHVVRUFRQFHSWV

/3$5 /3$5 /3$5 9LUWXDO

6KDUHG

'HGLFDWHG

,QDFWLYH &R'

'HFRQILJXUHG

3K\VLFDO
LQVWDOOHG

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-43. Processor concepts

Micro-Partitioning is a mainframe-inspired technology that is based on two major advances in the


area of server virtualization. Physical processors and I/O devices have been virtualized, enabling
these resources to be shared by multiple partitions. There are several advantages associated with
this technology, including finer grained resource allocations, more partitions, and higher resource
utilization.
In the Micro-Partitioning model, physical processors are abstracted into virtual processors, which
are assigned to partitions. These virtual processor objects cannot be shared, but the underlying
physical processors are shared, since they are used to actualize virtual processors at the platform
level. This sharing is the primary feature of this new partitioning model, and it happens
automatically.
Note that the virtual processor abstraction is implemented in the hardware and the POWER
Hypervisor, a component of firmware. From an operating system perspective, a virtual processor is
indistinguishable from a physical processor. The system administrator defines the number of virtual
processors that may be utilized by a partition as well as the actual physical processor capacity that
should be applied to actualize those virtual processors. The system administrator may specify that
a fraction of a physical processor be applied to a partition enabling fractional processor capacity
partitions to be created.

© Copyright IBM Corp. 1995, 2017 9-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Virtual processors
These are the whole number of concurrent operations that the operating system can use on a
partition. The processing power can be conceptualized as being spread equally across these virtual
processors. Selecting the optimal number of virtual processors depends on the workload in the
partition. Some partitions benefit from greater concurrence, where other partitions require greater
power.
Dedicated processors
Dedicated processors are whole processors that are assigned to a single partition. If you choose to
assign dedicated processors to a logical partition, you must assign at least one processor to that
partition.
By default, a powered-off logical partition using dedicated processors will have its processors
available to the shared processing pool. When the processors are in the shared processing pool,
an uncapped partition that needs more processing power can use the idle processing resources.
However, when you power on the dedicated partition while the uncapped partition is using the
processors, the activated partition will regain all of its processing resources. If you want to prevent
dedicated processors from being used in the shared processing pool, you can disable this function
using the logical partition profile properties panels on the Hardware Management Console.
Shared processor pool
The POWER Hypervisor schedules shared processor partitions from a set of physical processors
that is called the shared processor pool. By definition, these processors are not associated with
dedicated partitions.
Deconfigured processor
This is a failing processor left outside the system's configuration after a dynamic processor
deallocation has occurred.
Inactive (CoD)
Installed but not activated processor units. Can be activated by Capacity on Demand (CoD) code.

© Copyright IBM Corp. 1995, 2017 9-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

0LFUR3DUWLWLRQLQJ
‡ 7LPHVOLFHGVXESURFHVVRUDOORFDWLRQVDUHGLVSDWFKHGDFFRUGLQJWR
GHPDQGDQGHQWLWOHGFDSDFLW\
3K\VLFDO
SURFHVVRUV

3DUWLWLRQ
3 3 3 3 3DUWLWLRQ
t=0 3DUWLWLRQ
3DUWLWLRQ
3DUWLWLRQ
3DUWLWLRQ
3DUWLWLRQ

6KDUHGSURFHVVLQJSRRO
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-44. Micro-Partitioning

Micro-Partitioning
Micro-Partitioning is defined as the ability to create a partition and allocate less than a full processor
to it. Processing power may be allocated to partitions using dedicated processors or shared
processors. For shared processors, partitions may allocate processing power in processing units
that are equivalent of part of the execution capacity of a physical processor.
The visual above shows seven partitions each time-slicing on four physical processors that are part
of the shared processing pool. “t” shows the time scale. Each partition gets a percentage of the
execution dispatch time on the processors in the pool, based on its capacity assignment. We will
come back to this later. This page is here to give you some basic terminology until we reach the
advanced processor topic later in this course.

© Copyright IBM Corp. 1995, 2017 9-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

6LQJOH 6KDUHG 3RROZLWK&DSSHGDQG8QFDSSHG 3DUWLWLRQV


6HUYHUZLWKSURFHVVRUFRUHV
' (
&DSSHG 8QFDSSHG
$,; ,%0L

93  93 
(&  (& 

$ % &
,%0L $,; /LQX[
6KDUHG3RRO SURFHVVRUFRUHV
           

3DUWLWLRQ'FRUHVWROLFHQVH /LFHQVH5XOHV
‡ )RXUIURP(&IRUFDSSHG ƒ )RU&DSSHG3DUWLWLRQV7KHKLJKHVW OHYHORI(QWLWOHG&DSDFLW\ (& 
ƒ (&ZDVIRUPHUO\UHIHUUHGWRDV3URFHVVLQJ8QLW 3U8 
SDUWLWLRQ
ƒ )RU8QFDSSHG3DUWLWLRQV7KHKLJKHVW QXPEHURI2QOLQH93 9LUWXDO3URFHVVRUV
ƒ 6KDUHG3RROWKHORZHURIWKHVXPRIHDFKSDUWLWLRQIRUDSURGXFWRUWKHSURFHVVRU
3DUWLWLRQ(FRUHVWROLFHQVH FDSDFLW\RIWKHVKDUHGSRRO
‡ 6HYHQIURP93IRUXQFDSSHG
SDUWLWLRQ 7KHJUHDWHURIZKDWWKHSDUWLWLRQVWDUWVZLWKRUWKHUHVXOWRID'/3$5RSHUDWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-45. Single Shared Pool with Capped and Uncapped Partitions

Shared processors Partition (Also known as Micro-partition LPAR):


A logical partition that utilizes processor resources from the shared processing pool using
Micro-Partitioning technology are referred to as shared processor partitions.
The processing unit assigned to a shared processors partition is known as processor
entitlement, or entitled capacity. A shared processors partition can be defined as “capped” or
“uncapped”
The POWER Hypervisor automatically moves processor core resources among partitions
based on each partition’s entitled capacity, “capped or uncapped” attributes, and its load
Capped partition:
This type of shared processor partition can never be allocated processing capacity that is more
than its Entitled Capacity
Uncapped partition:
This type of shared processor partition can be allocated processing capacity that can exceed its
Entitled Capacity. It can access the unused processor cores in the shared pool, when available,
up to the Online VP value (VP).

© Copyright IBM Corp. 1995, 2017 9-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Micro-Partitioning:
The ability to divide a physical processor’s computing power into fractions of a processing unit
and share them among multiple logical partitions.
To obtain the number of license entitlements the customer should acquire, add up the total
number of cores per server then round up to the next whole number of processor cores
(aggregate and round up, by server)
Processor units are allocated in increments of 0.01 processor core
Multiple Shared Pools:
A POWER6 capability that allows the physical shared processor pool to be subdivided into
multiple virtual pools. LPARs that are part of a shared pool are limited by the number of
processor resources in that pool. There is only one level of pool nesting. The virtual shared
pools are always a child to the physical shared processor pool. POWER5 systems only have
the physical shared processor pool

© Copyright IBM Corp. 1995, 2017 9-68


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&DSDFLW\RQGHPDQG
‡ &DSDFLW\RQ'HPDQG &R'
ƒ 3HUPDQHQWWHPSRUDU\DFWLYDWLRQRISURFHVVRUVRUPHPRU\
‡ 7ULDO&R'
ƒ 1RFKDUJHGD\DFWLYDWLRQRISURFHVVRUVRUPHPRU\
UHVRXUFHV
‡ 2Q2II&R' (ODVWLF&R'
ƒ $ELOLW\WRDFWLYDWHSURFHVVRURUPHPRU\UHVRXUFHV
$GGUHVHUYH
WHPSRUDULO\
UHVRXUFHV
‡ 3RZHU(QWHUSULVH3RRO&R'
ƒ 0RYHSHUPDQHQWSURFHVVRURUPHPRU\DFWLYDWLRQIURPRQH
VHUYHUWRDQRWKHU

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-46. Capacity on demand

With Capacity on Demand (CoD) offerings, you can dynamically activate one or more resources on
your server as your business peaks dictate. You can activate inactive processor cores or memory
units that are already installed on your server on a temporary and permanent basis.
Capacities on demand offerings are available on select IBM servers. For ordering information, see
the POWER8 machine type/model tables within each CoD offering section of this document. Some
servers include a number of active and inactive resources. Active processor cores and active
memory units are resources that are available for use on your server. Inactive processor cores and
inactive memory units are resources that are included with your server, but are not available for use
until you activate them.
Capacity Upgrade on Demand (CUoD), you can activate additional processor cores and memory
units on selected servers by purchasing a permanent processor or memory unit activation feature.
CUoD adds capacity for new workloads, which enables your server to adapt to unexpected
performance demands.
Elastic Capacity on Demand (CoD) (formerly referred to as On/Off CoD) allows you to temporarily
activate and deactivate processor cores and memory units to help meet the demands of business
peaks. After you request that a number of processor cores or memory units are to be made
temporarily available for a specified number of days, those processor cores and memory units are

© Copyright IBM Corp. 1995, 2017 9-69


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
available immediately. You can start and stop requests for Elastic CoD, and you are billed for usage
at the end of each quarter.
Power Enterprise Pool provides flexibility and value for Power Systems. A Power enterprise pool is
a group of systems that can share Mobile Capacity on Demand (CoD) processor resources and
memory resources.

© Copyright IBM Corp. 1995, 2017 9-70


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

9LUWXDO,2
‡ (DFKSDUWLWLRQKDVYLUWXDO,2VORWV
ƒ 7KLVLVFRQILJXUDEOHIRUHDFKSDUWLWLRQ

‡ 6ORWVFDQKDYHDYLUWXDODGDSWHULQVWDQFH
ƒ 7KLVFDQEH(WKHUQHWVHULDO)LEUH&KDQQHORU6&6,

‡ ,WFDQEHG\QDPLFDOO\DGGHGRUUHPRYHGMXVWOLNHSK\VLFDO,2VORWV
ƒ ,WFDQQRWEHG\QDPLFDOO\PRYHGWRDQRWKHUSDUWLWLRQ
ƒ 7KHFRQILJXUDWLRQRIZKDWLVLQWKHVORWFDQEHUHGHILQHGZLWKRXWDUHVWDUWRI
WKHSDUWLWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-47. Virtual I/O

Virtual I/O basics


Each partition, by default, has two virtual Serial I/O slots (which are already used by system
functions - HMC console and debugging) and cannot be used or modified by the end user.
Additional slots can be configured and populated with a virtual adapter instance that allows
partitions to share devices. It also provides virtual Ethernet connections between partitions on the
same IBM Power System.
Virtual adapters interact with the operating system like any other adapter card, except that they are
not physically present. Virtual adapters are recorded in IBM Power System inventory and
management utilities.
As with physical I/O adapters, a virtual I/O adapter must first be varied off from the operating
system to perform a DLPAR remove operation.
Virtual Ethernet
Virtual Ethernet provides the same function as using an Ethernet adapter and is implemented
through high-speed, inter-partition, in-memory communication. Each partition can connect to
multiple networks through one or more adapters (using a virtual switch).

© Copyright IBM Corp. 1995, 2017 9-71


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Virtual serial
The virtual serial option is typically used for virtual console access.
Virtual SCSI
The virtual SCSI option provides access to block storage devices in other partitions such as device
sharing. It uses the client/server model where the server exports disks, logical volumes, or other
SCSI-based devices, and the client sees the imported device as a standard SCSI device. space to
other partitions. Disk unit, DVD, and tape devices on an IBM Power System are based on the SCSI
protocol.
Virtual Fibre Channel
The virtual Fibre Channel provides access to disks, logical volumes, or tape libraries using.

© Copyright IBM Corp. 1995, 2017 9-72


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

/3$5FRQILJXUDWLRQSURFHVV

 *DWKHUSDUWLWLRQUHTXLUHPHQWVWKURXJKH[LVWLQJGDWDRUPRGHOLQJ

 3ODQUHVRXUFHVIRUSDUWLWLRQV 637 

 6HWXS+0&

 3RZHURQDQGVHWXSPDQDJHGV\VWHP

 &UHDWHDQGFRQILJXUHSDUWLWLRQV

 $FWLYDWHSDUWLWLRQVDQGLQVWDOORSHUDWLRQV\VWHPV

 &RQILJXUHDQGWHVWVHUYLFHDSSOLFDWLRQV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-48. LPAR configuration process

These are the overall steps for configuring partitions on a new POWER8 LPAR-capable system.
Step 1: Plan for usage model and applications
The Step 1 is a system sizing process. As part of this step you should have some idea about how to
divide up the applications into partitions. You should also plan for future needs such as partitions for
development and testing.
Step 2: Plan resources for partitions
Planning the resource allocations for partitions is the most important step in the configuration
process because it will hopefully eliminate errors and multiple reconfigurations later in the process.
Planning is crucial because with multiple partitions the configuration information becomes quite
complex very quickly. This is particularly true for the network configuration of your partitions and the
HMC.
You should plan for the “normal” operation of the application in a partition and for best case and
worst case scenarios. It is important to document all configurations and keep the records up to
date.

© Copyright IBM Corp. 1995, 2017 9-73


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Step 3: Set up the HMC
Once the hardware has been delivered, set up the HMC. The HMC can (and should) be set up and
ready to go long before the managed IBM Power System is even powered on. Since the HMC has
its own operating system, it can be configured independently of any other hardware.
Step 4: Power on and set up the HMC managed system
The HMC must be configured to support the managed system. Then, when you power on the
managed system from the HMC. For new managed systems and HMCs before you start partitions
configuration check available updated of Power system firmware and HMC updates. After
installation go next step.
Step 5: Create and configure partitions
You must plan, create, and configure each logical partition. Configuring a partition consists of
allocating resources and setting other configuration options. If you want you can use templates to
create new partition.
Step 6: Activate partitions and install operating systems
At this point, you can activate each partition and install an operating system – if necessary.
Step 7: Configure and test service applications
Since IBM cannot predict how a particular system might be divided into separate operating system
environments, you may need to alter the configuration of the service applications, such as Service
Agent and Service Focal Point.

© Copyright IBM Corp. 1995, 2017 9-74


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

:KHUHFDQ,ILQGPRUHLQIRUPDWLRQRQ/3$5"
‡ (GXFDWLRQ
86* PowerVM on IBM i BootCamp

2/ Hardware Management Console (HMC) for Power


Systems with IBM i
$6(* PowerVM on IBM i

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-49. Where can I find more information on LPAR?

© Copyright IBM Corp. 1995, 2017 9-75


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
9.3. Topic 3: Clustering

© Copyright IBM Corp. 1995, 2017 9-76


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLF&OXVWHULQJ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-50. Topic 3: Clustering

© Copyright IBM Corp. 1995, 2017 9-77


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU+$6\VWHP0LUURU
‡ 3RZHU6\VWHPV+LJK$YDLODELOLW\6ROXWLRQ)RUPLVVLRQFULWLFDO
DSSOLFDWLRQDYDLODELOLW\WKURXJKSODQQHGDQGXQSODQQHGRXWDJHHYHQWV

‡ (GLWLRQVWDUJHWHGDWGDWDFHQWHUDQGRUPXOWLVLWHGHSOR\PHQWVYDOXH
JURZVLQIHDWXUHDQGIXQFWLRQZLWKHDFKQHZUHOHDVH

‡ 6KDUHG6WRUDJH&OXVWHULQJ7HFKQRORJ\GHVLJQHGIRUDXWRPDWLRQDQG
PLQLPDO,7RSHUDWLRQV

‡ 'HHS,QWHJUDWLRQIRUVLPSOLFLW\DQGUHOLDELOLW\

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-51. PowerHA SystemMirror

Complete IBM Power Systems integrated end to end solutions for HA DR


• Focus: 24x 7 Application availability through planned or unplanned outage events
• Deeply integrated extension of host operating system (AIX, IBM i)
• Developed and supported by the Power Systems engineering development team
HA Clustering technology
• Clustering provides the applications a complete resiliency infrastructure
• Cluster monitors and manages primary and secondary resources for HADR operations
Storage based data resiliency
• Data resiliency is an extension of the host system storage management architecture
• Storage volumes are either switchable or mirrored between nodes in the cluster
• Hardware based replication services for Multi-Site Operations
▪ Host Based Replication (geomirroring for IBM i, or GLVM for AIX)
▪ Storage Base Replication (Metro Mirror or Global Mirror)

© Copyright IBM Corp. 1995, 2017 9-78


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
Overall solution characteristic
• Automation, minimal IT operations involvement
• Data between primary and secondary nodes always in sync always ready for a failover event

© Copyright IBM Corp. 1995, 2017 9-79


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU+$6\VWHP0LUURU VROXWLRQVRYHUYLHZ
([WHQGHGRSWLRQVIRUDQ,%0GHOLYHUHGHQGWRHQGVROXWLRQIRU+$'5DQGEDFNXSV

3RZHU+$6\VWHP0LUURUIRUL
+$6 ± 
End-to-End Solution

/DE
3RZHU+$ +$6ZLWFKDEOH5HVRXUFHV ,%0LIHDWXUHRSWLRQ LQFOXGHG 6HUYLFHV
VROXWLRQV
,%0L&OXVWHUVDQG&OXVWHU5HVRXUFH6HUYLFHV
'6&/,'6&RPPDQG/LQH,QWHUIDFH
*HRJUDSKLF *HRJUDSKLF 0HWUR *OREDO )ODVK&RS\
0LUURULQJ 0LUURULQJ 0LUURU 0LUURU ‡'6
‡ 6\QFK ‡ $V\QFK ‡6\QFK ‡$V\QFK ‡69&
‡ $Q\VWRUDJH ‡ $Q\VWRUDJH ‡'6 ‡'6 ‡9
‡ 'LUHFWDWWDFKHG ‡ 'LUHFW9,26 ‡69& ‡69& ‡9
‡ 6$1DWWDFKHG ,%0L+RVWHG ‡9 ‡9 ‡9
VWRUDJH ‡9 ‡9
‡ 9,26RU,%0L ‡6SDFH
+RVWHG6WRUDJH ‡13,9 ‡9 (IILFLHQW
‡13,9 ‡13,9

,QGHSHQGHQW&RS\6HUYLFHV0DQDJHU ,&60 )XOO6\VWHP)ODVK&RS\0DQDJHU )6)&0 )XOO6\VWHP5HSOLFDWLRQ )65

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-52. PowerHA SystemMirror solutions overview

The IBM PowerHA SystemMirror for i solution offers a complete end-to-end integrated clustering
solution for high availability (HA) and disaster recovery (DR). PowerHA provides a data and
application resiliency solution that is an integrated extension of IBM i operation system and storage
management architecture and has the design objective of providing application high availability
through both planned and unplanned outages.
A key characteristic of PowerHA, is that the solution is automated. Because the data resiliency is
completely managed within the IBM i storage management architecture, there is no operator
involvement, just as there is no operator involvement with RAID 5 or disk mirroring.
Geographic mirroring offers IBM i customers an IBM i-based page-level replication solution for
implementing high availability and disaster recovery with any kind of IBM i-supported internal or
external storage solution.
With IBM System Storage DS8000 series or SAN Volume Controller (SVC)/Storwize V7000, V5000,
V3700 storage servers clients are able to exploit storage-based remote replication functions for
high availability and disaster recovery, LUN-level switching for local high availability, and FlashCopy
for reducing save window outages by enabling the creation of a copy that is attached to a separate
partition for offline backup to tape.

© Copyright IBM Corp. 1995, 2017 9-80


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU+$6\VWHP0LUURU(GLWLRQV
‡ 3RZHU+$6\VWHP0LUURU([SUHVV(GLWLRQ
ƒ +\SHU6ZDS
‡ 3RZHU+$6\VWHP0LUURU6WDQGDUG(GLWLRQ
‡ &OXVWHUPDQDJHPHQWIRUWKHGDWDFHQWHU
ƒ 0RQLWRUVGHWHFWVDQGUHDFWVWRHYHQWV
ƒ (VWDEOLVKHVDKHDUWEHDWEHWZHHQWKHV\VWHPV
ƒ (QDEOHVDXWRPDWLFVZLWFKRYHU
‡ ,%0VKDUHGVWRUDJHFOXVWHULQJ
ƒ &DQHQDEOHQHDUFRQWLQXRXVDSSOLFDWLRQVHUYLFH
ƒ 0LQLPL]HLPSDFWRISODQQHGDQGXQSODQQHGRXWDJHV
ƒ (DVHRIXVHIRU+$RSHUDWLRQV
‡ 3RZHU+$6\VWHP0LUURU(QWHUSULVH(GLWLRQ
‡ &OXVWHUPDQDJHPHQWIRUWKH(QWHUSULVH
ƒ 0XOWLVLWHFOXVWHUPDQDJHPHQW
ƒ ,QFOXGHVWKH6WDQGDUG(GLWLRQIXQFWLRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-53. PowerHA SystemMirror Editions

PowerHA SystemMirror for i Express Edition


This edition is designed to be the foundation for a class of disaster recovery offerings based on
restarting the LPAR into another LPAR on a different server for DR operations. The express edition
differs from the standard edition in that the database is not placed into an IASP separate from
SYSBAS. Rather, a primary LPAR is restarted or IPLd to a target LPAR on another server. With
PowerHA Express Edition offering enables single node full system IBM HyperSwap (external
storage only) which provides customers with continuously available storage through either planned
or unplanned storage events. With HyperSwap technologies, the act of moving between storage
servers is nearly seamless.
PowerHA SystemMirror for i Standard Edition
The IBM PowerHA SystemMirror for i standard edition helps you to protect your critical business
applications from planned or unplanned outages in the data center (a single-site solution using
switchable LUNs or geomirror synchronous mode). The standard edition provides reliable
monitoring, failure detection, and automated recovery of business application environments. It
provides the capability to monitor various event sources such as the HMC, Power Systems, and
storage server for a comprehensive list of errors, from hardware and network to application or
environmental (for example power loss) enabling automated or operator-initiated actions. PowerHA

© Copyright IBM Corp. 1995, 2017 9-81


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
SystemMirror Standard Edition supports LUN level switching for the IBM DS8000 and the IBM
Storwize family of storage servers.
IBM PowerHA SystemMirror for IBM i enterprise edition
The PowerHA SystemMirror for IBM i Enterprise Edition includes all of the capabilities of the
Standard Edition and more. The Enterprise Edition package enables you to extend your data center
solution across two sites. PowerHA SystemMirror Enterprise Edition includes support for DS8000,
SVC, and the Storwize family of storage servers with either Metro Mirror or Global Mirror and with
7.3 of PowerHA SystemMirror, the Enterprise Edition also includes support for geomirroring
asynchronous mode. Geomirroring synchronous mode support is included with the PowerHA
SystemMirror Standard Edition.
Geographic mirroring is the IBM i host-based mirroring over IP network solution that enables small
clients to set up a geographically dispersed two node PowerHA SystemMirror cluster using either
internal or external disk. The geographic mirroring solution can lower your total cost of ownership in
comparison to software replication options in both cost of acquisition and operational management
costs. The geomirror async mode support with PowerHA SystemMirror 7.3 enables clients to
extend the PowerHA SystemMirror cluster between sites with virtually unlimited distance.
The Enterprise Edition is essential for clients who must protect themselves from site-wide failures
or large-scale disasters by mirroring business-critical data across two sites while enabling
automated failover to the remote location. This applies to businesses of any size with multiple sites,
regional operations or wherever decentralization of data is wanted. The Enterprise Edition offers
multiple technologies for achieving long distance data mirroring, failover, and resynchronization.
The Enterprise Edition with the included geographic mirroring option provides asynchronous data
mirroring and failover to remote sites. Users deployed with the Standard Edition can readily expand
capabilities with the Enterprise Edition to deploy a highly resilient geographically dispersed
environment.
The Enterprise Edition supports Metro Mirror and Global Mirror with the DS8000, the SAN Volume
Controller (SVC), and the Storwize family of storage servers, enabling automatic failover or planned
switchover for semi-annual compliance testing. By automating the management of Metro Mirror or
Global Mirror, recovery time is minimized after an outage, regardless of whether the clustered
environment is local or geographically dispersed. The Enterprise Edition, in combination with Metro
Mirror or Global Mirror, manages a clustered environment to allow mirroring of critical data to be
maintained at all times. And let’s not forget about IBM FlashCopy which whether used with either
the Standard Edition or the Enterprise Edition enables you to create a point in time copy with almost
no disruption to your production environment that save window issue is gone. You can now backup
to tape at your convenience.
For clients wanting to support more complex configurations such as a campus two node cluster
with Metro Mirror in combination with a remote third node connected using Global Mirror IBM offers
PowerHA tools for IBM i option. This is a lab services offering that enables a customized
configuration to support your DS8000 PowerHA SystemMirror solution environment. The PowerHA
tool for IBM i automates virtually all of your HA/DR operations including FlashCopy.

© Copyright IBM Corp. 1995, 2017 9-82


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&OXVWHULQJ:KDWLVDFOXVWHU"

OS and other &OXVWHU


VW %DFNXS
OS and other
system data system data

&OXVWHUQRGH &OXVWHUQRGH
3ULPDU\ VW %DFNXS

‡ &OXVWHU
ƒ 3URYLGHVWKHFRPPXQLFDWLRQLQIUDVWUXFWXUHEHWZHHQV\VWHPV
DQGRUSDUWLWLRQV
ƒ )DFLOLWDWHVWKHH[HFXWLRQRIFOXVWHUHYHQWV
ƒ 6LPSOLILHGPDQDJHPHQWVLQJOHSRLQWRIFRQWURO

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-54. Clustering: What is a cluster?

With PowerHA SystemMirror, clustering is available to IBM i customers PowerHA SystemMirror:


• Delivers high availability (HA) and disaster recovery (DR) through IBM storage-based clustering
• Provides higher utilization and performance capabilities for scale-up computing
• Offers a simplified user interface, is economical and automated
• Delivers a low cost easy to use solution for small customers with internal disk
A cluster node is any IBM i system or partition that is a member of a cluster. Cluster nodes must be
interconnected on an IP network. A cluster node name is a one-to-eight character. cluster node
identifier. Each node identifier is associated with one or two IP addresses that represent the
system. Cluster communications that run over IP connections that provide the communications
path between cluster services on each node in the cluster. The set of cluster nodes that is
configured as part of the cluster is referred to as the cluster membership list.
A cluster consists of a minimum of two nodes.
A node of a cluster can fill one of three possible roles. These are the roles and associated
functions:
• Primary/source node
▪ The point of access for a resilient device.

© Copyright IBM Corp. 1995, 2017 9-83


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
▪ Contains the principal copy of any replicated resource.
▪ The current owner of any device resource.
• Backup node
▪ Can take over the role of primary access at failure of the current primary node.
▪ Contains a copy of the cluster resource.
▪ Copies of data are kept current using replication.
• Replicate node
▪ Has copies of cluster resources.
▪ Unable to assume the role of primary or backup.
However, in many publications you can find Primary/Backup node. For a better understanding, and
to avoid any mistakes it is better to use Preferred Source and Preferred Target (the roles points
physical location) and Current Production and Current Backup (point to current role depending on
switch or not).

© Copyright IBM Corp. 1995, 2017 9-84


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&OXVWHULQJ'HYLFH'RPDLQ

OS and other OS and other


system data &OXVWHU system data

3URGXFWLRQ
+$
*SYSBAS
*SYSBAS

&OXVWHUQRGH 'HYLFHGRPDLQ
&OXVWHUQRGH
3ULPDU\ ILUVW%DFNXS
Replication data

IASP IASP

‡ 'HYLFH'RPDLQ
ƒ 7KHGHYLFHGRPDLQGHILQHVWKHFOXVWHUQRGHVWKDWPD\VKDUH,$63V
ƒ (DFK,$63LVDVVLJQHGDXQLTXHDGGUHVVVSDFHZLWKLQWKHGHYLFHGRPDLQ
ƒ &DQQRWDOORZWZR,$63VZLWKWKHVDPHDGGUHVVVSDFHWRH[LVWRQWKHVDPH
,%0LQRGH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-55. Clustering: Device Domain

A device domain is the first of the cluster constructs to be defined when creating a switchable
resource. It is a logical construct within Cluster Resource Services that is used to ensure that there
are no configuration conflicts that prevent a switchover or failover.
The device domain is a subset of cluster nodes.
The set of configuration resources associated with a collection of resilient devices can be switched
across the nodes in the device domain. Resource assignments are negotiated to ensure that no
conflicts exist. The configuration resources assigned to the device domain must be unique within
the entire device domain. Therefore, even though only one node can use a. resilient device at any
given time, that device can be switched to another node and brought online.
These cluster resources are negotiated across a device domain to ensure that there are no
conflicts:
• IASP number assignments.
• IASPs are automatically assigned a number to IASP. The user can assign the IASP name.
• DASD unit number assignments.
• To keep from conflicting with the permanently attached disk units of each node, all IASP unit
numbers begin with a four.
• Virtual address assignments.

© Copyright IBM Corp. 1995, 2017 9-85


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&OXVWHULQJ&OXVWHU5HVRXUFH*URXS

OS and other OS and other


system data &OXVWHU system data

&OXVWHUUHVRXUFHJURXS
3URGXFWLRQ
&OXVWHUUHFRYHU\GRPDLQ +$
*SYSBAS
*SYSBAS

&OXVWHUQRGH &OXVWHUQRGH
3ULPDU\ 'HYLFHGRPDLQ
ILUVW%DFNXS
IASP IASP

Replication data

‡ &OXVWHU5HVRXUFH*URXS &5* 
ƒ 'HILQHVZKLFK,%0LQRGHVDUHSRWHQWLDOKRVWVIRUWKH,$63
ƒ 7KHUHFRYHU\GRPDLQ OLVWRIQRGHV LVRUGHUHG 7KLVGHWHUPLQHVUHSOLFDWLRQ
GLUHFWLRQ
ƒ $VZLWFKDEOH WDNHRYHU ,3DGGUHVVFDQDOVREHGHILQHGDQG3RZHU+$
DFWLYDWHVLWRQZKLFKHYHUQRGHLVFXUUHQWO\SULPDU\
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-56. Clustering: Cluster Resource Group

A cluster resource group is an IBM i system object that is a set or grouping of cluster resources.
The cluster resource group is a foundation for all types of resilience.
Resources that are available or known across multiple nodes within the cluster are called cluster
resources. A cluster resource can conceptually be any physical or logical entity (that is, database,
file, application, device). Examples of cluster resources include IBM i objects, IP addresses,
applications, and physical resources. When a cluster resource persists across an outage, that is
any single point of failure within the cluster, it is known to be a resilient resource. As such, the
resource is resilient to outages and accessible within the cluster even if an outage occurs to the
node currently hosting the resource. Cluster nodes that are grouped together to provide availability
for one or more cluster resources are called the recovery domain for that group of cluster
resources. A recovery domain can be a subset of the nodes in a cluster, and each cluster node
might participate in multiple recovery domains. Resources that are grouped together for the
purposes of recovery action or accessibility across a recovery domain are known as a cluster
resource group.

© Copyright IBM Corp. 1995, 2017 9-86


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
There are four cluster resource group (CRG) object types that are used with Cluster Resource
Services:
Application CRG
An application CRG enables an application (program) to be restarted on either the same node or a
different node in the cluster. The takeover IP address allows access to the
application without regard on which system the application is currently running. This capability
allows resilient applications to be switched from one node to another.
Data CRG
A data CRG enables data resiliency so that multiple copies of data can be maintained on more than
one node in a cluster. A data CRG does not do the replication, but uses the exit program to inform a
replication program when to start or end replication, and on which nodes to replicate. A data CRG
does not monitor for a data resource failure.
Device CRG
A device cluster resource group (CRG) supports device resiliency in IBM® i high availability
environments. Device CRGs can be used to control switchable resources in an
IBM i high availability environment. The device CRG contains a list of switchable devices. The
switchable devices include device descriptions such as an independent disk pool, tape or optical
device, line description, or network server. The entire collection of devices is switched to the
backup node when an outage, planned, or unplanned, occurs. Optionally, the devices can also be
made available (varied on) as part of the switchover or failover process.
Peer CRG
A peer CRG is a non-switchable cluster resource group in which each IBM i node in the recovery
domain plays an equal role in the recovery of the node. The peer cluster resource group provides
peer resiliency for groups of objects or services. The cluster resource group defines the recovery or
accessibility characteristics and behavior for that group of resources. A CRG describes a recovery
domain and supplies the name of the cluster resource group exit program that manages
cluster-related events for that group.
Recovery domain
A recovery domain is a subset of nodes in the cluster that are grouped together in a cluster
resource group for purposes such as performing a recovery action. Each cluster resource group
has a recovery domain that is a subset of the nodes in the cluster. Here are characteristics about
recovery domains:
• The nodes within a recovery domain participate in any recovery actions for the resources of the
domain.
• Different CRGs might have different recovery domains.
• As a cluster goes through operational changes (for example, nodes end, nodes start, nodes
fail), the current role of a node might change. Each node has a preferred role that is set when
the CRG is created.

© Copyright IBM Corp. 1995, 2017 9-87


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
CRG exit programs
In IBM i high availability environments, cluster resource group exit programs are called after a
cluster-related event for a CRG occurs and responds to the event.
An exit program is called when a CRG detects certain events, such as a new node being added to
the recovery domain, or the current primary node failing. The exit program is called with an action
code that indicates what the event is. Furthermore, the exit program has the capability to indicate
whether to process the event. User-defined simply means that the IBM i cluster technology does
not provide the exit program. Typically the exit program is provided by the application or data
replication provider. The exit program is the way that a CRG communicates cluster events to the
exit program provider. The exit program can perform the appropriate action based on the event,
such as allowing a resource access point to move to another node. The exit program is optional for
a resilient device CRG but is required for the other CRG types. When a cluster resource group exit
program is used, it is called on the occurrence of cluster-wide events.
For detailed information about the cluster resource group exit programs, including what information
is passed to them for each action code, see:
[Link]

© Copyright IBM Corp. 1995, 2017 9-88


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&OXVWHULQJ&OXVWHU$GPLQLVWUDWLYH'RPDLQ

OS and other OS and other


system data &OXVWHU system data

&OXVWHUUHVRXUFHJURXS
3URGXFWLRQ
&OXVWHUUHFRYHU\GRPDLQ +$
*SYSBAS
*SYSBAS

&OXVWHUQRGH &OXVWHU$GPLQLVWUDWLYH'RPDLQ &OXVWHUQRGH


3ULPDU\ 'HYLFHGRPDLQ VW %DFNXS

IASP IASP

Replication data
‡ $GPLQLVWUDWLYH'RPDLQ
ƒ /LVWRIFOXVWHUQRGHVWRV\QFKURQL]H 6<6%$6REMHFWV
ƒ ,QGHSHQGHQWRIWKHGDWDLQWKH,$63
‡ 0RQLWRUHG5HVRXUFH(QWULHV 05(¶V
ƒ 2EMHFWVLQWKH$GPLQ'RPDLQEHLQJV\QFKURQL]HG
ƒ 6SHFLILFDWWULEXWHVRIREMHFWVEHLQJV\QFKURQL]HG
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-57. Clustering: Cluster Administrative Domain

A cluster administrative domain provides a mechanism for maintaining a consistent operational


environment across cluster nodes within an IBM i high availability environment. A cluster
administrative domain ensures that highly available applications and data behave as expected
when switched to or failed over to backup nodes.
There are often configuration parameters or data associated with applications and application data,
which are known collectively as the operational environment for the application. Examples of this
type of data include user profiles used for accessing the application or its data, or system
environment variables that control the behavior of the application. With a high-availability
environment, the operational environment needs to be the same on every system where the
application can run, or where the application data resides. When a change is made to one or more
configuration parameters or data on one system, the same change needs to be made on all
systems.
A cluster administrative domain lets you identify resources that need to be maintained consistently
across the systems in an IBM i high availability environment. The cluster administrative domain
then monitors for changes to these resources and synchronizes any changes across the active
domain.

© Copyright IBM Corp. 1995, 2017 9-89


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
When a cluster administrative domain is created, the system creates a peer CRG with the same
name. The nodes that make up the cluster administrative domain are defined by the CRGs
recovery domain. Each cluster node can be defined in only one cluster administrative domain within
the cluster. After the cluster administrative domain is created, it can be managed with CL
commands or the Cluster Resource Services graphical interface in IBM Navigator for i.

© Copyright IBM Corp. 1995, 2017 9-90


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

&OXVWHULQJ&RS\'HVFULSWLRQDQG$636HVVLRQ
OS and other OS and other
system data &OXVWHU system data

&OXVWHUUHVRXUFHJURXS
3URGXFWLRQ
&OXVWHUUHFRYHU\GRPDLQ +$
*SYSBAS
*SYSBAS

&OXVWHUQRGH &OXVWHU$GPLQLVWUDWLYH'RPDLQ &OXVWHUQRGH


3ULPDU\ 'HYLFHGRPDLQ VW %DFNXS

IASP IASP

Replication data
ASP Copy Description ASP Copy Description
ASP Session
‡ &RS\'
ƒ 7KHFRS\GHVFULSWLRQGHVFULEHVRQHFRS\RIWKH,$63
ƒ *LYHV3RZHU+$DOOWKHLQIRUPDWLRQQHHGHGWRDFFHVVDQGFRQWUROWKH,$63
‡ 6HVVLRQ
ƒ 'HVFULEHVWKHUHODWLRQVKLSEHWZHHQFRS\GHVFULSWLRQV
ƒ :LOOGHWHUPLQHWKHW\SHRIUHSOLFDWLRQIURPDV\VWHPVWRUDJHSHUVSHFWLYH
ƒ 3RZHU+$XVHVWKHVHVVLRQWRFRQWUROWKHUHSOLFDWLRQ
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-58. Clustering: Copy Description and ASP Session

ASP Copy Descriptions are used by PowerHA to manage Geographic Mirror, Metro Mirror, Global
Mirror, and FlashCopy copies. The copy description defines a copy of an IASP. The parameters of
an IASP depends on the PowerHA SystemMirror for IBM i solution. The IASPs that are in the
device domain for the cluster have the same ASP copy descriptions on all nodes of the cluster.
An ASP session is used to link two ASP copy descriptions and start the Copy Services functions
between them. The IBM PowerHA for i sessions allow IBM PowerHA for i to manage and monitor
their activity. The status of the ASP session describes the current status of the replication.

© Copyright IBM Corp. 1995, 2017 9-91


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
9.4. Topic 4: PowerHA Solutions

© Copyright IBM Corp. 1995, 2017 9-92


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLF3RZHU+$6ROXWLRQV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-59. Topic 4: PowerHA Solutions

In this topic you can learn about currently available PowerHA solutions

© Copyright IBM Corp. 1995, 2017 9-93


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

)ODVK&RS\
‡ 7ZRRUPRUH,%0LSDUWLWLRQV
‡ 2QH³VRXUFH´DQGRQHRUPRUH³WDUJHW´VHWVRIGLVNV/81V
‡ )XQFWLRQLVDIHDWXUHRIH[WHUQDOVWRUDJHVXEV\VWHPV
‡ )ODVK&RS\SDLUVUHVLGHLQVDPHVWRUDJHVXEV\VWHP

352'

352')&

3URGXFWLRQ
,$63
6$16WRUDJH
,%0L

)ODVK&RS\

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-60. FlashCopy

Benefits
• Provides a point-in-time “copy” of production data
▪ Eliminates scheduled outage time for production backups
• Limited amount of disk required
• Can be managed through PowerHA or ICSM
Limitations
• Not a High Availability (HA) OR Disaster Recovery (DR) solution
• Full Copy and Incremental Copy require fully provisioned “target” LUNs
• With space-efficient (thin-provisioned) LUNs, there is no full copy on disk elsewhere
▪ Would require a restore from media
▪ Some performance penalties may apply, as most reads from source LUNs

© Copyright IBM Corp. 1995, 2017 9-94


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

*HRJUDSKLF0LUURULQJ
‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ 2QH,$63WZRFRSLHV WZRVHWVRIGLVNV/81V
‡ 7\SLFDOO\IRULQWHUQDOVWRUDJH
‡ 5HSOLFDWLRQKDQGOHGDW,%0L6/,&VWRUDJHPDQDJHPHQWOHYHO

352' %$&.83

,QWHUQDO ,QWHUQDO
'LVNV *HR0LUURU 'LVNV

3URGXFWLRQ 0LUURU&RS\
&RS\,$63 ,$63
,%0L ,%0L

&DQEHH[WHUQDOVWRUDJHEXWQRWDVFRPPRQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-61. Geographic Mirroring

Benefits
• High Availability (HA) and Disaster Recovery (DR) solution
• Replication handled at SLIC Storage Management level, as opposed to O/S and remote
journaling (for example, logical replication solutions)
• Managed using PowerHA
• True asynchronous transmission option
Limitations
• Requires sufficient bandwidth between sites to maintain consistent copies and avoid
auto-suspend issues
• Recommended to have equal quantity, capacity, and type of disks at both sites to maintain
consistency
• Replication ports use random ephemeral (1024+) TCP ports, not specific ports

© Copyright IBM Corp. 1995, 2017 9-95


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

0HWUR0LUURU 6\QFKURQRXV&RS\
‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ 7ZRFRSLHVWZRVHWVRIGLVNV/81V
‡ )XQFWLRQLVDIHDWXUHRIH[WHUQDOVWRUDJHVXEV\VWHPV
‡ 0LUURUFRS\LVDOZD\VV\QFKURQL]HG

352' %$&.83

0HWUR0LUURU

3URGXFWLRQ 0LUURU
&RS\ &RS\

,%0L
,%0L

6$16WRUDJH 6$16WRUDJH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-62. Metro Mirror (Synchronous Copy)

Benefits
• High Availability (HA) and Disaster Recovery (DR) solution
• Replication handled at storage level, as opposed to IBM i
• Managed using PowerHA for DS8000, SVC, Storwize
• Managed using ICSM for DS8000, with additional ease of automation and use
Limitations
• Requires external storage
• Synchronous replication, so recommended at limited distances
• Requires sufficient bandwidth to avoid performance issues

© Copyright IBM Corp. 1995, 2017 9-96


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

*OREDO&RS\ $V\QFKURQRXV335& &RQWLQXRXV&RS\


‡ 0LUURUFRS\QRWJXDUDQWHHGWREHXVDEOHXQOHVVVRXUFHV\VWHPLV
SRZHUHGRII
‡ &ORQLQJDQ,%0LSDUWLWLRQ7ZRFRSLHV
‡ 0LJUDWLRQWRDQHZVWRUDJHVXEV\VWHP

352' %$&.83

*OREDO&RS\

3URGXFWLRQ 0LUURU
&RS\ &RS\

,%0L
,%0L

'669& '669&
6WRUZLVH 6WRUZLVH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-63. Global Copy: (Asynchronous PPRC) Continuous Copy

DS800 series
• Mirror copy not guaranteed to be usable, unless source system is powered off
• Cloning an IBM i partition; Two copies, two sets of LUNs
• Migration to a new storage subsystem
• Included with Metro or Global Mirror
SVC, STORWISE
• Asynchronous copy; Writes sent sequentially in order
• Requires sufficient bandwidth, Size for peak I/O workload
• Better suited for fiber replication, not IP replication
• Nearly unlimited distance; Maximum 80 ms round trip

© Copyright IBM Corp. 1995, 2017 9-97


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

*OREDO0LUURU ZLWK&RQVLVWHQF\*URXS
‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ 7KUHHFRSLHVWKUHHVHWVRIGLVNV/81V
‡ 8VHV*OREDO&RS\&RQVLVWHQF\*URXS &* )ODVK&RS\
‡ 7DUJHWFDQEH³YHU\FORVH´WREHLQJV\QFKURQL]HG

352' %$&.83

*OREDO&RS\

3URGXFWLRQ 335&7DUJHW
&RS\ &RS\

&*&RS\
,%0L ,%0L

'6 '6

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-64. Global Mirror - with Consistency Group

Benefits
• Disaster Recovery (DR) solution
• Replication handled at storage level, as opposed to IBM i
• Managed using PowerHA
• Managed using ICSM, with additional ease of automation and use
• Does not require bandwidth to meet peaks
• Unlimited distance
Limitations
• Data loss occurs on source storage failure, but could be as low as 1 second, depending on
bandwidth and data changes
• Only global copy in reverse direction

© Copyright IBM Corp. 1995, 2017 9-98


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

*OREDO0LUURU&KDQJH9ROXPHV 69&6WRUZL]H
‡ &KDQJHYROXPHVKROGSRLQWLQWLPHFRS\WKDWLVFKDQJHGGXULQJF\FOLQJ
PRGH )ODVK&RS\LVSHUIRUPHG
‡ &KDQJHYROXPHVUHTXLUHGDWERWKVRXUFHDQGWDUJHWVLWH W\SLFDOO\WKLQ
SURYLVLRQHG
‡ 5HTXLUHVIRXU³VHWV´RIGLVNV/81V WZRVRXUFHWZRWDUJHW

352' %$&.83

*OREDO0LUURU
3URGXFWLRQ 0LUURU&RS\
&RS\
&KDQJH9ROXPH
&KDQJH9ROXPH
)ODVK&RS\
,%0L )ODVK&RS\ ,%0L

69&6WRUZL]H 69&6WRUZL]H

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-65. Global Mirror + Change Volumes (SVC Storwize)

Benefits
• High Availability (HA) and Disaster Recovery (DR) solution
• Replication handled at storage level, as opposed to IBM i
• Managed using PowerHA, FSR
• Does not require bandwidth to meet peaks
• Unlimited distance, up to 80 ms round trip latency
Limitations
• Data loss occurs on source storage failure, but could be as low as 60 seconds, depending on
bandwidth, data changes, and cycle time
• Recommended when performance is poor with Metro Mirror or Global Mirror continuous copy
on SVC Storwize
• Additional disk capacity required for change volumes (auxiliary volumes)

© Copyright IBM Corp. 1995, 2017 9-99


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

*OREDO0LUURU 6\PPHWULFDO '6


‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ )RXUFRSLHVIRXUVHWVRIGLVNV/81V
‡ 8VHV*OREDO&RS\&RQVLVWHQF\*URXS &* )ODVK&RS\
‡ &DQEHUHYHUVHGZLWKIXOO*OREDO0LUURUFDSDELOLW\

352' %$&.83

*OREDO&RS\

3URGXFWLRQ 335&7DUJHW
&RS\ &RS\

&*&RS\ &*&RS\
,%0L ZKHQUHYHUVHG ,%0L

'6 '6

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-66. Global Mirror (Symmetrical): DS8000

Benefits
• High Availability (HA) and Disaster Recovery (DR) solution
• Replication handled at storage level, as opposed to IBM i
• Managed using PowerHA ICSM or FSR
• Does not require bandwidth to meet peaks
• ICSM FRS offers additional ease of use and automation above and beyond PowerHA
• Ability to reverse replication with full Global Mirror solution
Limitations
• Data loss occurs on source storage failure, but could be as low as 1 second, depending on
bandwidth and data changes
• Additional storage capacity required for CG FlashCopy volumes
• CG volumes cannot be used for normal FlashCopy backups

© Copyright IBM Corp. 1995, 2017 9-100


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLFVXPPDU\
‡ 6LQJOHVLWHVROXWLRQVFDQSURYLGHVRPH+LJK$YDLODELOLW\ +$ DQGPD\
VDYHEXWFDQQRWSURYLGH'LVDVWHU5HFRYHU\ '5
‡ &RQVLGHULQWHUQDOYVH[WHUQDOVWRUDJH DQGZKDWW\SHRIH[WHUQDO
VWRUDJH GHSHQGLQJRQZKLFKVROXWLRQ\RXFKRRVH
‡ &RQVLGHUFRQQHFWLYLW\RSWLRQV 'LUHFWDWWDFKHG6$1DWWDFKHG9,26
Y6&6,13,9 DQGQXPEHURIKRVWFRQQHFWLRQVZKHQGHFLGLQJZKLFK
VROXWLRQVFDQRUFDQQRWEHLPSOHPHQWHG
‡ &RQVLGHUWKHDPRXQWRIGLVNQHHGHGIRUPXOWLSOHFRSLHV 0LUURU&RS\
/81V)ODVK&RS\/81V&RQVLVWHQF\*URXS/81V&KDQJH9ROXPH
/81V
‡ &RQVLGHU%$1':,'7+UHTXLUHPHQWVEHWZHHQVLWHVWRHQVXUHHIILFLHQW
GHOLYHU\RISDFNHWVRQPLUURULQJVROXWLRQV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-67. Topic summary

Note you can combine presented solutions depending on requirements and availability.

© Copyright IBM Corp. 1995, 2017 9-101


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

:KHUHFDQ,ILQGPRUHLQIRUPDWLRQRQFOXVWHULQJ"
‡ (GXFDWLRQ
ƒ $6*IBM PowerHA for i, Clustering, and IASP Implementation

‡ $YDLODEOHOLQNVDQGPDQXDOV
ƒ PowerHA SystemMirror Technology
KWWSVZZZLEPFRPV\VWHPVSRZHUVRIWZDUHDYDLODELOLW\LLQGH[KWPO

‡ ZZZUHGERRNVLEPFRP
ƒ IBM PowerHA SystemMirror for i
KWWSZZZUHGERRNVLEPFRPDEVWUDFWVVJKWPO"2SHQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-68. Where can I find more information on clustering?

© Copyright IBM Corp. 1995, 2017 9-102


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
9.5. Additional topics

© Copyright IBM Corp. 1995, 2017 9-103


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

7RSLF$GGLWLRQDOWRSLFV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-69. Topic 5: Additional topics

© Copyright IBM Corp. 1995, 2017 9-104


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8QLQWHUUXSWLEOHSRZHUVXSSO\
‡ %HQHILWV
ƒ &RQWLQXHRSHUDWLRQVGXULQJEULHISRZHU
LQWHUUXSWLRQ
ƒ 3URYLGHRUGHUO\VKXWGRZQDQGDYRLG
OHQJWK\UHFRYHU\ ,3/


 
 
 
 
 


:LWKRXW
2EMHFWVPLJKWEHGDPDJHGUHFRYHU\
WLPHPLJKWEHVLJQLILFDQW

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-70. Uninterruptible power supply

The loss of system utility power can cause major problems for an IBM Power System with IBM i. If
the IBM i is not protected against the loss of power and power is lost, the IBM i immediately shuts
down (abnormal shutdown), resulting in the loss of the contents of main memory, possible
damaged objects, and significantly increasing the amount of time required for an IPL. The system
may attempt to automatically restart and reconstruct information after power is returned, depending
upon how the QPWRRSTIPL system value is set.
Continuously Powered Main store and an uninterruptible power supply (UPS) can help prevent the
occurrence of an abnormal shutdown.
The UPS feature provides a source of power for the IBM Power System if utility power is
interrupted. It allows for continuous operations during brief power interruptions and permits a
controlled shutdown of the system for longer power interruptions. The capacity of a UPS should be
sized to meet the system requirements. Power is not normally supplied to devices such as
workstations. Applications can be programmed to recognize this situation and end in an orderly
fashion
Consider to use to separated power line to avoid of power lost from one.

© Copyright IBM Corp. 1995, 2017 9-105


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

3RZHU6\VWHPDFWLRQDIWHUSRZHUUHVWRUHG

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-71. Power System action after power restored

Using HMC interface you can setup parameters for server after power restored. To do this you must
1. Log on with user and password to HMC.
2. On the left pane, expand Systems Management and then expand Servers.
3. On the main pane, find your server and select it.
4. Click double arrow next to server name and choose Properties.
5. On the Properties click Power-On Parameters tab.
6. Setup parameters.
Power-On Parameters
Use the “Power-on Parameters” window to display the partition start policy for powering on the
managed system and other settings such as the initial program load (IPL) source mode.
For more information, select one of the following options:
• Partition start policy: Displays the current partition start policy specified for the managed
system. The partition start policy represents the hypervisor IPL state. You can change the
partition start policy by selecting one of the following values in the Next field:

© Copyright IBM Corp. 1995, 2017 9-106


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Auto-Start Always: This option specifies that the HMC power on logical partitions
automatically after the managed system powers on. If powering on the managed system is the
result of a user action, the HMC starts all partitions that are configured for automatic start up. If
powering on the managed system is the result of an automatic recovery process, the HMC
starts only those logical partitions that were running at the time the system powered off. This
option is always available for selection.
• Stop at Partition Standby: This option specifies that logical partition start up is in standby
mode after the managed system powers on. The HMC does not start any logical partitions when
the managed system powers on. If powering on the managed system is the result of an
automatic recovery process and the HMC is used to start a logical partition, the HMC starts all
logical partitions that were running at the time the system powered off. This option is available
for selection only when the firmware for the managed system does not support advanced IPL
capabilities.
• Auto-Start for Auto-Recovery: This option specifies that the HMC power on logical partitions
automatically only after the managed system powers on as the result of an automatic recovery
process. This option is available for selection only when the firmware for the managed system
supports this advanced IPL capability.
• User-Initiated: This option specifies that the HMC does not start any logical partitions when the
managed system powers on. You must start logical partitions manually on the managed system
by using the HMC. This option is available for selection only when the firmware for the managed
system supports this advanced IPL capability.
Power-on side
Displays the Platform power-on side. Possible values are:
• Permanent
• Temporary
The Current field displays the power-on side value at this time. You can change the power-on side
for the next restart by changing the value in the Next field. These changes will only be valid for the
next restart.
Power-on speed
Displays the speed of the power-on operation. Possible values are:
• Slow: The system performs complete hardware diagnostics
• Fast: The system performs only a minimum, critical set of hardware diagnostics
The Current field displays the power-on speed value at this time. You can change the power-on
speed for the next restart by changing the value in the Next field. These changes will only be valid
for the next restart.
The power-on speed fields are available for POWER5, POWER6, and POWER7 (firmware level
AL710 only) servers only.
Power-on speed override
Override field for the power-on speed. Possible values are:
• No override: no override is set

© Copyright IBM Corp. 1995, 2017 9-107


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Slow: The system performs complete hardware diagnostics
• Fast: The system performs only a minimum, critical set of hardware diagnostics
The Current field displays the power-on speed override value at this time. You can change the
power-on speed override for the next restart by changing the value in the Next field. These
changes will only be valid for the next restart.
The power-on speed override fields are available for POWER5, POWER6, and POWER7 (firmware
level AL710 only) servers only.
Keylock position
Displays the keylock position for restarting the managed system. Possible values are:
Manual: After power-on, operating the system in Manual (attended) mode indicates that an
operator uses the control panel to direct the system for special needs. For security reasons, you
should not set the keylock position to Manual.
Normal: After the power-on, operating the system in Normal (unattended) mode requires no
operator intervention during the restart.
The value in the Current field displays the position of the keylock at this time. You can change the
keylock position by changing the value in the Next field.
Power-on source
Displays the power-on tool or interface source used to power on the managed system. This
information is used by service and support to diagnose issues.
Manufacturing defaults
Shows the manufacturing default settings for IPL source (IBM i partitions) and boot mode
(AIX/Linux partitions). The manufacturing default configuration is the initial partition setup of the
managed system as received from your service provider.
These settings are applicable only when the system configuration is the manufacturing default
configuration. The Current field displays the restart setting (IPL source or boot mode) at this time.
When the system configuration is the manufacturing default configuration, you can change the
setting for the next restart by changing the value in the Next field. These changes will be valid only
for the next restart.
IBM i IPL Source Displays the IBM i IPL source. Possible values are:
• IPL type A: Use IPL type A when directed for special work, such as diagnostic work.
• IPL type B: Use IPL type B for routine work.
• IPL type C: This type of IPL is reserved for hardware service representatives.
• IPL type D: Use IPL type D when directed for special work, such as installing and reloading
programs. IPL type D loads the system programs from an alternate IPL load source, such as a
tape drive or CD-ROM.
AIX/Linux boot mode Displays the AIX/Linux boot mode. Possible values are:
• Normal: The logical partition starts up as normal. (This is the mode that you use to perform
most everyday tasks.)
• SMS: The logical partition boots to the System Management Services (SMS) menu.

© Copyright IBM Corp. 1995, 2017 9-108


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty
• Diagnostic Default Boot List: The logical partition boots using the default boot list that is
stored in the system firmware. This mode is normally used to boot customer diagnostics from
the CD-ROM drive. Use this boot mode to run stand-alone diagnostics.
• Diagnostic Stored Boot List: The logical partition performs a service mode boot using the
service mode boot list saved in NVRAM. Use this boot mode to run online diagnostics.
• Open Firmware: The logical partition boots to the open firmware prompt. This option is used
by service personnel to obtain additional debug information.

© Copyright IBM Corp. 1995, 2017 9-109


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8366\VWHPYDOXHV

QUPSMSGQ QUPSDLYTIM QPWRRSTIPL

QSYSOPR *CALC 

7KHV\VWHP ,IXWLOLW\SRZHULV
GHWHUPLQHV UHVWRUHGVKRXOG
ZKHQWRVDYH WKHV\VWHP
PDLQVWRUDJH DXWRPDWLFDOO\
0HVVDJHV DQGSRZHU
UHODWHGWR ,3/"
GRZQ
XQLQWHUUXSWLEOH
SRZHUVXSSO\

QSYSOPR 3RZHU6\VWHPZLWK
PHVVDJH 7LPHU ,%0L
TXHXH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-72. UPS: System values

QPWRRSTIPL, Power Restore IPL system value, controls what happens if the system ends when
utility power is interrupted and then restored at a later time.
• 0 does not allow an automatic IPL after a power failure.
• 1 does an automatic IPL after a power failure.
The default is 0.
QUPSDLYTIM, Uninterruptible Power Supply Delay Time system value, controls the length of time
that the system waits before saving main storage and powering the system down. If utility power is
restored before the delay time, the system resets the times. If the delay time is exceeded, the
system saves main storage and begins to perform a controlled shutdown.
• *BASIC or *CALC Performs a controlled shutdown after the default 45 seconds.
• 0 - 99999 specifies a delay time in seconds before the system powers down.
• *NOMAX is used when a user supplied program is controlling the system or a generator is
providing unlimited UPS power.
QUPSMSGQ, Uninterruptible Power Supply Message Queue system value, determines the message
queues the power supply message are sent to. Messages generated are sent to the specified
message queues in addition to the QSYSOPR message queue.

© Copyright IBM Corp. 1995, 2017 9-110


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

836:KHQSRZHUIDLOV
‡ 7KH836EDWWHU\SRZHULVXVHG
‡ 7KHV\VWHPFKHFNVQUPSDLYTIM
QUPSMSGQ
‡ 7KHRSHUDWRURUSURJUDPH[HFXWHV
PWRDWNSYS
‡ $WQUPSDLYTIMWKH,%03RZHU
6\VWHPZLWK,%0LLQLWLDWHV48,&.
32:(5'2:1

6SHFLDO

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-73. UPS: When power fails

© Copyright IBM Corp. 1995, 2017 9-111


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8367LPHOLQHRI4836'/<7,0IXQFWLRQ
8WLOLW\SRZHU
JRHVRII

7LPH836FDQUXQ
$FWLRQVE\RSHUDWRU
RUSURJUDP

6DYHRI
6DIHW\
5XQ PWRDWNSYS PDUJLQ PDLQVWRUDJH 6DIHW\
FRQWUROOHG PDUJLQ
VKXWGRZQ
QUPSDLYTIM

7LPH
836DFWLYH QUPSDLYTIM &RQWUROOHGVKXWGRZQ
WLPHRXW FRPSOHWHV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-74. UPS: Time line of QUPSDLYTIM function

Additionally, in some cases, users may prefer to customize how their IBM Power System with IBM i
is shutdown. In these instances, a Power-handling program may be used to control system activity
during a power interruption when used in conjunction with a power protection device (UPS or
generator). A power-handling program allows:
• Sending specific messages to interactive users
• Pending batch jobs and subsystems in preparation for powering down
• Dynamically changing the system values that control the uninterruptible power supply handling
• Issuing the PWRDWNSYS command to power down the system
For more information on power-handling programs, suggest that students review the information
available on the IBM Power Systems with IBM i Knowledge Center.

© Copyright IBM Corp. 1995, 2017 9-112


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8363RZHUORVVFRQWUROOHGVKXWGRZQ
‡ 8WLOLW\SRZHUORVW
‡ 836DQGQUPSDLYTIM H[SLUHV
‡ -REVVLJQDOHGWRHQGDWQH[WLQVWUXFWLRQERXQGDU\
‡ 0DLQVWRUDJHZULWWHQWRGLVN ZKLOHUXQQLQJRQ836
‡ 6\VWHPSRZHUHGRII
‡ 8WLOLW\SRZHUUHWXUQV
‡ ,3/LVQRUPDOIRU/,&DEQRUPDOIRU,%0L

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-75. UPS: Power loss controlled shutdown

© Copyright IBM Corp. 1995, 2017 9-113


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8363RZHUKDQGOLQJSURJUDP
‡ 0XVWDOORFDWHPHVVDJHTXHXHLQQUPSMSGQ
‡ &DQRSHUDWHXQGHUXQLQWHUUXSWLEOHSRZHUVXSSO\
‡ 7DNHDFWLRQV
ƒ 6HQGPHVVDJHVWRXVHUV
ƒ (QGEDWFKMREVDQGVXEV\VWHPV
ƒ &KDQJHV\VWHPYDOXHV
ƒ ,VVXHPWRDWNSYS EHIRUHWKHV\VWHPJRHVLQWRDSRZHUORVVFRQWUROOHG
VKXWGRZQ

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-76. UPS: Power handling program

© Copyright IBM Corp. 1995, 2017 9-114


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH:KHQHYHUWKHUHLVDGLVNIDLOXUHRQWKHV\VWHP
WKLVIRUFHVDIXOOUHFRYHU\RIDOOGDWD

 :KLFKRIWKHIROORZLQJLVDKDUGZDUHDYDLODELOLW\IXQFWLRQ
GHVLJQHGWRSURWHFWGDWDIURPORVVGXHWRWZRGLVNXQLWIDLOXUHV
RUEHFDXVHRIGDPDJHWRWZRGLVNV"
D 5$,'
E 5$,'
F 0LUURULQJ
G &RQFXUUHQWPDLQWHQDQFHVXSSRUW

 :KLFKRIWKHIROORZLQJSURYLGHVDPHDQVWRVDYHDQREMHFW
ZKLOHWKHV\VWHPUHPDLQVDFWLYHDQGXVHUVDUHZRUNLQJZLWK
WKHGDWD"
D 3DUDOOHOVDYH
E 6DYHRIDOOXVHUGDWD
F 6DYHFKDQJHGREMHFWV
G 6DYHZKLOHDFWLYH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-77. Review questions (1 of 3)

© Copyright IBM Corp. 1995, 2017 9-115


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH:KHQHYHUWKHUHLVDGLVNIDLOXUHRQWKHV\VWHPWKLV
IRUFHVDIXOOUHFRYHU\RIDOOGDWD
7KHDQVZHULVIDOVH

 :KLFKRIWKHIROORZLQJLVDKDUGZDUHDYDLODELOLW\IXQFWLRQGHVLJQHGWR
SURWHFWGDWDIURPORVVGXHWRWZRGLVNXQLWIDLOXUHVRUEHFDXVHRI
GDPDJHWRWZRGLVNV"
D5$,'
E5$,'
F0LUURULQJ
G&RQFXUUHQWPDLQWHQDQFHVXSSRUW
7KHDQVZHULV5$,'

 :KLFKRIWKHIROORZLQJSURYLGHVDPHDQVWRVDYHDQREMHFWZKLOHWKH
V\VWHPUHPDLQVDFWLYHDQGXVHUVDUHZRUNLQJZLWKWKHGDWD"
D3DUDOOHOVDYH
E6DYHRIDOOXVHUGDWD
F6DYHFKDQJHGREMHFWV
G6DYHZKLOHDFWLYH
7KHDQVZHULVVDYHZKLOHDFWLYH
,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-78. Review answers (1 of 3)

© Copyright IBM Corp. 1995, 2017 9-116


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZTXHVWLRQV RI
 7KHPD[LPXPQXPEHURISDUWLWLRQVVXSSRUWHGRQ32:(5EDVHG
KDUGZDUHLV EODQN 
D 
E 
F 
G 
H 

 :KLFKRIWKHIROORZLQJDUHUHVRXUFHVWKDWFDQEHDOORFDWHGWRDQ/3$5"
6HOHFWDOOWKDWDSSO\
D 2QO\ZKROHSURFHVVRUV
E 0HPRU\
F ,2DGDSWHUV
G 'LVNGULYHV
H 2SHUDWLQJV\VWHPVRIWZDUH

 :KLFKRIWKHIROORZLQJLVQRWVXSSRUWHGLQDQ,%03RZHU6\VWHPSDUWLWLRQ"
D $,;
E /LQX[
F ,%0L
G :LQGRZVVHUYHUVRIWZDUH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-79. Review questions (2 of 3)

© Copyright IBM Corp. 1995, 2017 9-117


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZDQVZHUV RI
 7KHPD[LPXPQXPEHURISDUWLWLRQVVXSSRUWHGRQ32:(5EDVHG
KDUGZDUHLV
D 
E 
F 
G 
H 
7KHDQVZHULVD 

 :KLFKRIWKHIROORZLQJDUHUHVRXUFHVWKDWFDQEHDOORFDWHGWRDQ/3$5"
6HOHFWDOOWKDWDSSO\
D 2QO\ZKROHSURFHVVRUV
E 0HPRU\
F ,2DGDSWHUV
G 'LVNGULYHV
H 2SHUDWLQJV\VWHPVRIWZDUH
7KHDQVZHUVDUHPHPRU\,2DGDSWHUVDQGGLVNGULYHV

 :KLFKRIWKHIROORZLQJLVQRWVXSSRUWHGLQDQ,%03RZHU6\VWHPSDUWLWLRQ"
D $,;
E /LQX[
F ,%0L
G :LQGRZVVHUYHUVRIWZDUH
7KHDQVZHULV:LQGRZVVHUYHUVRIWZDUH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-80. Review answers (2 of 3)

© Copyright IBM Corp. 1995, 2017 9-118


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH(DFK/3$5UHTXLUHVDVHSDUDWHOLFHQVHIURP
,%0IRUWKH26LQVWDOOHGLQWKDW/3$5

 :KLFKRIWKH3RZHU+$6\VWHP0LUURU(GLWLRQLVPLQLPXP
UHTXLUHGIRU+\SHU6ZDS"
D 6WDQGDUG
E ([SUHVV
F (QWHUSULVH

 $ EODQN LVDV\VWHPRUSDUWLWLRQWKDWLVLQDFOXVWHU
D 6HSDUDWHVHUYHU
E 6ZLWFKDEOH'$6'VHUYHU
F &URVVVLWHPLUURU
G &OXVWHUQRGH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-81. Review questions (3 of 3)

© Copyright IBM Corp. 1995, 2017 9-119


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH(DFK/3$5UHTXLUHVDVHSDUDWHOLFHQVHIURP
,%0IRUWKH26LQVWDOOHGLQWKDW/3$5
7KHDQVZHULVIDOVH

 :KLFKRIWKH3RZHU+$6\VWHP0LUURU(GLWLRQLVPLQLPXP
UHTXLUHGIRU+\SHU6ZDS"
D 6WDQGDUG
E ([SUHVV
F (QWHUSULVH
7KHDQVZHULV([SUHVV

 $FOXVWHUQRGH LVDV\VWHPRUSDUWLWLRQWKDWLVLQDFOXVWHU
D 6HSDUDWHVHUYHU
E 6ZLWFKDEOH'$6'VHUYHU
F &URVVVLWHPLUURU
G &OXVWHUQRGH
7KHDQVZHULVFOXVWHUQRGH

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-82. Review answers (3 of 3)

© Copyright IBM Corp. 1995, 2017 9-120


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 9. IBM Power Systems with IBM i: Availability overview

Uempty

8QLWVXPPDU\
‡ ([SODLQWKHFRQFHSWRIDYDLODELOLW\
‡ 'HVFULEHWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXU
‡ 'HVFULEHKDUGZDUHDQGVRIWZDUHDYDLODELOLW\IHDWXUHV
‡ ([SODLQWKHFRQFHSWRIORJLFDOSDUWLWLRQLQJ /3$5
‡ ([SODLQWKHFRQFHSWRIDYDLODELOLW\
‡ 'HVFULEHWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXU
‡ 'HVFULEHKDUGZDUHDQGVRIWZDUHDYDLODELOLW\IHDWXUHV
‡ ([SODLQWKHFRQFHSWRIORJLFDOSDUWLWLRQLQJ /3$5
‡ /LVWVRPHRIWKHUHDVRQVWRLPSOHPHQWORJLFDOSDUWLWLRQV
‡ ([SODLQWKHIXQFWLRQVVHUYHGE\D+DUGZDUH0DQDJHPHQW&RQVROH +0&
‡ ([SODLQWKHFRQFHSWRIFOXVWHULQJ
‡ ([SODLQ3RZHU+$6\VWHP0LUURU
‡ /LVWWKHGLIIHUHQWW\SHVRI3RZHU+$VROXWLRQV
‡ 'HVFULEHWKHFRQVHTXHQFHVIRUDFRPSDQ\LIWKH6\VWHP,%0LDUHQRWDYDLODEOH
WRSHUIRUPQRUPDOEXVLQHVV

,%03RZHU6\VWHPVZLWK,%0L$YDLODELOLW\RYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 9-83. Unit summary

© Copyright IBM Corp. 1995, 2017 9-121


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

Unit 10. Disk management


Estimated time
01:30

Overview
As the amount of disk increases, so does the potential for a disk failure. To reduce or prevent
system recovery time, the System i provides you with the ability to manage the resources on disk.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 10-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

8QLWREMHFWLYHV
‡ ([SODLQWKHFRQFHSWRIGLVNSRROV
‡ /LVWWKHGLIIHUHQWW\SHVRIDX[LOLDU\VWRUDJHSRROV $63V WKDWFDQEH
FRQILJXUHG
‡ ([SODLQVRPHRIWKHEHQHILWVRILPSOHPHQWLQJWKHGLIIHUHQWW\SHVRI
$63V
‡ ([SODLQWKHFRQFHSWVRIGHYLFHSDULW\DQGPLUURUHGSURWHFWLRQ
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQ5$,'5$,'DQG5$,'SURWHFWLRQ
‡ 'HVFULEHWKHGLIIHUHQWOHYHOVDWZKLFKPLUURUHGSURWHFWLRQFDQEH
LPSOHPHQWHG
‡ 'HVFULEHKRZWRILQGWKHFRUUHFWSURFHGXUHIRUGLVNFRQILJXUDWLRQDQG
UHFRYHU\
‡ 'HVFULEHWKHGLVNXQLWIXQFWLRQVRI,%01DYLJDWRUIRUL
‡ 'HVFULEHWKHHIIHFWVRIDQDEQRUPDOV\VWHPHQGDQGWKHUHFRYHU\
SURFHGXUH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 10-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.1. Topic 1: Concepts and overview of
auxiliary storage pools

© Copyright IBM Corp. 1995, 2017 10-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF&RQFHSWVDQG
RYHUYLHZRIDX[LOLDU\VWRUDJH
SRROV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-2. Topic 1: Concepts and overview of auxiliary storage pools

© Copyright IBM Corp. 1995, 2017 10-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7\SHVRIGLVNSRROV RI

6\VWHP 8VHU

%DVLF ,QGHSHQGHQW

6HFRQGDU\

6HFRQGDU\
8')6

3ULPDU\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-3. Types of disk pools (1 of 2)

A disk pool, also referred to as an auxiliary storage pool (ASP), is a software definition of a group of
disk units on your system. This means that a disk pool does not necessarily correspond to the
physical arrangement of disks. Conceptually, each disk pool on IBM i is a separate pool of disk units
for single-level storage. The system spreads data across the disk units within a disk pool. If a disk
failure occurs, you need to recover only the data in the disk pool that contained the failed unit.
There are two main categories of disk pools: the system disk pool and user disk pools. There are
two types of user disk pools: basic and independent. Independent disk pools are further divided into
primary, secondary, and UDFS disk pools.

© Copyright IBM Corp. 1995, 2017 10-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7\SHVRIGLVNSRROV RI
‡ 6\VWHP$63
ƒ $63
ƒ ,%0LRSHUDWLQJV\VWHP
‡ %DVLF
ƒ $63
ƒ $OVRNQRZQDVXVHURUGHSHQGHQW$63V
‡ ,QGHSHQGHQW ,$63
ƒ $63
ƒ 8VHUGHILQHGILOHV\VWHP 8')6 
ƒ 3ULPDU\ [Link] REMHFWV 
í 6HFRQGDU\
‡ 'LVNSRRO,$63DQGGDWDEDVHFDQEHXVHGLQWHUFKDQJHDEO\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-4. Types of disk pools (2 of 2)

System disk pool


The system automatically creates the system disk pool (disk pool one) which contains disk unit one
and all other configured disks that are not assigned to a user disk pool. The system disk pool
contains all system objects for the IBM i licensed program and all user objects that are not assigned
to a basic or independent disk pool.
User disk pools
You can create a user disk pool by grouping a set of disk units together and assigning that group to
a disk pool. User disk pools can contain libraries, documents, and certain types of objects. User
disk pools exist in two forms: basic disk pools and independent disk pools. In a clustered
environment, independent disk pools can be switched between systems without having to perform
an IPL, allowing for continuously available data.
Basic disk pools
A basic disk pool is used to isolate some objects from the other objects that are stored in the
system disk pool. Basic disk pools are defined by the user. Data in a basic user pool is always
accessible whenever the server is up and running. You can configure basic disk pools with numbers
two through 32.

© Copyright IBM Corp. 1995, 2017 10-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
Independent disk pool
The terms, independent auxiliary storage pool (ASP), and independent disk pool are synonymous.
An independent disk pool is a collection of disk units that can be brought online or taken offline
independent of the rest of the storage on a system, including the system disk pool, basic user disk
pools, and other independent disk pools. You can configure independent disk pools with numbers
33 - 255. An independent disk pool can be either of the following:
• Switchable among multiple systems in a clustered environment
• Privately connected to a single system
The benefits, in both multisystem clustered environments and single-system environments, can be
significant. For example, in a clustered environment, the use of independent disk pools can provide
disk storage that is switchable among servers in the cluster, providing continuous availability of
resources. In a single-system environment, independent disk pools could be used to isolate
infrequently used data that does not always need to be present when the IBM Power System with
IBM i is operational.
Contrast basic and independent disk pools
Basic disk pools and independent disk pools, also called auxiliary storage pools (ASPs), are both
useful to group disk units containing certain information together; however, they have some
inherent differences:
• When the server IPLs, all of the disk units configured to a basic disk pool must be accounted in
order for the server to continue the IPL. Independent disk pools are not included in the IPL.
When you vary on the independent disk pool, the node then verifies that all disk units are
present.
• When an unprotected disk unit in a disk pool fails, it typically stops all normal processing on the
server until it can be repaired. The total loss of a disk unit in a basic disk pool requires lengthy
recovery procedures to restore the lost data before the server can IPL and resume normal
operations.
• The data in a basic disk pool belongs to the attaching node and can only be directly accessed
by that system. In an independent disk pool, the data does not belong to the node, but it
belongs to the independent disk pool. You can share the data in the independent disk pool
between nodes in a cluster by varying it off one node and varying it on to another node.
• When you create a basic disk pool, you assign the disk pool a number. When you create an
independent disk pool, you name the disk pool and the system assigns a number.
• If a basic disk pool fills up, it can overflow excess data into the system disk pool. Independent
disk pools cannot overflow. If they did, they would lose their independence. When the
independent disk pool nears its threshold, you need to add more disk units or delete objects to
create more storage space.
• When you make restricted changes to disk configuration in a basic disk pool, you must have
your server restarted to Dedicated Service Tools (DST). In an offline independent disk pool, you
do not have to have your server in DST mode to start or stop mirroring, start device parity
protection, start compression, remove a disk unit, and so on.
You can have disk units that are attached to your system but are not configured and are not being
used. These are called nonconfigured disk units.

© Copyright IBM Corp. 1995, 2017 10-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,$63([WHQVLRQRIVLQJOHOHYHOVWRUDJH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-5. IASP: Extension of single level storage

IASPs are another extension of single level storage. When objects are referenced, their names are
resolved to virtual addresses and the virtual addresses are used to access the object. The
operating system might find the virtual address in main storage or disk or any of the processor
caches or disk caches of the system. In addition, the address might be that of an object in
*SYSBAS or in an IASP. Within *SYSBAS the object might be in the system ASP or in a basic user
ASP. If the object is in an IASP, it might be in a primary, UDFS, or a secondary IASP. It does not
matter where the object resides in single level storage – it is found. And, an application referencing
object is unaware of the location. So, few applications need to be changed. As an analogy, consider
a mobile/cell phone. When a call is made to a mobile/cell phone, the caller has no idea and does
not care where the person being called is located (same room, same building, same city, and so
on). This is similar to an object’s location in storage. The object can move to/from disk, disk cache,
main storage, or processor cache. Nor does the caller care which carrier the person being called
uses. This is similar to an object’s IASP location. The object can move from ASP1 to a basic ASP,
to a primary ASP, or to a secondary ASP. In all cases, the caller never changes the method of
calling the mobile/cell phone number.

© Copyright IBM Corp. 1995, 2017 10-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'LVNSRROJURXSV
‡ 0DGHXSRI
ƒ $SULPDU\GLVNSRRO
ƒ =HURRUPRUHVHFRQGDU\GLVNSRROV 7KHV\VWHPGDWDEDVHLV
UHIHUUHGWRDV SYSBAS
‡ *URXSVORJLFDOO\FRQQHFWGLVN
SRROV 6\VWHP$63

ƒ 9DU\WKHPRQDQGRIIWRJHWKHU
ƒ 6ZLWFKWKHPWRJHWKHU %DVLF L$63

‡ 6KDUHWKHVDPHGDWDEDVH
ƒ 6LPLODUDVV\VWHP$63DQGEDVLF
$63V 3RROJURXSVIRUPXOWLSOHGDWDEDVHV
ƒ )RUH[DPSOH 8')6
í 3ULPDU\LQGHSHQGHQW$63IRUOLEUDULHV
DQGGDWDEDVHILOHV 3ULPDU\ 3ULPDU\ 3ULPDU\
í 6HFRQGDU\LQGHSHQGHQW$63IRU
MRXUQDOVDQGMRXUQDOUHFHLYHUV
‡ 'RQRWRYHUIORZ 6HFRQGDU\ 6HFRQGDU\
ƒ ,IDGLVNSRROILOOVQRPRUHGDWDFDQ
EHDGGHGEXWWKHV\VWHPNHHSV
UXQQLQJ 6HFRQGDU\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-6. Disk pool groups

Independent disk pools can be grouped. The disk pool group has a primary disk pool and zero or
more secondary disk pools. Disk pools in a disk pool group:
• Function as a single entity
• Are varied on and off together
• Are treated as a single high availability resource by cluster resource services.
The objects in a disk pool group also share a single database base that by default, has the same
name as the primary disk pool.
Probably the most common usage of a disk pool group is to provide a primary disk pool for data and
secondary disk pool for journal receivers.
Finally, unlike basic disk pools, independent disk pools do not overflow. Secondary disk pools will
not overflow to a primary disk pool, and a primary disk pool will not overflow to the system ASP.

© Copyright IBM Corp. 1995, 2017 10-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

&KDUDFWHULVWLFVRI,$63V
‡ (DFK$63JURXSLVUHSUHVHQWHGDVDVHSDUDWH'%GDWDEDVHLQVWDQFH
‡ 'XSOLFDWHOLEUDU\QDPHVDUHDOORZHGZLWKLQGLIIHUHQW$63JURXSVRQWKH
VDPHV\VWHP
‡ 'XSOLFDWHOLEUDU\QDPHVDUHQRWDOORZHGEHWZHHQ6<6%$6 $63V 
DQGDQ\,$63RQWKHV\VWHP
‡ (DFKMRERUWKUHDGDOZD\VKDVYLVLELOLW\WRREMHFWVLQ6<6%$6EXWLV
³DWWDFKHG´WRDWPRVWRQH$63JURXSDWDWLPH
‡ ,$63VDUHQRWDYDLODEOHDIWHUDQ,3/7KH\PXVWEHYDULHGRQ
‡ 5'%',5(IRU,$63'%DFWLYDWHGDWYDU\RQ
‡ ,)6IRUDQ,$63LVPRXQWHGDV/<IASPNAME> DWYDU\RQ

‡ 0RVWZRUNWKDWLVDVVRFLDWHGZLWK,$63HQDEOHPHQWLQYROYHVJHWWLQJ
XVHUVDQGMREV³DWWDFKHG´WRWKHDSSURSULDWH,$63

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-7. Characteristics of IASPs

Many IASPs can exist on the same system. Each primary IASP and any associated secondary
IASPs constitutes a separate database. Since jobs or threads can only have visibility to a single
ASP Group at a time, duplicate library names are allowed between different ASP groups. Since ALL
jobs on the system have visibility to ASPs 1-32, duplicate library names are not allowed between
any IASP on the system and the SYSBAS (ASPs 1-32).
IASPs must be varied on in order to be used. The system has no information about what is on the
IASP while it is varied off. There is no option to have an IASP device “auto vary on”. It must be
explicitly varied on, and is generally performed in the startup program. During vary on processing,
the system modifies the RDBDIRE for the IASP database to reflect the fact that this database
represents an IASP. The system also mounts the IFS for the IASP to a mount point on the root file
system that is the same name as the IASP device description.

© Copyright IBM Corp. 1995, 2017 10-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

(QFU\SWLRQIRU,$63
‡ 3URWHFWVGDWDWUDQVPLVVLRQWRDQGIURPWKHGLVNGULYH LPSRUWDQWLQD6$1
HQYLURQPHQW
‡ 3URWHFWVGDWDWUDQVPLVVLRQGXULQJUHSOLFDWLRQ
‡ 3URWHFWVGDWDLQWKHFDVHRIWKHIWRIWKHGLVNGULYH
‡ 3URWHFWVGDWDLQWKHFDVHRIUHWXUQRUUHVDOHRIDGLVNGULYH UHGXFHVWKH
QHHGWRVDQLWL]HWKHGLVNGULYH
‡ )RUEHVWSHUIRUPDQFHSXWGDWDWREHHQFU\SWHGLQWRDVHFRQGDU\,$63
‡ &DSDELOLW\WRVWDUWDQGVWRSHQFU\SWLRQRQDQH[LVWLQJ,$63

662SWLRQ(QFU\SWHG$63(QDEOHPHQWUHTXLUHG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-8. Encryption for IASP

© Copyright IBM Corp. 1995, 2017 10-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

-REQDPHVSDFH
6<6%$6
6<6%$6DQGRSWLRQDOO\RQH$63JURXS
EHFRPHVWKHMREQDPHVSDFH³
6\V$63

8VHU$63V

6<6%$6

$63JURXS
3ULPDU\
$63 $63
,$63
JURXS JURXS
6HFRQGDU\
,$63V

&RPSDQ\ &RPSDQ\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-9. Job namespace

*SYSBAS and optional one Asp group becomes the „job namespace” you can switch between them
using SETASPGRP command.
The Set Auxiliary Storage Pool Group (SETASPGRP) command sets the auxiliary storage pool
(ASP) group for the current thread. Additionally, this command allows you to change the libraries in
the library list for the current thread. If an ASP group had already been set, this command removes
the old ASP group from the current thread and set the specified ASP group for the current thread.
Once the specified ASP group is set for the current thread, all libraries in the independent ASPs in
the ASP group are accessible. And, objects in those libraries can be referenced using regular
library-qualified object name syntax. The libraries in the independent ASPs in the specified ASP
group plus the libraries in the system ASP (ASP number 1) and basic user ASPs (ASP numbers
2-32) form the library name space for the thread. All libraries in the library list need to be in the new
library name space or the library list is not changed and the new ASP group is not set.

© Copyright IBM Corp. 1995, 2017 10-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

1DPHVSDFH

0XOWLSOH'DWDEDVH6XSSRUW± 6HWXS([DPSOH

8VHUSURILOHV-REGHVFULSWLRQV

6<6%$6
‡ 26 &RQWDLQV&RPPRQ$SSOLFDWLRQ&RGH
‡ /LFHQVHG3URJUDPV
‡ :RUN0JWDQG8VHU'HILQLWLRQV

,$63V 0<&3< 0<&3< 0<&3<

'DWDEDVH 'DWDEDVH$6,$ 'DWDEDVH86


(8523( ‡ &DWDORJ ‡ &DWDORJ
‡ &DWDORJ ‡ &ROOHFWLRQV ‡ &ROOHFWLRQV
‡ &ROOHFWLRQV /LEUDULHV /LEUDULHV
/LEUDULHV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-10. Namespace

When a system has multiple disk pool groups, users can be attached to different disk pool groups.
In example, three disk pool groups are in use by different groups of users. Note that each disk pool
group is likely to have identical library structures. However, each group has its own database. The
code in use by the three groups is common and is located in *SYSBAS. If there are application
differences for each set of users, the application code can be stored in the appropriate disk pools.
Once again, the end-user environment is similar to a distributed system implementation.

© Copyright IBM Corp. 1995, 2017 10-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,$63VXSSRUWHGREMHFWW\SHVDVRI,%0L
$/57%/ '7$4 -515&9 3$*')1 63/)
%/.6) )&7 /,% 3$*6(* 64/3.*
%1'',5 ),)2 /2&$/( 3'* 64/8'7
&+56) ),/( 0('')1 3*0 6593*0
&+7)07 )1756& 0(18 31/*53 670)
&/' )177%/ 0*7&2/ 69567*
&/6 )250') 02'8/( 36)&)* 6<0/1.
&0' )75 06*) 40)250 7%/
&54' *66 06*4 4045< 865,';
&6, ,*&'&7 12'*53 45<')1 8654
',5 -2%' 12'/ 6%6' 86563&
'7$$5$ -2%4 2874 6&+,'; 9/'/
'7$'&7 -51 29/ 63$'&7 :6&67
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-11. IASP supported object types as of IBM i

This chart shows a list of all of the objects that can be placed in an IASP. Subsystem descriptions
can be placed in an IASP, but cannot be activated if they reside in an IASP.
Restrictions for supported object types
*ALRTBL If network attributes reference the alert table, this object must exist in the system disk
pool.
*CLS If an active subsystem references the class object, the class must exist in the library name
space of the job that is being started by that subsystem. The library name space of a prestart job
must be the same as the library name space of the subsystem job.
*FILE Database files that are either multiple-system database files, or that have DataLink fields
that are created as Link Control, cannot be in an independent disk pool. If an active subsystem
references the file object.
*FILE must exist in the system disk pool; for example, the sign-on display file.
*JOBD If an active subsystem references the job description object, the job description must exist
in the system disk pool or in the ASP group parameter of the subsystem description. A subsystem
references a job description from an autostart job entry, communication entry, remote location
name entry, a workstation entry, or a prestart job entry. When the job description is referenced by a

© Copyright IBM Corp. 1995, 2017 10-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
prestart job entry, the INLASPGRP parameter for the job description must match the ASPGRP
parameter of the subsystem description.
*JOBQ Jobs that are contained in a job queue on an independent disk pool are ended when the
independent disk pool is varied off or if an IPL occurs for the system. Jobs do not switch with the
independent disk pool group to another system. To submit a job to a job queue, the job queue must
exist in the library name space of the thread that issued the SBMJOB command. For a subsystem to
start jobs from a job queue, the job queue must exist in the library name space of the subsystem
job. *LIB The library that is specified by CRTSBSD SYSLIBLE() must exist in the system disk pool.
*MSGQ If network attributes reference the message queue.
*MSGQ must exist in the system disk pool.
*PGM If an active subsystem references the program object, the program must exist in the library
name space of the job that is being started by that subsystem. The library name space of a prestart
job must be the same as the library name space of the subsystem job.
*SBSD The subsystem description can be restored to an Independent Disk Pool and changed
while in the Independent disk pool, but it must be copied to the System disk pool to be used. You
cannot start a subsystem whose description is in an independent disk pool. You cannot start a
subsystem if the ASP group parameter in the subsystem description names an ASP group that is
not varied on and available.

© Copyright IBM Corp. 1995, 2017 10-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,$63XQVXSSRUWHGREMHFWW\SHVDVRI,%0L
‡ 6HFXULW\REMHFWV
‡ /HJDF\REMHFWV
‡ &RQILJXUDWLRQREMHFWV

$87+/5 '',5 ,0*&/* 1:6'


$87/ '(9' ,3;' 35'$9/
&)*/ '2& -2%6&' 35'')1
&11/ '670) /,1' 35'/2'
&26' ('7' 02'' 62&.(7
&5* (;,75* 0 661'
&630$3 )/5 0&)* 6
&637%/ ,*&657 17%' 5&7
&7/' ,*&7%/ 1:,' 86535)
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-12. IASP unsupported object types as of IBM i 7.2

Objects affecting security remain in SYSBAS. Non-strategic objects (that is, *S36) must remain in
SYSBAS. System configuration objects have no use on another system, and must remain in
SYSBAS.
*DSTMF is the object type that is returned for stream files that are being accessed through the
QNTC file system from a remote system. So you should not see *DSTMF ever when accessing the
IASP directories from the local system.

© Copyright IBM Corp. 1995, 2017 10-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

/LEUDULHVLQDQ,$63
‡ +RZDUHREMHFWVSODFHGLQDQ,$63"
‡ /LEUDULHVDUHWKHNH\

ƒ &UHDWHDQG5HVWRUH/LEUDU\FRPPDQGV CRTLIB DQGRSTLIB KDYH


SDUDPHWHUVIRUGLFWDWLQJWKH$63RU,$63ZKHUHWKHOLEUDU\UHVLGHV
ƒ 2QFHDOLEUDU\LVSODFHGLQDQ,$63DOOREMHFWVZLWKLQWKDWOLEUDU\DUHDOVRLQ
WKH,$63
ƒ 7KH,$63GRHVQRWQHHGWREHLQWKHQDPHVSDFHRIWKHMRELVVXLQJWKH
CRTLIB RUWKHRSTLIB FRPPDQG
ƒ 'XSOLFDWHOLEUDU\QDPHVDUHQRWDOORZHGEHWZHHQ6<6%$6DQGDQ,$63

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-13. Libraries in an IASP

© Copyright IBM Corp. 1995, 2017 10-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,)6LQDQ,$63
‡ +RZDUH,)6GLUHFWRULHVDQGREMHFWVSODFHGLQDQ,$63"
‡ 7KH,$63PRXQWSRLQWLVWKHNH\

ƒ $WYDU\RQRIWKH,$63WKH,)6RQWKH,$63LVPRXQWHGWRWKHGLUHFWRU\
/<myiasp>
ƒ $IWHUWKH,$63,)6LVPRXQWHGWRWKLVORFDWLRQGXULQJYDU\RQSURFHVVLQJDOO
,)6GLUHFWRULHVDQGREMHFWVWKDWDUHSODFHGLQVLGHWKLVGLUHFWRU\ZLOOUHVLGHRQ
WKH,$63
ƒ ,)6YLVLELOLW\LVKLHUDUFKLFDO1RQDPHVSDFHFKDQJHVDUHUHTXLUHGIRUYLVLELOLW\
WR,$63,)6

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-14. IFS in an IASP

© Copyright IBM Corp. 1995, 2017 10-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,)6REMHFWVLQ,$63V

,)6REMHFWVDUHDFFHVVHGLQDQ,$63E\
VSHFLI\LQJWKH,$63GLUHFWRU\QDPHILUVWLQWKHSDWK
 URRW

46<6/,% 4,%0 ,$63Q DQGVRRQ

4,%0 46<6/,% DQGVRRQ

3DWKWR4,%0LQ,$63Q µ/IASPn/QIBM¶
1RWH/IASPn/[Link]/«FRQWDLQVOLEUDULHVLQWKH,$63
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-15. IFS objects in IASPs

After the IASP directory is mounted and objects are placed in the IASP, the path to these objects
begins with the IASP directory.

© Copyright IBM Corp. 1995, 2017 10-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,$63YLVLELOLW\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-16. IASP visibility

While the IASP is varied off, the system has no visibility to the contents of the IASP. As such,
neither do any user jobs on the system. When the IASP is in the process of being varied on, it goes
through several stages. The operating system has visibility to the contents of the IASP when the
IASP achieves 'Active' status. But user jobs cannot access the IASP, except for being able to
rename libraries that conflict with library names in SYSBAS. As the IASP completes the 'vary on'
process, it achieves a status of 'Available'. The system has full visibility to the contents of the IASP
at this point. But by default, user jobs only have visibility to objects in the IASP by using commands
that can reach outside the job’s current name space. This IASP must be in an “Available” state
before jobs can attach to the IASP and include that IASP in the job’s namespace.

© Copyright IBM Corp. 1995, 2017 10-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

.H\FRQFHSWV
‡ 6<6%$6
ƒ 5HIHUVWRV\VWHP$63DQGDOOXVHU$63V  

‡ 'LVNSRROJURXS
ƒ 2QH'%,QVWDQFHRQHSULPDU\,$63DQGRSWLRQDOVHFRQGDU\,$63V

‡ 0XOWLSOH,$63VSHUV\VWHPDUHDOORZHG

‡ -REQDPHVSDFH
ƒ 6<6%$6DQG]HURRURQH'LVNSRROJURXSDWDWLPH

‡ 1RWDOOREMHFWW\SHVFDQEHSODFHGLQDQ,$63

‡ ,$63VDUHQRWDYDLODEOHE\GHIDXOW
ƒ ,$63GHYLFHGHVFULSWLRQPXVWEHYDULHGRQDQGDYDLODEOHDQGMREPXVWWDNH
DFWLRQWRJDLQYLVLELOLW\WRREMHFWVDQGGDWDLQDQ,$63
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-17. Key concepts

© Copyright IBM Corp. 1995, 2017 10-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

$63EHQHILWV
‡ 'DWDSURWHFWLRQ
ƒ ,VRODWHHIIHFWVRIDGLVNIDLOXUH

‡ ,PSURYHGSHUIRUPDQFH
ƒ +LJKXVHREMHFWV
ƒ 6HSDUDWHILOHVDQGMRXUQDOUHFHLYHUV

‡ 6HSDUDWHE\DYDLODELOLW\DQGUHFRYHU\UHTXLUHPHQWV
ƒ 'LIIHUHQWGLVNSURWHFWLRQWHFKQLTXHVE\$63
ƒ 'LIIHUHQWWDUJHWUHFRYHU\WLPHVIRUUHFRYHULQJDFFHVVSDWKV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-18. ASP benefits

User ASPs can improve performance when extensive journaling operations are offloaded to user
ASPs.
Journaling operations work most productively if active journal receivers can be placed in separate
user ASPs to reduce disk contention.

© Copyright IBM Corp. 1995, 2017 10-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

6\VWHP$63 $63
‡ $XWRPDWLFDOO\FUHDWHG
‡ /RDGVRXUFH XQLWRQH DQGDOOXQLWVQRWLQXVHU$63V
‡ 6\VWHPREMHFWVDQGREMHFWVQRWLQXVHU$63V
‡ $EQRUPDOHQGLIIXOO
ƒ 7KUHVKROGSHUFHQW QSYSOPR 0HVVDJH
ƒ QSTGLOWLMT /RZOLPLWRIDYDLODEOHVWRUDJH
ƒ QSTGLOWACN $FWLRQZKHQQSTGLOWLMT UHDFKHG
í QSYSOPR PHVVDJHRUFULWLFDOPHVVDJH
í &DOOUHJLVWHUHG ADDEXITPGM H[LWSURJUDPV
í ENDSYS RUPWRDWNSYS
‡ ,I$63ORVWDGGUHVVDELOLW\RIREMHFWVLQXVHU$63VORVW
ƒ RCLSTG RUUHVWRUHHQWLUHV\VWHP
ƒ ,IRCLSTGQDFTOWN RZQVDOOREMHFWV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-19. System ASP (ASP1)

QSTGLOWLMT
The auxiliary storage lower limit specifies the percent of available storage remaining in the system
ASP when the auxiliary storage lower limit is reached. The QSTGLOWACN system value specifies the
action associated with this limit. The percent of storage currently used in the system ASP is viewed
with the Work with System Status (WRKSYSSTS) command.
*ALLOBJ and *SECADM special authorities are required to change the system value QSTGLOWLMT.
A change to this system value takes effect immediately. The shipped value is 5.
Lower limit
0 - 100
Specify the percentage of storage to remain available.
QSTGLOWACN
The auxiliary storage lower limit action specifies the action to take when the available storage in the
system ASP is below the lower limit for auxiliary storage.
*ALLOBJ and *SECADM special authorities are required to change the QSTGLOWACN system
value.

© Copyright IBM Corp. 1995, 2017 10-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
A change to this system value takes effect immediately. The shipped value is *MSG. If you want to
change the QSTGLOWACN system value, see the Work Management Book, SC41-5306, for
additional information.
Action
*MSG
Send message CPI099C to QSYSMSG and QSYSOPR message queue. This message is also
sent for the other actions.
*CRITMSG
Send critical message CPI099B to the user who is specified in the service attribute to receive
critical messages.
*REGFAC
Submit a job to call exit programs registered for the QIBM_QWC_QSTGLOWACN exit point.
*ENDSYS
End the system to the restricted state.
*PWRDWNSYS
Power down the IBM Power System with IBM i immediately and restart it.

© Copyright IBM Corp. 1995, 2017 10-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,%03RZHU6\VWHPVZLWK,%01DYLJDWRUIRUL6WRUDJH
6\VWHP9DOXHV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-20. IBM Power Systems with IBM Navigator for i: Storage System Values

To work with storage system values do following:


1. Type at the web browser [Link] name or IP address>>:2001 and press
Enter key.
2. Log on to the system with user and password.
3. On the main pane, expand Configuration and Service and then click System Values.
4. On the main pane right-click Storage and from pop-up menu click Properties.
5. Set up system values for storage.

© Copyright IBM Corp. 1995, 2017 10-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

8VHU$63V $63$63
‡ /LEUDU\XVHU$63 SUHIHUUHGW\SH
ƒ /LEUDU\RUIROGHULQ$63ILUVW
ƒ 0RVWREMHFWW\SHVDOORZHG

‡ 1RQOLEUDU\XVHU$63
ƒ 2QO\MRXUQDOVMRXUQDOUHFHLYHUVDQGVDYHILOHV
ƒ /LEUDU\LQV\VWHP$63

‡ 2YHUIORZVWR$63LIILOOHGXS
ƒ 7KUHVKROGSHUFHQWQSYSOPR PHVVDJH
ƒ 3URWHFWLRQORVWUHFRYHU\DFWLRQVUHTXLUHG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-21. User ASPs (ASP2-ASP32)

Library user disk pools


Library user disk pools, contain libraries and user-defined file systems (UDFS). IBM recommends
that you use library user disk pools because the recovery steps are easier than with non-library
user disk pools. There are several factors to consider when using library user disk pools.
Non-library user disk pools
Non-library user disk pools contain journals, journal receivers, and save files whose libraries are in
the system disk pool.
If you are assigning access path recovery times for individual disk pools, you should set the target
recovery time for a non-library user disk pool to *NONE. A non-library user disk pool cannot contain
any database files and cannot, therefore, benefit from system-managed access-path protection
(SMAPP). If you set an access path recovery time for a non-library user disk pool to a value other
than *NONE, this causes the system to do extra work with no possible benefit. System-managed
access-path protection describes how to set access path recovery times.
Refer to the Information Center for specific procedures to manage ASPs (also known as disk
pools).

© Copyright IBM Corp. 1995, 2017 10-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

$GGLWLRQDO$63FRQVLGHUDWLRQV
‡ 2EMHFWVH[LVWZLWKLQDQ$63
‡ 7KH\DUHORJLFDOJURXSRIXQLWVQRWDSK\VLFDOJURXSLQJRUKDUGZDUH
IXQFWLRQ
‡ $GGLWLRQDOGLVNXQLWVPLJKWEHUHTXLUHG
‡ 6KRXOGEHSURWHFWHGE\GHYLFHSDULW\SURWHFWLRQRUPLUURUHGSURWHFWLRQ
‡ -RXUQDOVDQGWKHLUILOHVPXVWEHLQWKHVDPH$63
‡ 3K\VLFDOILOHVDQGGHSHQGHQWORJLFDOILOHVPXVWEHLQWKHVDPH$63
‡ 7KH\FDQFRQWDLQ64/VFKHPDV
‡ &RQILJXULQJDQGVHWWLQJWKUHVKROGUHTXLUHV'67667

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-22. Additional ASP considerations

© Copyright IBM Corp. 1995, 2017 10-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.2. Topic 2: Concepts and overview of device
parity protection: RAID-5 RAID-6 RAID10

© Copyright IBM Corp. 1995, 2017 10-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF&RQFHSWVDQG
RYHUYLHZRIGHYLFHSDULW\
SURWHFWLRQ5$,'5$,'
5$,'

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-23. Topic 2: Concepts and overview of device parity protection: RAID-5 RAID-6 RAID10

© Copyright IBM Corp. 1995, 2017 10-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'HYLFHSDULW\SURWHFWLRQ RI

+RZFDQ,NHHSWKHV\VWHP
UXQQLQJZKLOHWKHGULYHLVEHLQJ ,PSOHPHQWdevice
UHSODFHGDQGGDWDUHEXLOW" parity protection
5$,'DQG
5$,' 

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-24. Device parity protection (1 of 2)

© Copyright IBM Corp. 1995, 2017 10-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'HYLFHSDULW\SURWHFWLRQ RI

36 36 '6 '6


'6 36 '6 '6
'6 '6 36 '6
'6 '6 '6 36

5HEXLOG

36 3DULW\VHFWRU
'6 'DWDVHFWRU
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-25. Device parity protection (2 of 2)

One of the earliest forms of protection was check summing. Here is a brief overview.
All the units are in ASP1 and are check summed. If one of the disk units fails, the system stops with
an SRC error code displayed. The failed unit must be replaced. When the IBM i is IPLed, the
system rebuilds the lost data during storage management recovery. The advantage of check
summing is that the data is not lost if only one disk unit fails. One of the disadvantages is the
system stops if there is a failure in the set, and there is a performance and resource cost.
RAID-5 Device parity works similarly to check summing and is intended to prevent data from being
lost if a single disk unit failure occurs. RAID-6 provides protection if two disk units fail. In many
cases, this protection can prevent the system from stopping when a disk unit fails, and might allow
concurrent maintenance.
Device parity protection is a hardware availability function that protects data from being lost
because of a disk unit failure or because of damage to a disk. To protect data, the disk input/output
adapter (IOA) calculates and saves a parity value for each bit of data. Conceptually, the IOA
computes the parity value from the data at the same location on each of the other disk units in the
device parity set.

© Copyright IBM Corp. 1995, 2017 10-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5$,'5$,'DQG5$,'

5$,' 5$,' 5$,'


2QHDGGLWLRQDO 7ZRDGGLWLRQDO
3URWHFWLRQ GLVNGULYHSHU GLVNGULYHVSHU 2QHGLVN
5$,'DUUD\ 5$,'DUUD\
0LQLPXPVL]H 7ZRGLVNVSHU
7KUHHGLVNV )RXUGLVNV
DUUD\ SDULW\VHW
0D[LPXPVL]H
(LJKWHHQGLVNV (LJKWHHQGLVNV ',6.6
DUUD\
6XSSRUWLQJ $OOFXUUHQW $OOFXUUHQW  $OOFXUUHQW 
,%0L   
:RUVWWKHQ
3HUIRUPDQFH :RUVWWKHQ0LUURU &DQEHIDVWHU
5$,'PRUH
LPSOLFDWLRQ EXWOHVVFRVW WKDQ5$,'
VHFXULW\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-26. RAID-5 RAID-6 and RAID-10

Device parity protection, like checksum, is a hardware function that protects data from being lost
because of a disk unit failure or damage to a disk. Calculating and saving a parity value for each bit
of data protects data. There are two levels of protection offered, RAID-5 and RAID-6.
RAID-5
RAID-5 protects against the failure of a single disk unit. Logically, the capacity of one disk unit is
dedicated to storing parity data in a parity set. In practice, the parity data is spread among multiple
disk units depending upon the number of disk units in the parity set and the level of the disk I/O
adapter.
RAID-6
RAID-6 protects against the failure of two disk units. Logically, the capacity of two disk units is
dedicated to storing parity data. In practice, the parity data is spread among multiple disk units. The
minimum number of disk units in a parity set is four and the maximum is eighteen.

© Copyright IBM Corp. 1995, 2017 10-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
RAID10
RAID 10 protects availability due to disk unit failure by pairing disks together into logical mirrors.
Each pair of disks is considered a parity set. In addition to being logically mirrored, RAID 10 also
uses block-level striping. RAID 10 protection is effectively the combination of RAID 0 (data striping)
and RAID 1 (disk mirroring).

© Copyright IBM Corp. 1995, 2017 10-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5$,'FRQFHSW

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-27. RAID-10 concept

The IOA determines how parity sets are formed. RAID 10 protection uses two disk units in each
parity set. Optimal performance, capacity, and balancing are achieved with any of the parity
optimizations settings. It is not possible to include more disk units of the same capacity in a parity
set after device parity protection is started. To add disk units to an existing I/O adapter that is
running RAID 10, the system requires that you start a new parity set, rather than include them in an
existing parity set.
To start device parity protection with hot spare protection with the command line, take the following
steps:
1. Start System Service Tools (STRSST), and specify the user name and password.
2. On the System Service Tools (SST) display, select Work with disk units.
3. On the Work with Disk Units display, select Work with disk configuration.
4. On the Work with Disk Configuration display, select Work with device parity protection.
5. On the Work with device parity protection display, select Start device parity protection - RAID
10 device parity protection or RAID 10 with hot spare.

© Copyright IBM Corp. 1995, 2017 10-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'HYLFHSDULW\SURWHFWLRQEHQHILWV
‡ /RVWGDWDLVDXWRPDWLFDOO\UHFRQVWUXFWHGDIWHUDGLVNIDLOXUH

‡ 6\VWHPFRQWLQXHVWRUXQDIWHURQHGLVNIDLOXUHZLWK5$,'5$,'RU
DIWHUXSWRWZRGLVNIDLOXUHVZLWK5$,'SURWHFWLRQ

‡ )DLOHGGLVNXQLWVFDQEHUHSODFHGZLWKRXWVWRSSLQJWKHV\VWHP

‡ ,WUHGXFHVWKHQXPEHURIGDPDJHGREMHFWVZKHQGLVNVIDLO

‡ 2QHRUWZRGLVNXQLWVRIFDSDFLW\VWRUHVSDULW\GDWDLQSDULW\VHW

‡ &KHDSHUWKDQ0LUURUSURWHFWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-28. Device parity protection benefits

© Copyright IBM Corp. 1995, 2017 10-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'HYLFHSDULW\SURWHFWLRQRQLQSXWRXWSXWDGDSWHUV
‡ ,WSURYLGHVKLJKDYDLODELOLW\WKURXJKGHYLFHSDULW\SURWHFWLRQIRUGLVNXQLWV
FDSDEOHRIGHYLFHSDULW\SURWHFWLRQ

‡ :KHQSDULW\LVVWDUWHGWKH,2$VFUHDWHSDULW\VHWV

‡ $SDULW\VHWFDQRQO\WROHUDWHRUGLVNIDLOXUHV

‡ $GGLWLRQDOGLVNVFDQEHLQFOXGHGLQWRDSDULW\VHWDIWHULWLVVWDUWHG

‡ $OOGHYLFHVLQDSDULW\VHWPXVWEHWKHVDPHFDSDFLW\

‡ <RXKDYHWKHDELOLW\WRFKRRVHKRZ\RXZDQWWKHSDULW\VHWWREH
RSWLPL]HG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-29. Device parity protection on input/output adapters

The minimum number of disk units in a parity set is three; the maximum number of disk units in the
parity set is 18.
Parity data requires space equal to the size of one disk per device parity set. If a device parity set is
started with 4 - 7 disks, the parity data is spread over four disks. If eight or more disks are in the
device parity set when you start it, the parity data is spread over eight disks.
You can include additional disks into a device parity set after you start it. You can exclude disks that
do not have parity data from a device parity set without stopping device parity protection.
Then you select to optimize a parity set, the IOA chooses disk units for parity sets according to the
optimization value you chose.
Depending on your configuration, different parity set optimizations might generate the same parity
sets. You have several options for parity set optimization.
Availability
A parity set optimized for availability offers a greater level of protection because it allows a parity set
to remain functional in case of an I/O bus failure. The availability optimization value ensures that a
parity set is formed from at least three disk units of equal capacity each attached to a separate bus
on the IOA. For example, if an IOA had 15 disk units and was optimized for availability, the result
might be five parity sets with three disk units each attached to separate I/O buses on the adapter.

© Copyright IBM Corp. 1995, 2017 10-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
Capacity
A parity set optimized for capacity stores the most data possible. The IOA can generate fewer parity
sets with more disk units in each parity set. For example, if an IOA has 15 disk units and is
optimized for capacity, the result might be one parity set containing 15 disk units.
Balanced
A balanced parity set compromises between the ability to store large amounts of data and also
provide fast access to data. For example, if an IOA has 15 disk units and you choose balanced
parity optimization, the result might be two parity sets. One with nine disk units, and one with six
disk units.
Performance
Parity sets optimized for performance provide the fastest data access. The IOA might generate
more parity sets with fewer numbers of disk units. For example, if an IOA had 15 disk units and is
optimized for performance, the result might be three parity sets with five disk units each.
When in a dual storage IOA configuration, the system attempts to create an even number of parity
sets. An even number of parity sets distributes the workload evenly between a pair of adapters that
are in a dual storage IOA configuration. This provides the fastest data access since each adapter
has a piece of the workload.
Changing parity set optimization
Changing the parity set optimization stays in effect until you change it again. If you need to start
parity, you can also change the parity set optimization as part of the start parity process.

© Copyright IBM Corp. 1995, 2017 10-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

&KDQJLQJSDULW\SURWHFWLRQRSWLPL]DWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-30. Changing parity protection optimization

To change parity optimization from 5250 do following:


1. Start System Service Tools (SST) running command STRSST. Provide the DST/SST user ID
and password. Note: This is not operating system user ID and by default password is in capital
letter.
2. From SST menu, choose option 3 Work with disk units.
3. From Work with disk units menu choose option 2 Work with disk configuration.
4. Choose option 8 Work with device parity protection.
5. From Work with device parity protection choose option 7 Select parity optimization.
6. Using option 1-4 choose required optimization and confirm with Enter.

© Copyright IBM Corp. 1995, 2017 10-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'HYLFHSDULW\SURWHFWLRQOLPLWDWLRQV
‡ 5$,'
ƒ 6LQJOHGLVNXQLWIDLOXUHV
í 3HUIRUPDQFHGHFUHDVHGXULQJGDWDUHFRQVWUXFWLRQ
ƒ 0XOWLSOHXQLWIDLOXUHV PRUHWKDQRQH
í 6\VWHPEHFRPHVXQXVDEOH
í $63GDWDPXVWEHUHVWRUHG
‡ 5$,'
ƒ 7ZRGLVNXQLWIDLOXUHV
í 3HUIRUPDQFHGHFUHDVHGXULQJGDWDUHFRQVWUXFWLRQ
ƒ 0XOWLSOHXQLWIDLOXUHV PRUHWKDQWZR
í 6\VWHPEHFRPHVXQXVDEOH
í $63GDWDPXVWEHUHVWRUHG
‡ 5$,'
ƒ +HDY\ZULWHZRUNORDGVVXFKDVUHVWRUHRSHUDWLRQ
ƒ 'LVNXQLWVWKDWDUHUHTXLUHGDUHWZLFHWKDWRIDQXQSURWHFWHGDUUD\
‡ %86,2$IDLOXUHV
ƒ 6\VWHPRXWDJHVPLJKWUHVXOW
‡ 5HVWRUHRSHUDWLRQVPLJKWWDNHORQJHU
‡ 0LJKWGHFUHDVHSHUIRUPDQFH
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-31. Device parity protection limitations

© Copyright IBM Corp. 1995, 2017 10-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

:ULWHFDFKHDQGDX[LOLDU\ZULWHFDFKH,2$
‡ :ULWHFDFKHSURYLGHV
ƒ *UHDWHUGDWDLQWHJULW\

ƒ )DVWHUZULWHFDSDFLW\LPSURYHGSHUIRUPDQFH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-32. Write cache and auxiliary write cache IOA

The write cache provides greater data integrity and improved performance. When a system sends a
write operation, the data is written to the cache. Then, a write-completion message is sent back to
the system. Later, the data is written to the disk. The cache provides a faster write capability and
ensures data integrity.
The following actions occur during a write request from the system:
• Data is committed to a nonvolatile battery-backed cache in the IOA.
• A write completion message is sent from the system.
• The following actions occur after the write completion message is sent.
▪ A write operation is sent from the IOA cache to the disk unit:
- A write operation is sent from the IOA cache to the disk unit:
○ Reads the original data.
○ Calculates delta parity by comparing new and original data.
○ Writes the new data.

© Copyright IBM Corp. 1995, 2017 10-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
- Write operations for parity data:
○ Reads the original parity information.
○ Calculates the new parity by comparing the delta parity and the original parity.
○ Writes the new parity information.
• Data is marked as committed data when it is successfully written to both the data disk unit and
the parity disk unit.
The performance for this type of write operation is dependent on disk contention and the time that is
needed to calculate the parity information.
The auxiliary cache IOA mirrors the write cache on a storage IOA. Protection is enhanced because
two copies of data are stored onto two separate IOAs. If a failure occurs to the write cache, then the
auxiliary cache IOA serves as a backup during the recovery of the failed IOA.
When the system sends a write operation, the data is written to the write cache on the storage IOA.
The storage IOA mirrors the write cache data to the auxiliary write cache IOA. Then, a
write-completion message is sent back to the system and the data is then written to a disk.
The auxiliary write cache is an additional IOA that has a one-to-one relationship with a disk IOA.
The auxiliary write cache protects against extended outages due to the failure of a disk IOA or its
cache by providing a copy of the write cache, which can be recovered following the repair of the
disk IOA. This avoids a potential system reload and gets the system back online as soon as the
disk IOA is replaced and the recovery procedure completes.

© Copyright IBM Corp. 1995, 2017 10-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'LVNSURWHFWLRQZLWKGXDOVWRUDJH 5$,'

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-33. Disk protection with dual storage - RAID

You can increase availability using a dual storage I/O adapter (IOA) configuration to connect
multiple controllers to a common set of disk expansion drawers and the included disks and disk
arrays.
For RAID 5 and Raid 6 required:
• Two controllers
• Both controllers must have the same write cache capability and write cache sizes
• Both controllers must support dual storage IOA configuration
• Controllers are in the same system or partition

© Copyright IBM Corp. 1995, 2017 10-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0XOWLLQLWLDWRU+$PRGH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-34. Multi-initiator HA mode

Currently, most of disk drive adapters (controllers) required to be paired. On the visual you can see
two RAID SAS adapters with HD connectors to a disk expansion drawer in a multi-initiator HA
mode.
The PCI Express (PCIe) SAS adapter generation 3 that provides high-performance capabilities and
supports the attachment of SAS hard disk drive (HDD) and SAS solid-state drive (SDD). A pair of
FC 4 adapters are required to provide additional performance, mirrored write cache data and
adapter redundancy. If the pairing is broken, then the write cache is disabled. Integrated flash
memory with super capacitors provides protection of the write cache without batteries in case of
power failure. Adapters effectively provide write cache that uses compression of physical cache.
The terms multi-initiator and high availability (HA) in the SAS arena refer to connecting multiple
controllers (typically two controllers) to a common set of disk expansion drawers for the purpose of
increasing availability. IBM® SAS RAID controllers support high availability with up to two
controllers in one IBM i system (two for Linux).

© Copyright IBM Corp. 1995, 2017 10-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.3. Topic 3: Concepts and overview of
mirrored protection

© Copyright IBM Corp. 1995, 2017 10-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF&RQFHSWVDQG
RYHUYLHZRIPLUURUHG
SURWHFWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-35. Topic 3: Concepts and overview of mirrored protection

© Copyright IBM Corp. 1995, 2017 10-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURUHGSURWHFWLRQ,QWURGXFWLRQ

,VWKHUHDQ\WKLQJWKDWFRXOG
PDNHWKHV\VWHPHYHQ
PRUHDYDLODEOH"
,PSOHPHQWmirrored
protection

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-36. Mirrored protection: Introduction

Mirrored protection is beneficial if you have a multibus system or a system with a large single bus.
A greater number of disk units provides more opportunity for failure and increased recovery time.
Mirrored protection is local to a single system and is distinct from cross-site mirroring. Mirrored
protection works to prevent outage on the system by keeping a second copy of the data on a
mirrored disk unit. If one disk unit fails, the system relies on the mirrored disk unit.
Hot spare protection can be used with mirrored protection. When an appropriate hot spare disk unit
exists in the system and a mirrored disk unit is suspended because of a disk failure, the hot spare
disk unit replaces the failed subunit.
Mirrored protection is a software availability function that protects data from being lost because of
failure or because of damage to a disk-related component. Data is protected because the system
keeps two copies of data on two separate disk units.
When a disk-related component fails, the system can continue to operate without interruption by
using the mirrored copy of the data until the failed component is repaired.

© Copyright IBM Corp. 1995, 2017 10-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
When you start mirrored protection or add disk units to a disk pool that has mirrored protection, the
system creates mirrored pairs using disk units that have similar capacities. The overall goal is to
protect as many disk-related components as possible. To provide maximum hardware redundancy
and protection, the system attempts to pair disk units that are attached to separate I/O buses, IOAs,
and expansion units.
If a disk failure occurs, mirrored protection is intended to prevent data from being lost. Mirrored
protection is a software function that uses duplicates of disk-related hardware components to keep
your system available if one of the components fails. It can be used on any model of IBM i systems
and is a part of the Licensed Internal Code.
Remote mirroring support allows you to have one mirrored disk unit within a mirrored pair at the
local site, and the second mirrored disk unit at a remote site. For some systems, standard disk unit
mirroring remains the best choice; for others, remote disk unit mirroring provides important
additional capabilities. You must evaluate the uses and needs of your system, consider the
advantages and disadvantages of each type of mirroring support, and decide which is best for you.

© Copyright IBM Corp. 1995, 2017 10-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURULQJGHILQLWLRQV
‡ :LWKRXWPLUURULQJRQHXQLWHTXDOVRQHDFWXDWRU

,2$GDSWHU

8QLW 8QLW 8QLW 8QLW

‡ :LWKPLUURULQJRQHXQLWHTXDOVWZRDFWXDWRUV DPLUURUHGSDLU

,2$GDSWHU

8QLW 8QLW
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-37. Mirroring definitions

Because mirrored protection is configured by disk pool, you can mirror one, some, or all disk pools
on the system.
By default, every system has a system disk pool. It is not necessary to create user disk pools in
order to use mirrored protection. Although mirrored protection is configured by disk pool, all disk
pools must be mirrored to provide for maximum system availability. If a disk unit fails in a disk pool
that is not mirrored, the system cannot be used until the disk unit is repaired or replaced.
The start mirrored pairing algorithm automatically selects a mirrored configuration that provides the
maximum protection at the bus, IOA for the hardware configuration of the system. When disk units
of a mirrored pair are on separate buses, they have maximum independence or protection.
Because they do not share any resource at the bus, IOA levels, a failure in one of these hardware
components allows the other mirrored disk unit to continue operating.
Any data that is written to a disk unit that is mirrored is written to both disk units of the mirrored pair.
When data is read from a disk unit that is mirrored, the read operation can be from either disk unit of
the mirrored pair. It is not apparent to the user, which mirrored disk unit the data is being read from.
A user is not aware of the existence of two physical copies of the data.

© Copyright IBM Corp. 1995, 2017 10-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
If one disk unit of a mirrored pair fails, the system suspends mirrored protection to the failed
mirrored disk unit. The system continues to operate using the remaining mirrored disk unit. The
failing mirrored disk unit can be physically repaired or replaced. When a hot spare disk unit is
configured to protect the mirrored unit, the hot spare disk unit automatically replaces the failed
mirrored disk unit after the failed mirrored disk unit has been suspended for 5 minutes. The 5
minute waiting period avoids consuming the hot spare disk unit if the mirror suspension is a
temporary condition.
After the failed mirrored disk unit is repaired or replaced, the system synchronizes the mirrored pair
by copying current data from the disk unit that remains operational to the other disk unit. During
synchronization, the mirrored disk unit to which the information is being copied is in the resuming
state. Synchronization does not require a dedicated system and runs concurrently with other jobs
on the system. System performance is affected during synchronization. When synchronization is
complete, the mirrored disk unit becomes active.

© Copyright IBM Corp. 1995, 2017 10-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURUHGSURWHFWLRQ%HQHILWVDQGFRQVLGHUDWLRQV
‡ %HQHILWV
ƒ 'LVNXQLWV DQGGDWD GXSOLFDWHG
ƒ &RQWLQXHWRUXQZLWKRXWUHVWRUHDIWHUGLVNIDLOXUH
ƒ &RQFXUUHQWRUGHIHUUHGPDLQWHQDQFH
ƒ %HWWHUSHUIRUPDQFHWKDQGHYLFHSDULW\SURWHFWLRQ
ƒ (DV\DQGIDVWWRVWDUWDQGVWRS
‡ &RQVLGHUDWLRQV
ƒ &RQWLQXHWRUXQDIWHUPXOWLSOHGLVNIDLOXUHVEXWQRWERWKXQLWVLQPLUURUHGSDLU
ƒ 6\QFKURQL]DWLRQDIWHUUHSODFLQJIDLOHGGLVNDIIHFWVSHUIRUPDQFH
ƒ 3RVVLEOHLQFUHDVHG,3/WLPHDIWHUDEQRUPDOHQGWRV\QFKURQL]HGDWD
ƒ $GGLWLRQDOKDUGZDUH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-38. Mirrored protection: Benefits and considerations

Even if your system is not a large one, mirrored protection can provide valuable protection.
With the best possible mirrored protection configuration, the system continues to run after a single
disk-related hardware failure. On some system units, the failed hardware can sometimes be
repaired or replaced without having to turn off the system. If the failing component is one that
cannot be repaired while the system is running, such as a bus or an IOA, the system typically
continues to run after the failure. Maintenance can be deferred. The system can be shut down
normally, and a long recovery time can be avoided.
A disk or disk-related hardware failure on an unprotected system leaves your system unusable for
several hours. The actual time depends on the kind of failure, the amount of disk storage, your
backup strategy, the speed of your tape unit, and the type and amount of processing the system
performs. If you or your enterprise cannot tolerate this loss of availability, you should consider
mirrored protection for your system, regardless of your system's size.
Mirrored protection: Costs and limitations
The main cost of using mirrored protection is in additional hardware. To achieve high availability
and prevent data loss when a disk unit fails, you need mirrored protection for all the ASPs. This
normally requires twice as many disk units. If you want continuous operation and prevention of data
loss when a disk unit, I/O adapter, you need duplicate disk I/O adapters.

© Copyright IBM Corp. 1995, 2017 10-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
A model upgrade can be done to get nearly continuous operation and to prevent data loss when
any of these failures occur, as well as the failure of a bus. If bus 1 fails, the system cannot continue
to operate. Because bus failures are rare, and bus-level protection is not significantly greater than
I/O processor-level protection, you might not find a model upgrade to be cost-effective for your
protection needs.
Mirrored protection has a minimal effect on performance.
Limitations
Although mirrored protection can keep the system available after disk-related hardware failures
occur, it is not a replacement for save procedures. There can be multiple types of disk-related
hardware failures, or disasters (such as flood or sabotage) that require backup media.
Mirrored protection cannot keep your system available if the remaining storage unit in the mirrored
pair fails before the first failing storage unit is repaired and mirrored protection is resumed. If two
failed storage units are in different mirrored pairs, the IBM Power System with IBM i is still available
and normal mirrored protection recovery is done because the mirrored pairs are not dependent on
each other for recovery. If a second storage unit of the same mirrored pair fails, the failure might not
result in a data loss.
If both storage units in a mirrored pair fail causing data loss, the entire ASP is lost and all units in
the ASP are cleared. You must be prepared to restore your ASP from the backup media and apply
any journal changes.

© Copyright IBM Corp. 1995, 2017 10-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'LVNOHYHOPLUURUHGSURWHFWLRQ

%XV

,2$GDSWHU ,2$

'LVN 'LVN
XQLW XQLW

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-39. Disk-level mirrored protection

Disk unit-level protection


Mirrored protection always provides disk unit-level protection because the storage units are
duplicated. If your main concern is protection of data and not high availability, then disk unit-level
protection might be adequate. The disk unit is the most likely hardware component to fail, and disk
unit-level protection keeps your system available after a disk unit failure.
Concurrent maintenance is often possible for certain types of disk unit failures with disk unit-level
protection.
Some details about disk-level protection:
• The level of mirrored protection determines whether the system keeps running when different
levels of hardware fail. Mirrored protection always provides disk unit-level protection that keeps
the system available for a single disk unit failure. To keep the system available for failures of
other disk-related hardware requires higher levels of protection.
• The level of mirrored protection also determines whether concurrent maintenance can be done
for different types of failures. Certain types of failures require concurrent maintenance to
diagnose hardware levels above the failing hardware component. The higher the level of
mirrored protection, the more often concurrent maintenance is possible.

© Copyright IBM Corp. 1995, 2017 10-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• The level of protection you get depends upon the hardware you duplicate. If you duplicate disk
units, you have disk unit-level protection. If you duplicate unit I/O adapters as well, you have
IOA-level protection. If you duplicate buses, you have bus-level protection. Mirrored units will
always have at least disk unit-level protection. Because most internal disk units have the I/O
adapter packaged along with the disk unit, they at least have IOA-level protection.
• During the start mirrored protection operation, the system pairs the disk units to provide the
maximum level of protection for the system. When disk units are added to a mirrored ASP, the
system pairs only those disk units that are added without rearranging the existing pairs. The
hardware configuration includes both the hardware and how the hardware is connected.

© Copyright IBM Corp. 1995, 2017 10-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

,2$OHYHOPLUURUHGSURWHFWLRQ

%XV

,2$GDSWHU ,2$GDSWHU

'LVN 'LVN
XQLW XQLW

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-40. IOA-level mirrored protection

This visual details the concept of I/O adapter level protection.


IOA-level protection: Determine whether you want IOA-level protection based on the following:
• To keep your system available when a IOA fails.
• To concurrently repair a failed disk unit or IOA.
• To use problem recovery procedures in preparation for isolating a failing item or to verify a
repair action, To achieve IOA-level protection, all disk units must have a mirrored unit attached
to a different IOA. Most internal disk units have their IOA packaged as part of the disk unit, so
internal disk units generally have at least IOA-level protection.

© Copyright IBM Corp. 1995, 2017 10-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

%XVOHYHOPLUURUHGSURWHFWLRQ

%XV %XV

,2$GDSWHU ,2$GDSWHU

'LVN 'LVN
XQLW XQLW

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-41. Bus-level mirrored protection

This visual details the concept of bus-level protection.


Bus-level protection: Bus-level protection might allow the system to run when a bus fails. If a bus
fails, disk I/O operations might continue, but so much other hardware is lost, such as printers and
communication lines, that from a practical standpoint, the IBM Power System with IBM i is not
usable.
• Bus failures are rare compared with other disk-related hardware failures.
• Concurrent maintenance is not possible for bus failures.
To achieve bus-level protection, all disk units that are attached to a bus must have a mirrored unit
attached to a different bus.

© Copyright IBM Corp. 1995, 2017 10-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

([SDQVLRQXQLWOHYHOPLUURUHGSURWHFWLRQ

6$6FDEOH
6$6FDEOH

0LUURUHG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-42. Expansion unit level mirrored protection

This visual details the concept of Expansion-level protection.


Expansion-level protection: POWER7 or POWER7+ allows the use of HSL2 ring. Now with
Power8 and SAS expansion (drawers) you can set up mirroring between drawers then you have
the highest level of mirror protection.
To achieve expansion-level protection, you must have two expansion [Link] highest availability is
if drawers are attached to different CEC (Central Electronic Complex) like in the visual.

© Copyright IBM Corp. 1995, 2017 10-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

3URWHFWLRQOHYHO

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-43. Protection level

The Display Protection for Multiple Connection Disk Units display shows the level of data
accessibility for each disk unit with multiple connections.
Protection:
This is the level of accessibility to the disk unit data that the system has through the operational
connections to the disk units.
The valid values are:
I/O Bus:
The disk unit is protected at the I/O Adapter bus level. The system continues to have access to the
disk unit data if the I/O Adapter bus of one of the connections to the disk unit fails.
I/O Adapter:
The disk unit is protected at the I/O Adapter level. The system continues to have access to the disk
unit data if the I/O Adapter of one of the connections to the disk unit fails.
I/O Processor:
The disk unit is protected at the I/O Processor level. The system continues to have access to the
disk unit data if the I/O Processor of one of the connections to the disk unit fails. Note: Currently
there are no physical IOPs now there are only virtual IOPs (firmware).

© Copyright IBM Corp. 1995, 2017 10-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
Bus:
The disk unit is protected at the system bus level. The system continues to have access to the disk
unit data if the system bus that controls the I/O Processor for one of the connections to the disk unit
fails.
CEC Node:
The disk unit is protected at the CEC node level. The system continues to have access to the disk
unit data if the CEC node that contains the I/O Processor of one of the connections to the disk unit
fails.
Tower:
The disk unit is protected at the tower level. The system continues to have access to the disk unit
data if the tower that contains the I/O Processor of one of the connections to the disk unit fails.
Ring:
The disk unit is protected at the ring level. The system continues to have access to the disk unit
data if the I/O loop (12X and/or RIO no in Power8) which controls the I/O Processor of one of the
connections to the disk unit fails.
Remote Bus:
The disk unit is protected at the remote bus level. The system continues to have access to the disk
unit data if the system bus that controls the I/O Processor of one of the connections to the disk unit
fails.
To display protection level use SST:
1. Run STRSST command on the command line and type DST/SST user ID and password.
2. Choose option 3 Work with Disk Unit.
3. Choose option 1 Display Disk Configuration.
4. Choose option 11 Display protection for multiple connection disk units.

© Copyright IBM Corp. 1995, 2017 10-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'LVNSURWHFWLRQZLWKGXDOVWRUDJH PLUURU

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-44. Disk protection with dual storage - mirror

You can increase availability by using a dual storage I/O adapter (IOA) configuration to connect
multiple controllers to a common set of disk expansion drawers and the included disks and disk
arrays.
For operating system mirroring:
• Four controllers (two pairs of controllers)
• Each pair of controllers must have the same write cache capability and write cache sizes
• Each pair of controllers must support dual storage IOA configuration
• Controllers are in the same system or partition

© Copyright IBM Corp. 1995, 2017 10-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURULQJSHUIRUPDQFH
‡ 7KHUHLVHTXDORUEHWWHUSHUIRUPDQFHIRUUHDGV

‡ 7KHUHLVDVOLJKWGHFUHDVHLQSHUIRUPDQFHIRUZULWHV

‡ ,3/DIWHUDEQRUPDOHQGPLJKWEHORQJHULIV\QFKURQL]DWLRQLVQHFHVVDU\

‡ <RXZLOOQRWLFHDGHFUHDVHLQSHUIRUPDQFHZKLOHPLUURULQJLVILUVWEHLQJ
VWDUWHGDQGZKLOHDIDLOHGGLVNLVEHLQJUHSODFHG

‡ 0DFKLQHSRRO,QFUHDVHVL]H

‡ 0DLQWDLQUDWLRRIGLVNXQLWVWR,2SURFHVVRUV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-45. Mirroring performance

Mirroring and performance: When mirrored protection is started, most systems show little
difference in performance; in some cases, mirrored protection can improve performance. Generally,
functions that do mostly read operations see equal or better performance with mirrored protection.
This is because read operations have a choice of two storage units to read from, and the one with
the faster expected response time is selected. Operations that do mostly write operations (such as
updating database records) might see slightly reduced performance on a system that has mirrored
protection because all changes must be written to both storage units of the mirrored pair. Thus,
restore operations are slower.
In some cases, if the system ends abnormally, the system cannot determine whether the last
updates were written to both storage units of each mirrored pair. If the IBM Power System with IBM
i is not sure that the last changes were written to both storage units of the mirrored pair, the system
synchronizes the mirrored pair by copying the data in question from one storage unit of each
mirrored pair to the other storage unit. The synchronization occurs during the IPL that follows the
abnormal system end. If the system can save a copy of main storage before it ends, the
synchronization process takes just a few minutes. If not, the synchronization process can take
much longer. The extreme case could be close to a complete synchronization.
Mirrored protection normally requires additional disk units and input/output devices. However, in
some cases, you might need additional hardware to achieve the level of performance that you want
(for example additional drawer, additional place in SAN switch if using external storage).

© Copyright IBM Corp. 1995, 2017 10-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

&RQFXUUHQWPDLQWHQDQFH
‡ 5HSODFHRUUHSDLUIDLOLQJKDUGZDUHZKLOHWKHV\VWHPUXQV

‡ 0LUURULQJOHYHO!OHYHORIFRQFXUUHQWPDLQWHQDQFH

‡ 667'LVNVXSSRUWWRROVDUHDYDLODEOH

‡ (&6LVDYDLODEOHWRUHSRUWDSUREOHP

‡ 6RPHUHSDLUVUHTXLUHDFWLYHXQLWVWREHVXVSHQGHG
ƒ <RXFDQFKRRVHWRGHIHUPDLQWHQDQFH

‡ 6RPHUHSDLUVUHTXLUHWKHV\VWHPWREHSRZHUHGRII GHIHUUHG
PDLQWHQDQFH 

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-46. Concurrent maintenance

ECS - Electronic Customer Support


Concurrent maintenance is the process of repairing or replacing a failed disk-related hardware
component while using the system.
With mirrored protection the failing hardware can be repaired or replaced while the IBM Power
System with IBM i is being used.
Concurrent maintenance support is a function of system unit hardware packaging. Mirrored
protection only provides concurrent maintenance when the hardware and packaging of the system
support it. The best hardware configuration for mirrored protection also provides for the maximum
amount of concurrent maintenance.
It is possible for the system to operate successfully through many failures and repair actions. For
example, a failure of a disk head assembly will not prevent the system from operating. A
replacement of the head assembly and synchronization of the mirrored unit can occur while the
system continues to run. The greater your level of protection, the more often concurrent
maintenance can be performed.

© Copyright IBM Corp. 1995, 2017 10-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURUHGSURWHFWLRQSODQQLQJ
‡ 'HFLGHZKLFK$63RU$63VWRSURWHFW

‡ 'HWHUPLQHGLVNVWRUDJHFDSDFLW\UHTXLUHPHQWV

‡ 'HWHUPLQHWKHOHYHORISURWHFWLRQ\RXZDQWIRUHDFKPLUURUHG$63

‡ 'HWHUPLQHWKHH[WUDKDUGZDUH\RXQHHGIRUPLUURUHGSURWHFWLRQ

‡ 'HWHUPLQHWKHH[WUDKDUGZDUH\RXQHHGIRUSHUIRUPDQFH

‡ 2UGHU\RXUKDUGZDUH

‡ 3ODQWKHLQVWDOODWLRQRI\RXUV\VWHPDQGWKHFRQILJXUDWLRQRIQHZXQLWV

‡ ,QVWDOOWKHQHZKDUGZDUH
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-47. Mirrored protection planning

Deciding which ASPs to protect


Mirrored protection is configured by auxiliary storage pool because the ASP is the user's level of
control over single-level storage. Mirrored protection can be used to protect one, some, or all ASPs
on a system. All units should be protected with mirror or parity protection.
To provide the best protection and availability for the entire system, all ASPs in the system should
have protection type depending on availability of hardware.
The disk units that are used in user ASPs should be selected carefully. For best protection and
performance, an ASP should contain disk units that are attached to several different I/O adapters.
Determining the disk units that are needed
A mirrored ASP requires twice as much auxiliary storage as an ASP that is not mirrored because
the system keeps two copies of all the data in the ASP. Also, mirrored protection requires an even
number of disk units of the same capacity so that disk units can be made into mirrored pairs. On an
existing system, it should be noted that it is not necessary to add the same types of disk units
already attached in order to provide the required additional storage capacity. Any new disk units
might be added as long as sufficient total storage capacity and an even number of storage units of
each size are present. The system assigns mirrored pairs and automatically move the data as
necessary.

© Copyright IBM Corp. 1995, 2017 10-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
The process of determining the disk units that are needed for mirrored protection is similar for
existing or new systems. You should do the following:
• Plan how much data each ASP contains.
• Plan a target percent of storage used for the ASP (how full the ASP is).
• Plan the number and type of disk units needed to provide the storage that is required. For an
existing ASP, you can plan a different type and model of disk unit to provide the required
storage. You must ensure an even number of each type of disk unit and model.
• After planning for all ASPs is completed, plan for spare units, if wanted.
• Once you know all of this information, you can calculate your total storage needs.
Determining the level of protection that you want
The level of mirrored protection determines whether the system keeps running when different levels
of hardware fail. The level of protection is the amount of duplicate disk-related hardware that you
have. The more mirrored pairs that have higher levels of protection, the more often your IBM Power
System with IBM i is usable when disk related hardware fails. You might decide that a lower level of
protection is more cost effective for your system than a higher level. The levels of protection, in
order from lowest to highest, are as follows:
1. Disk unit-level protection
2. IOA-level protection
3. Bus-level protection
4. Expansion-level protection
When determining what level of protection is adequate, you should consider the relative
advantages of each level of protection with respect to the following:
• The ability to keep the system operational during a disk-related hardware failure
• The ability to perform maintenance concurrently with system operations
• To minimize the time that a mirrored pair is unprotected after a failure, you might want to repair
failed hardware while the IBM Power System with IBM i is operating
During the start mirrored protection operation, the system pairs the disk units to provide the
maximum level of protection for the system. When disk units are added to a mirrored ASP, the
system pairs only those disk units that are added without rearranging the existing pairs. The
hardware configuration includes both the hardware and how the hardware is connected.
Determining the hardware that is needed for mirroring
In order to communicate with the rest of the system, disk units are attached to I/O adapters.
To provide the best protection and performance, each level of hardware should be balanced under
the next level of hardware. That is, the disk units of each device type and model should be evenly
distributed under their I/O adapters.
To plan what disk-related hardware is needed for your mirrored system, you must plan the total
number and type of disk units (old and new) that are needed on the system, as well as the level of
protection for the system.

© Copyright IBM Corp. 1995, 2017 10-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
When planning for additional disk-related hardware, you need to do the following:
• Determine the minimum hardware that is needed for the planned disk units to function - plan for
one disk unit size at a time.
• Plan the additional hardware needed to provide the wanted level of protection for each disk unit
type.
Determine the extra hardware needed for performance
Mirrored protection normally requires additional disk units and controllers. However, in some cases,
you might need additional hardware to achieve the level of performance that you want.
Use the following information to decide how much extra hardware you might need:
• Processing unit requirements
▪ Mirrored protection causes a minor increase in central processing unit usage
(approximately 1% to 2%).
• Main storage requirements
▪ If you have mirrored protection, you need to increase the size of your machine pool. During
synchronization, mirrored protection can use an additional memory.
▪ Amount of memory depending on mirrored storage and it could require additional tuning.
Planning your installation
You must work with your IBM marketing representative to plan for the installation of mirrored
protection on your system. The marketing representative helps you determine whether your IBM
Power System with IBM i is balanced and meets standard configuration rules. The system must be
configured according to the standard rules in order for the mirrored pairing function to pair up
storage units to provide the best protection possible from the hardware that is available. Your
marketing representative also helps you plan for the new units that are needed to add for each ASP.

© Copyright IBM Corp. 1995, 2017 10-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURUHGIDLOXUHVFHQDULR
‡ 6WRUDJHPDQDJHPHQWGHWHFWVXQUHFRYHUDEOHGLVNIDLOXUH

‡ 6\VWHPGRHVQRWVKXWGRZQ

‡ 3URWHFWLRQLVORVWRQO\RQWKDWPLUURUHGSDLU

‡ 6WRUDJHPDQDJHPHQWVXVSHQGVIDLOLQJGHYLFHRIPLUURUHGSDLU

‡ 0HVVDJHLVVHQWWRQSYSOPR

‡ 5HSDLURUUHSODFHIDLOLQJGHYLFH

‡ 0LUURULQJLVUHVXPHGDXWRPDWLFDOO\IRUUHSODFHGXQLWV

‡ ,IQHFHVVDU\UHVXPHPLUURUHGSURWHFWLRQIRUUHSDLUHGRUVXVSHQGHG
XQLWV
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-48. Mirrored failure scenario

If one storage unit of a mirrored pair fails, the system suspends mirrored protection to the failed
mirrored unit. The system continues to operate using the remaining mirrored unit. The failing
mirrored unit can be physically repaired or replaced.
After the failed mirrored unit is repaired or replaced, the system synchronizes the mirrored pair by
copying current data from the storage unit that has remained operational to the other storage unit.
During synchronization, the mirrored unit to which the information is being copied is in the resuming
state. Synchronization does not require a dedicated system and runs concurrently with other jobs
on the system. System performance is affected during synchronization. When synchronization is
complete, the mirrored unit becomes active.

© Copyright IBM Corp. 1995, 2017 10-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0LUURULQJYHUVXVGHYLFHSDULW\SURWHFWLRQ

$YDLODELOLW\ 3HUIRUPDQFH &RVW

0LUURUHG
0LUURUHG 'HYLFHSDULW\
 SURWHFWLRQ
SURWHFWLRQ SURWHFWLRQ
VHHQRWH

'HYLFHSDULW\ 'HYLFHSDULW\ 0LUURUHG



SURWHFWLRQ SURWHFWLRQ SURWHFWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-49. Mirroring versus device parity protection

When mirrored protection is started, most systems show little difference in performance; in some
cases, mirrored protection can improve performance. Generally, functions that do mostly read
operations see equal or better performance with mirrored protection. This is because read
operations have a choice of two storage units to read from, and the one with the faster expected
response time is selected. Operations that do mostly write operations (such as updating database
records) might see slightly reduced performance on a system that has mirrored protection because
all changes must be written to both storage units of the mirrored pair. Thus, restore operations are
slower.
With both device parity protection and mirrored protection, the system continues to run after a
single disk failure when using RAID-5 or two disk failures when using RAID-6. With mirrored
protection, the system might continue to run after the failure of a disk-related component, such as
an IOA or bus, drawer.
When a second disk failure occurs such that the system has two failed disks (and you are not using
RAID-6), the IBM Power System with IBM i is failed and need restore from tape.
The mirrored protection is usually a more expensive solution than device parity protection.
Usually, neither device parity protection nor mirrored protection has a noticeable effect on system
performance. In some cases, mirrored protection actually improves system performance.

© Copyright IBM Corp. 1995, 2017 10-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
The restore time to disk units protected by device parity protection is slower than the restore time to
the same disk devices without device parity protection activated because the parity data must be
calculated and written.

© Copyright IBM Corp. 1995, 2017 10-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.4. Topic 4: Hot spare protection

© Copyright IBM Corp. 1995, 2017 10-68


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF+RWVSDUHSURWHFWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-50. Topic 4: Hot spare protection

© Copyright IBM Corp. 1995, 2017 10-69


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

+RWVSDUHFRQFHSW
‡ +RWVSDUHSURWHFWLRQFRQFHSWV
ƒ +RWVSDUHGLVNXQLWVDUHVSDUHGLVNXQLWVVWRUHGRQDV\VWHPWRUHSODFHIDLOHG
GLVNVLQFDVHDGLVNIDLOXUHRFFXUV

ƒ +RWVSDUHGLVNXQLWVFDQEHXVHGWRSURWHFWERWKGHYLFHSDULW\SURWHFWHGGLVN
XQLWVDQGPLUURUSURWHFWHGGLVNXQLWV

ƒ $KRWVSDUHGLVNXQLWLVVWRUHGRQWKHV\VWHPDVDQRQFRQILJXUHGGLVN:KHQ
DGLVNIDLOXUHRFFXUVWKHV\VWHPH[FKDQJHVWKHKRWVSDUHGLVNXQLWZLWKWKH
IDLOHGGLVNXQLW

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-51. Hot spare concept

For device parity protected disk units, the hot spare disk unit must be the same capacity as the
failed disk unit for a Small Computer System Interface (SCSI) IOA, or the same or larger capacity
for a Serial Attached SCSI (SAS) IOA. The hot spare disk unit must also be under the same IOA in
order for the exchange to occur. After the exchange occurs, the system rebuilds the data on the
new disk unit.
For mirror-protected disk units, the hot spare disk unit must be the same capacity as the failed disk
unit in order for the exchange to occur. The exchange of a mirrored subunit with the hot spare disk
unit does not occur until mirror-protection has been suspended for 5 minutes and the replacement
disk has been formatted.
After the exchange occurs, the system synchronizes the data on the new disk unit. A hot spare disk
unit can be created manually from non-configured disk units on your system to protect existing or
future mirror-protected units and device parity protected units. You can select which disk units and
how many become hot spares.
When using hot spare protection with device parity protection, the system can automatically select
and configure the hot spare disk unit when you initially start device parity protection.
The hot spare disk units are not designated to any particular parity set. The hot spare disk unit
protects the first failed disk unit that has parity protection, is the appropriate capacity for the hot
spare disk unit, and is under the same IOA as the hot spare disk unit.

© Copyright IBM Corp. 1995, 2017 10-70


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

+RWVSDUHFRVWDQGOLPLWDWLRQV
‡ +RWVSDUHGLVNXQLWVSURWHFWRQO\SDULW\VHWVZLWKWKHVDPHFDSDFLW\GLVN
XQLWV IRU6&6,,2$V RUSURWHFWRQO\SDULW\VHWVZLWKWKHVDPHRU
VPDOOHUFDSDFLW\GLVNXQLWV IRU6$6,2$V 

‡ +RWVSDUHGLVNXQLWVSURWHFWRQO\PLUURUSURWHFWHGXQLWVZKHUHWKH
FDSDFLW\RIWKHKRWVSDUHLVWKHVDPHFDSDFLW\DVUHTXLUHGZKHQ
UHSODFLQJDVXEXQLWLQDPLUURUHGSDLU

‡ ,QRUGHUWRFUHDWHDQHZ5$,'SDULW\VHWZLWKKRWVSDUHGLVNXQLWVD
PLQLPXPRIILYHGLVNXQLWVLVQHHGHG,IWKHUHDUHQRWDWOHDVWILYHGLVN
XQLWVWKHQWKHV\VWHPUHFRPPHQGVWKHFUHDWLRQRID5$,'SDULW\VHW
ZLWKKRWVSDUHLQVWHDG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-52. Hot spare cost and limitations

In order to use hot spare for your parity protected disk units, the following requirements must be
met:
• The disk units must be parity protected.
• The hot spare disk unit must be under the same IOA as the disk units that you want protected.
• The hot spare disk unit must be the same capacity as the failed parity protected disk unit (for
SCSI IOAs) or must be the same or larger capacity as the failed parity protected disk unit (for
SAS IOAs).
• When an IOA controls the load source disk unit, the hot spare disk unit must be in a valid load
source location. This might require additional planning when using a SCSI IOA since the valid
load source.
• Locations are typically a subset of the possible disk unit locations within the enclosure. The
system will not allow the Start device parity protection with Hot Spare to occur if this requirement
is not met.
• The hot spare disk unit must be a non-configured and unprotected disk unit.

© Copyright IBM Corp. 1995, 2017 10-71


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• In order to use hot spare for your mirror protected disk units, the following requirements must be
met:
▪ The disk units must be mirror protected.
▪ The hot spare disk unit is under any IOA that supports hot spare.
▪ The hot spare disk capacity must meet the same requirement as when replacing a subunit
in a mirrored pair. The hot spare capacity must be the same or slightly larger than the
suspended disk unit.
▪ The hot spare disk unit must be a non-configured and unprotected disk unit.

© Copyright IBM Corp. 1995, 2017 10-72


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

6WDUWLQJVWRSSLQJKRWVSDUH RI

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-53. Starting stopping hot spare (1 of 2)

To start hot spare protection with the command line, take the following steps:
1. Start System Service Tools (STRSST), and specify the user name and password.
2. On the System Service Tools (SST) display, select option 3 Work with disk units.
3. On the Work with Disk Units display, select option 2 Work with disk configuration.
4. On the Work with Disk Configuration display, select option 9 Start hot spare or 10 Stop hot
spare depending on the requirements.

© Copyright IBM Corp. 1995, 2017 10-73


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

6WDUWLQJVWRSSLQJKRWVSDUH RI

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-54. Starting stopping hot spare (2 of 2)

To start hot spare protection with the command line, take the following steps:
1. Start System Service Tools (STRSST), and specify the user name and password.
2. On the System Service Tools (SST) display, select option 3 Work with disk units.
3. On the Work with Disk Units display, select option 2 Work with disk configuration.
4. On the Work with Disk Configuration display, select option 9 Start hot spare or 10 Stop hot
spare depending on the requirements.

© Copyright IBM Corp. 1995, 2017 10-74


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0DQDJLQJKRWVSDUH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-55. Managing hot spare

To display hot spare status using the command line, take the following steps:
1. Start System Service Tools (STRSST), and specify the user name and password.
2. On the System Service Tools (SST) display, select option 3 Work with disk units.
3. On the Work with Disk Units display, select option 2 Work with disk configuration.
4. On the Work with Disk Configuration display, select option 1 Display disk configuration.
5. On the Display disk configuration display, select option 8 Display hot spare disk unit status.

© Copyright IBM Corp. 1995, 2017 10-75


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.5. Topic 5: Multipathing

© Copyright IBM Corp. 1995, 2017 10-76


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF0XOWLSDWKLQJ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-56. Topic 5: Multipathing

© Copyright IBM Corp. 1995, 2017 10-77


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

0XOWLSDWKLQJ

,2$
3DUWLWLRQ 
,2$

,2$
3DUWLWLRQ  ,2$
,2$
,2$

6$16ZLWFK

6HUYHU 6WRUDJH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-57. Multipathing

Multiple connections can be defined from multiple Input / Output Adapters (IOAs) on a system to a
single logical unit number (LUN) in the external or internal disk storage.
Because multipathing to external storage is more flexibility here more about it.
The concurrently supports diverse host systems over diverse attachment protocols. Each
connection for a multipath disk unit functions independently.
Several connections provide availability by allowing disk storage to be used even if a single path
fails.
Partition 1 has multiple paths defined from two different IOAs to one LUN in the storage.
Partition 2 also has multiple paths defined from four different IOAs to a different LUN (than
partiotion1) in the storage.
The multipathing can improve performance.

© Copyright IBM Corp. 1995, 2017 10-78


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.6. Topic 6: Disk configuration and recovery

© Copyright IBM Corp. 1995, 2017 10-79


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF'LVNFRQILJXUDWLRQ
DQGUHFRYHU\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-58. Topic 6: Disk configuration and recovery

© Copyright IBM Corp. 1995, 2017 10-80


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'LVNFRQILJXUDWLRQDQGSURWHFWLRQSURFHGXUHV

0LUURUHGSURWHFWLRQ $63V
'LVNFRPSUHVVLRQ /3$5V
'HYLFHSDULW\SURWHFWLRQ

%DFNXSDQG5HFRYHU\PDQXDO
6HOHFWDSSURSULDWHFKHFNOLVW
  
  
   
 
  
  

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-59. Disk configuration and protection procedures

The IBM i Systems Management Recovering Your System (SC41-5304-12) manual has detailed
checklists for procedures involving disk configuration and protection. The checklists can be found
starting on page 373, in the section titled Part 6: Disk configuration and protection.

Note

Many of the checklists require the use of either the System Service Tools (SST) or Dedicated
Service Tools (DST).

You can reach this document at:


[Link]

© Copyright IBM Corp. 1995, 2017 10-81


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HFRYHU\RIGLVNIDLOXUHRUGLVNHUURUV RI

%DFNXSDQG5HFRYHU\PDQXDO

 6HOHFW'LVNUHFRYHU\FKHFNOLVW


 

 



'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-60. Recovery of disk failure or disk errors (1 of 2)

For disk failure or disk errors, first recover the disk, then recover the data. To recover the disk select
the appropriate checklist. The checklist selection depends on the following:
• Which disk unit failed.
• Whether device parity protection or mirrored protection was active.
• Whether the ASPs are configured.
• Whether or not the failed disk could be pumped.
If a disk unit must be replaced, a service representative normally tries to copy the information from
the disk unit when it is replaced.
The recovery checklists are very specific procedures to guide you through recovery.

© Copyright IBM Corp. 1995, 2017 10-82


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HFRYHU\RIGLVNIDLOXUHRUGLVNHUURUV RI

%DFNXSDQG5HFRYHU\PDQXDO
6HOHFWFKHFNOLVWWRUHFRYHUXVHUGDWD

 


 

 


'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-61. Recovery of disk failure or disk errors (2 of 2)

After the disk is recovered, then the next step is to recover the user data.
To recover user data select the appropriate checklist. The checklist depends on the following:
• Whether all ASPs are being recovered.
• The procedure used to save the data.
• Whether there are SAVCHGOBJs or journal receivers to apply.
• Whether you want to use menu options to recover.

© Copyright IBM Corp. 1995, 2017 10-83


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

'$6'GLVNPDQDJHPHQW
‡ 8VLQJ,%01DYLJDWRUIRUL
ƒ &RPSOHWH'$6'PDQDJHPHQW
ƒ '67VXSSRUW VXEVHW
ƒ 9LHZDQGDGGGLVNXQLWV
ƒ 'LVNEDODQFLQJ
ƒ &UHDWHDQGPDQDJH$63VDQG
GLVNXQLWV
ƒ &UHDWHDQGPDQDJH,$63
ƒ &RPSUHVVLRQ
ƒ *UDSKLFSK\VLFDOORFDWLRQ
LQWHUQDOGLVNVRQO\
‡ 8VLQJ
ƒ &UHDWH$63DQG,$63
ƒ $GGFKDQJHUHPRYHGLVNV
ƒ )RUPDW
ƒ 5HSDLUGLVNVGDWD
ƒ &RS\ORDGVRXUFH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-62. DASD disk management

DASD Direct Access Storage Device. Today we talk rather about storage because quiet often IBM i
use external storage.
To manage storage you can use both GUI using IBM Navigator for i and 5250 interface.
To use IBM Navigator from i to manage disks:
1. Logon to IBM Navigator for i by opening [Link] or IP address>>:2001 and logon
with user name and password.
2. On the left pane expand Configuration and Service you must provide DST/SST user ID and
profile.
3. On the left pane click Disk Unit.
To manage disk from 5250 you can:
On the command line use WRKDSKSTS command to work with existing disks status.
CFGDEVASP allows you to create ASP or IASP different than *SYSBAS (ASP1).
DST / SST allows you to do a lot of disk operations.

© Copyright IBM Corp. 1995, 2017 10-84


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

:RUNZLWK'LVN&RQILJXUDWLRQ

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-63. Work with Disk Configuration

To manage disk using SST


1. Run STRSST on the command line and type DST/SST user ID and password
2. Choose option 3 Work with Disk Unit.
3. Choose option 2 Work with Disk Configuration and choose following options:
• Option 1. Display disk configuration
▪ Select this option to display the system's current disk configuration and any non-configured
disk units.
▪ Non-configured disk units are units attached to the system but not yet assigned to an
auxiliary storage pool (ASP).
• Option 2. Add units to ASPs
▪ Select this option to create unencrypted ASPs, encrypted ASPs or add disk units to any
ASPs, and to not balance data on any ASPs. This option is adequate if you are adding
many units to an ASP that has relatively few units. Otherwise use option 4.

© Copyright IBM Corp. 1995, 2017 10-85


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• Option 3. Work with ASP threshold
▪ Select this option to display or change the threshold value for the amount of storage in use
for every auxiliary storage pool (ASP) on the system. The default value of the threshold is
90 percent.
▪ The system notifies you when the threshold value is reached.
• Option 4. Add units to ASPs and balance data
▪ Select this option to create unencrypted ASPs, encrypted ASPs or add disk units to any
ASPs, and then for each selected ASP, balance data among all units in the ASP.
▪ This option is useful if you are adding a small number of units to an ASP that already has
many units.
• Option 5. Enable remote load source mirroring
▪ Select this option to turn on the ability to physically place the two units that make up the
mirrored load source disk unit (unit 1) on different IOPs.
▪ This option does not start mirrored protection.
• Option 6. Disable remote load source mirroring
▪ Select this option to turn off the ability to physically place the two units that make up the
mirrored load source disk unit (unit 1) on different IOPs.
▪ This option does not stop mirrored protection.
• Option 7. Start compression on non-configured units
▪ Select this option to start compression on a non-configured disk unit. This will effectively
increase the size of the disk unit.
• Option 8. Work with device parity protection
▪ Select this option to Display parity protection, include a disk unit into a parity set, or to start
device parity.
• Option 9. Start Hot Spare
▪ Select this option to allow a hot spare disk unit to be created. If a Storage IOA is selected
and sufficient resources are available, a single hot spare disk unit is created under that IOA.
If a disk unit is selected, that disk becomes the hot spare disk unit.
▪ The disk unit remains reserved as a hot spare disk unit until a failure occurs in the parity set
and the hot spare disk unit replaces the failed unit.
• Option 10. Stop Hot Spare
▪ Select this option to stop hot spare on the selected disk unit. In case of disk failure,
immediate manual intervention is required to avoid data loss.
▪ After hot spare is stopped the disk unit's normal behavior is achieved, the hot spare disk unit
is possible to use.

© Copyright IBM Corp. 1995, 2017 10-86


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• Option 11. Work with encryption
▪ Select this option to display encryption status, create encrypted ASPs, add units to
encrypted ASPs, start or stop encryption on existing ASPs, or change the data encryption
key used to encrypt data on ASPs. Base operating system option 45, Encrypted ASP
Enablement must be installed in order to use some of the functions of this option.
• Option 12. Work with removing units from configuration
▪ Select this option to remove disk units from an ASP configuration, resume a paused remove
operation, display the status of current remove operations, pause removing disk units or
cancel the remove operation.

© Copyright IBM Corp. 1995, 2017 10-87


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

:RUNZLWK'LVN8QLW5HFRYHU\

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-64. Work with Disk Unit Recovery

To recovery disk using SST:


1. Run STRSST on the command line and type DST/SST user ID and password
2. Choose option 3 Work with Disk Unit.
3. Choose option 3 Work with Disk Unit Recovery and choose following options:
• Option 1. Replace configured unit
▪ Select this option to replace a configured disk unit with a disk unit that is not configured. The
replace function will not save or restore the data.
• Option 2. Disk unit problem recovery procedures
▪ Select this option when a disk unit service manual directs you to use the system
documentation to run problem recovery procedures.
• Option 3. Suspend mirrored protection
▪ Select this option when you want to stop mirrored protection for a unit in a mirrored auxiliary
storage pool.

© Copyright IBM Corp. 1995, 2017 10-88


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• Option 4. Resume mirrored protection
▪ Select this option when you want to restart mirrored protection for a unit in a mirrored
auxiliary storage pool.
• Option 5. Delete disk unit data
▪ Select this option when you want to remove the data from one or more disk units. This
action clears all data from the selected units after you confirm the choice.
• Option 6. Rebuild disk unit data
▪ Select this option when a disk unit that caused a parity set to become exposed has been
repaired and is ready to be used again. Using this option rebuilds all the data on the unit
using the redundancy feature of device parity protection.
• Option 7. Reclaim IOA Cache Storage
▪ Select this option to discard the data in IOA cache. The discarded data is lost, so damaged
objects could result from using this function.
• Option 8. Detect attached IASP disk units
▪ Select this option to accept into the configuration IASPs. The system examines the
non-configured disk units to find eligible IASPs.

© Copyright IBM Corp. 1995, 2017 10-89


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
10.7. Topic 7: Abnormal system end

© Copyright IBM Corp. 1995, 2017 10-90


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

7RSLF$EQRUPDOV\VWHPHQG

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-65. Topic 7: Abnormal system end

© Copyright IBM Corp. 1995, 2017 10-91


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

$EQRUPDOV\VWHPHQG
‡ &DXVHVRIDQDEQRUPDOHQG
ƒ 3RZHUIDLOXUH
ƒ 'LVNIDLOXUH
ƒ )DLOXUHRIFULWLFDO,%0LSURJUDP

‡ :KDWPLJKWQRWKDYHEHHQILQLVKHG
ƒ &KDQJHGSDJHVZULWWHQWRDX[LOLDU\VWRUDJH
ƒ &ORVLQJRIILOHVDQGDFFHVVSDWKV
ƒ (QGRISURJUDPVDWQDWXUDOSRLQWV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-66. Abnormal system end

The following list describes the circumstances that can cause your system to stop unexpectedly
and what happens when it does.
• Power failure with uninterruptible power supply: When the system loses normal power, the
uninterruptible power supply system takes over and keeps the system running. The system
detects this change and sends a message to your power-monitoring program. Your program
can decide whether to keep the system running until power returns or to begin an orderly
shutdown.
• Power failure with continuously powered main store: If your system has this feature, a
battery provides sufficient power to shut down the system and maintain the contents of memory
after a power loss. In many cases, this can significantly reduce the amount of time the system
requires to perform an initial program load (IPL) after a power loss. This continuously powered
main store feature can also take control if the uninterruptible power supply system can no
longer maintain power.
Depending on configuration the system can automatically restarts when power is restored. You
might see the Disk Configuration Error Report display.
• Power failure with no protection: If your system does not have an uninterruptible power
supply and the power fails, your system stops immediately. The contents of main memory are
lost. The system must reconstruct information when power returns. This can be very

© Copyright IBM Corp. 1995, 2017 10-92


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
time-consuming. Whether the system starts automatically depends on how you have set the
QPWRRSTIPL system value.
• Disk failure with device parity protection or mirrored protection: In many cases, the
system can continue running without full disk protection until the failed unit is replaced.
• Disk failure without disk protection: This is like a power failure without protection. The
system stops immediately. The system must reconstruct information about jobs that were
running and files that were open after the disk is repaired or replaced.
• Failure of a critical operating system program: The system stops immediately, just as it does
if an unprotected power failure or disk failure occurs. The system attempts to copy the contents
of main memory so that the problem can be analyzed. This is called a main storage dump.
When the system stops, you see the Main Storage Dump Manager Occurred display

© Copyright IBM Corp. 1995, 2017 10-93


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HVWDUWDIWHUDEQRUPDOHQG
‡ $FWLRQVWDNHQE\WKHV\VWHP
ƒ &ORVHILOHVWKDWZHUHLQXVH
ƒ 5HEXLOGDFFHVVSDWKVWKDWZHUHRSHQ
ƒ 9HULI\ILOHFRQVWUDLQWV
ƒ *HQHUDWHGLVNFRQILJXUDWLRQHUURUUHSRUWLIGLVNVDUHLQDFFHVVLEOH
ƒ )RUVHULRXVVRIWZDUHSUREOHPVSURPSWWRFRS\PDLQVWRUDJHGXPS
‡ 1RUPDO,3/
ƒ 6\VWHPGHWHUPLQHVZKHQWRUHEXLOGDQGYHULI\
‡ $WWHQGHG,3/ UHIHUWR%DFNXSDQG5HFRYHU\PDQXDOIRUVSHFLILF
SURFHGXUH 
ƒ (GLW5HEXLOGRI$FFHVV3DWKVGLVSOD\
ƒ (GLW&KHFN3HQGLQJ&RQVWUDLQWVGLVSOD\
‡ 5HFRYHUIURPGDPDJHGREMHFWVDQGXQUHDGDEOHVHFWRUV VHH%DFNXS
DQG5HFRYHU\PDQXDOIRUVSHFLILFSURFHGXUHV 

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-67. Restart after abnormal end

When your system starts, it checks to ensure that it can access all of the disk units that are
configured. If it cannot access one or more disk units, you are shown at IPL
The Disk Configuration Error Report display. From the display you can choose option 5 Display
Detailed Report.
Option Error
Missing disk units in the configuration
Following a temporary power outage you might see the display because power has been restored
to the processor but not to the peripheral devices. Wait to respond to the display until power is
restored to all the disk units. The system's ability to access all the disk units when the IBM Power
System with IBM i is starting, particularly if you have the continuously powered main store feature,
is important for a successful recovery. If disk units are not available, the system might not be able to
recover changed pages of memory. This can lengthen the time it takes to perform the IPL.
This screen might also be presented:
• After abnormal termination, if the IBM Power System with IBM i is unable to activate all the
DASD on the re-IPL.

© Copyright IBM Corp. 1995, 2017 10-94


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
• During any IBM Power System with IBM i IPL that has a similar problem, even if normal system
shutdown had taken the system down last.
If your system encounters a serious software problem, you are shown the Main Storage Dump
Manager Occurred display.
Follow the instructions for your service provider in responding to this display. In most cases, you
should make a copy of the main storage dump, either to tape media or to auxiliary storage (disk), to
assist with diagnosing the problem.
When you have solved whatever problem caused your system to stop, you must start it again. In
some cases, you start the initial program load (IPL) yourself. When you start your system again
after it ends abnormally, the system tries to put things back in order. It closes files that were in use,
rebuilds access paths that were open, and verifies file constraints. This process can take a long
time.
If you want the system to determine when to rebuild and verify, perform a normal (automatic) IPL to
restart your system. If you want to view and change the schedules for rebuilding access paths and
verifying referential constraints, follow the steps in the Backup and Recovery manual.

© Copyright IBM Corp. 1995, 2017 10-95


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

(GLW5HEXLOGRI$FFHVV3DWKV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-68. Edit Rebuild of Access Paths

The Edit Rebuild of Access Paths display shows the names of the file members that have
immediate or delayed maintenance access paths that are not valid
The display allows you to rebuild the access path for a given member of the file. The access path
for a file member is marked as not valid when the system ends abnormally and the file member is in
use.
Files with journaled access paths and files with rebuild maintenance of the access path are not
shown on the Edit Rebuild Access Path display.
When a sequence value is selected and the Enter key is pressed, the status field is updated to
show the current rebuild condition of the access path.
The following sequence values can be selected:
• 1-99=Rebuild sequence
▪ Rebuild during IPL (number less than IPL Threshold) If the sequence value is a number less
than or equal to the
▪ IPL threshold value, the access path is rebuilt during the IPL. This recovery option ensures
that the file's access path is rebuilt before the job uses the file. Note that rebuilding access
paths during the IPL causes the IPL to run longer.

© Copyright IBM Corp. 1995, 2017 10-96


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty
▪ Rebuild after IPL (number greater than IPL Threshold) If the sequence value is a number
greater than the IPL threshold value, the access path is rebuilt after the IPL is completed.
Jobs cannot use a file whose access path is rebuilt after the IPL until the rebuilding of the
access path for the file is complete. However, jobs not using a file whose access path is
rebuilt after the IPL can begin running immediately after the IPL is complete.
• *OPN=Rebuild at open
▪ The access path is rebuilt when the file is next opened. If the access path has unique keys,
rebuilding the access path at open time prevents some applications from adding and
updating records to the file until the rebuild of the access path is complete.
• *HLD=Hold the rebuild
▪ The access path is rebuilt when the sequence value is changed to 1-99 or *OPN.
Sequence
The sequence in which access paths are rebuilt is determined by the values assigned to them. The
possible values include: whole numbers ranging from 1 through 99, *OPN, and *HLD. One (1)
represents the highest priority path and is rebuilt first. Whether paths with values 1 - 99 are rebuilt
before or after the IPL is determined by the value specified on the THRESHOLD parameter. *OPN
designates a value of 100, which means the access path is rebuilt the next time the file is opened,
and *HLD designates a value of 200, which means the access path is not rebuilt until the value has
been changed to *OPN or to a number ranging from 1 through 99.

© Copyright IBM Corp. 1995, 2017 10-97


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

(GLW&KHFN3HQGLQJ&RQVWUDLQWV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-69. Edit Check Pending Constraints

You can define required attributes for physical files on the system. These are referred to as
referential constraints or simply constraints. When you perform an IPL after the system ends
abnormally or when you restore database files, the system checks the validity of file constraints.
Refer to the DB2 UDB for IBM i Database Programming document for more information about using
referential constraints.
If database constraints are marked for verification, you are shown the above display.
The Edit Check Pending Constraints display shows a list of constraints in check pending. The
display includes the status, constraint name, file name, library name, the estimated time to verify
the constraint, the current elapsed time since verification started and constraint type.

© Copyright IBM Corp. 1995, 2017 10-98


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH7KHWHUPVGLVNSRRODQG,$63DUHWHUPVWKDWDUHQRW
LQWHUFKDQJHDEOH

 7KHPD[LPXPQXPEHURIEDVLF$63V\RXFDQFUHDWHLV EODQN DQG


WKHPD[LPXPQXPEHURI,$63V\RXFDQFUHDWHLV EODQN 
D DQG
E DQG
F DQG
G DQG
H 7KHQXPEHULVWKHVDPHIRUERWK

 %ODQN LVDKDUGZDUHIXQFWLRQWKDWSURWHFWVGDWDIURPEHLQJORVW
EHFDXVHRIRQHGLVNXQLWIDLOXUHRUGDPDJHWRWKHGLVNGULYH
D 0LUURULQJ
E 5$,'
F 5$,'
G ,$63V

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-70. Review questions (1 of 3)

© Copyright IBM Corp. 1995, 2017 10-99


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH 7KHWHUPVGLVNSRRODQG,$63DUHWHUPVWKDWDUHQRW
LQWHUFKDQJHDEOH
7KHDQVZHULVIDOVH

 7KHPD[LPXPQXPEHURIEDVLF$63V\RXFDQFUHDWHLVDQGWKH
PD[LPXPQXPEHURI,$63V\RXFDQFUHDWHLV
D DQG
E DQG
F DQG
G DQG
H 7KHQXPEHULVWKHVDPHIRUERWK
7KHDQVZHUVDUHDQG

 5$,' LVDKDUGZDUHIXQFWLRQWKDWSURWHFWVGDWDIURPEHLQJORVW
EHFDXVHRIRQHGLVNXQLWIDLOXUHRUGDPDJHWRWKHGLVNGULYH
D 0LUURULQJ
E 5$,'
F 5$,'
G ,$63V
7KHDQVZHULV5$,'

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-71. Review answers (1 of 3)

© Copyright IBM Corp. 1995, 2017 10-100


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZTXHVWLRQV RI
 %ODQN LVDW\SHRIGLVNSURWHFWLRQWKDWLVLPSOHPHQWHG
WKURXJKVRIWZDUH
D 5$,'
E 5$,'
F 0LUURULQJ
G $63V

 0LUURULQJFDQEHLPSOHPHQWHGDWZKLFKRIWKHIROORZLQJ
OHYHOV"
D 'LVN
E ,2$
F ([SDQVLRQXQLW
G %XV
H $OORIWKHDERYH

 7UXHRUIDOVH7KH26VHFXULW\RIILFHUXVHU,'DQGSDVVZRUG
DUHGLIIHUHQWIURPWKHVHUYLFHWRROVVHFXULW\RIILFHUXVHU,'
DQGSDVVZRUG
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-72. Review questions (2 of 3)

© Copyright IBM Corp. 1995, 2017 10-101


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZDQVZHUV RI
 0LUURULQJ LVDW\SHRIGLVNSURWHFWLRQWKDWLVLPSOHPHQWHGWKURXJK
VRIWZDUH
D5$,'
E5$,'
F0LUURULQJ
G$63V
7KHDQVZHULVPLUURULQJ

 0LUURULQJFDQEHLPSOHPHQWHGDWZKLFKRIWKHIROORZLQJOHYHOV"
D'LVN
E,2$
F([SDQVLRQXQLW
G%XV
H$OORIWKHDERYH
7KHDQVZHULVDOORIWKHDERYH

 7UXH RUIDOVH7KH26VHFXULW\RIILFHUXVHU,'DQGSDVVZRUGDUH
GLIIHUHQWIURPWKHVHUYLFHWRROVVHFXULW\RIILFHUXVHU,'DQG
SDVVZRUG
7KHDQVZHULVWUXH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-73. Review answers (2 of 3)

© Copyright IBM Corp. 1995, 2017 10-102


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZTXHVWLRQV RI
 :KLFKRIWKHIROORZLQJLVQRWXVXDOO\WKHFDXVHRIDQ
DEQRUPDOV\VWHPHQG"
D 3RZHUIDLOXUH
E 'LVNIDLOXUH
F 8VHUHUURU
G )DLOXUHRIFULWLFDO,%0LSURJUDP

 7UXHRUIDOVH'XULQJDQRUPDO,3/DIWHUWKHUHKDVEHHQDQ
DEQRUPDOHQGWKHV\VWHPGHWHUPLQHVZKLFKDFFHVVSDWKV
QHHGWREHUHEXLOW

 7UXHRUIDOVH'XULQJDQDWWHQGHG,3/DIWHUWKHUHKDVEHHQ
DQDEQRUPDOHQGWKHXVHULVQRWSUHVHQWHGZLWKDQ\RSWLRQV
IRUUHEXLOGLQJDFFHVVSDWKV

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-74. Review questions (3 of 3)

© Copyright IBM Corp. 1995, 2017 10-103


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

5HYLHZDQVZHUV RI
 :KLFKRIWKHIROORZLQJLVQRWXVXDOO\WKHFDXVHRIDQ
DEQRUPDOV\VWHPHQG"
D3RZHUIDLOXUH
E'LVNIDLOXUH
F8VHUHUURU
G)DLOXUHRIFULWLFDO,%0LSURJUDP
7KHDQVZHULVXVHUHUURU

 7UXH RUIDOVH'XULQJDQRUPDO,3/DIWHUWKHUHKDVEHHQDQ
DEQRUPDOHQGWKHV\VWHPGHWHUPLQHVZKLFKDFFHVVSDWKV
QHHGWREHUHEXLOW
7KHDQVZHULVWUXH

7UXHRUIDOVH'XULQJDQDWWHQGHG,3/DIWHUWKHUHKDVEHHQ
DQDEQRUPDOHQGWKHXVHULVQRWSUHVHQWHGZLWKDQ\RSWLRQV
IRUUHEXLOGLQJDFFHVVSDWKV
7KHDQVZHULVIDOVH
'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-75. Review answers (3 of 3)

© Copyright IBM Corp. 1995, 2017 10-104


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 10. Disk management

Uempty

8QLWVXPPDU\
‡ ([SODLQWKHFRQFHSWRIGLVNSRROV
‡ /LVWWKHGLIIHUHQWW\SHVRIDX[LOLDU\VWRUDJHSRROV $63V WKDWFDQEH
FRQILJXUHG
‡ ([SODLQVRPHRIWKHEHQHILWVRILPSOHPHQWLQJWKHGLIIHUHQWW\SHVRI
$63V
‡ ([SODLQWKHFRQFHSWVRIGHYLFHSDULW\DQGPLUURUHGSURWHFWLRQ
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQ5$,'5$,'DQG5$,'SURWHFWLRQ
‡ 'HVFULEHWKHGLIIHUHQWOHYHOVDWZKLFKPLUURUHGSURWHFWLRQFDQEH
LPSOHPHQWHG
‡ 'HVFULEHKRZWRILQGWKHFRUUHFWSURFHGXUHIRUGLVNFRQILJXUDWLRQDQG
UHFRYHU\
‡ 'HVFULEHWKHGLVNXQLWIXQFWLRQVRI,%01DYLJDWRUIRUL
‡ 'HVFULEHWKHHIIHFWVRIDQDEQRUPDOV\VWHPHQGDQGWKHUHFRYHU\
SURFHGXUH

'LVNPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 10-76. Unit summary

© Copyright IBM Corp. 1995, 2017 10-105


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

Unit 11. Backup and recovery strategy


using save/restore
Estimated time
02:00

Overview
The save and restore procedures are the foundation for a backup and recovery plan. A knowledge
of how to save and restore the part of the system that is in error is critical to a disaster recovery
plan.
This unit does not discuss other facilities available for ensuring system integrity. These are
discussed in another unit.

How you will check your progress


• Review questions
• Exercises

© Copyright IBM Corp. 1995, 2017 11-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

8QLWREMHFWLYHV
‡ /LVWWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXURQWKHV\VWHP
‡ /LVWWKHGLIIHUHQWPHGLDW\SHVWKDWFDQEHXVHGIRUEDFNXSRI\RXUGDWD
‡ 3HUIRUPWKHVWHSVUHTXLUHGWRVHWXSDQGXVHDYLUWXDOWDSHGULYH
‡ ([SODLQZKLFKFRPPDQGVDUHXVHGWRVDYHZKLFKW\SHVRIGDWD
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQWKHSAVSYS DQGSAVSYSINF FRPPDQG
‡ ,GHQWLI\WKHSURFHGXUHVXVHGWRVDYHDQGUHVWRUHGLIIHUHQWW\SHVRI
V\VWHPLQIRUPDWLRQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 11-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
11.1. Topic 1: Overview of the save/restore
capabilities

© Copyright IBM Corp. 1995, 2017 11-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7RSLF2YHUYLHZRIWKH
VDYHUHVWRUHFDSDELOLWLHV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-2. Topic 1: Overview of the save/restore capabilities

© Copyright IBM Corp. 1995, 2017 11-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

+RZLPSRUWDQWLVVDYHUHVWRUH"
,WLVWKHIRXQGDWLRQRQZKLFK\RXU
GLVDVWHUUHFRYHU\SODQLVEXLOW

Your company

Disaster Disaster
recovery recovery
plan plan

Save/restore

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-3. How important is save/restore?

The method that you use to back up your server depends upon your backup strategy. If you do not
have a strategy, review the information in Planning a Backup and Recovery Strategy. After
reviewing the information, determine how you should save your data.
The save and restore commands are the foundation for a backup and recovery plan. A knowledge
of how to save the system in order to be able to restore that part of the system that is in error is
critical to a disaster recovery plan.
If it would never be necessary to restore, there would be no need to make a save!
Think of the data on your computer as company assets, the same as inventory and fixed assets. It
has value to the company and it would be difficult to do business if it were lost. Save and restore is
the foundation upon which all recovery plans are built.

© Copyright IBM Corp. 1995, 2017 11-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

8VHVIRUWKHVDYHDQGUHVWRUHFDSDELOLWLHV
‡ 5HFRYHUIURPSURJUDPRUV\VWHPIDLOXUH

‡ 6DYHV\VWHP

‡ ([FKDQJHLQIRUPDWLRQEHWZHHQV\VWHPV

‡ 6WRUHLQIUHTXHQWO\XVHGREMHFWVRIIOLQH

‡ 1RWH 1RUPDOO\REMHFWVDUHIUHTXHQWO\VDYHGDQGLQIUHTXHQWO\UHVWRUHG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-4. Uses for the save and restore capabilities

The Save commands (SAVxxx) allow for copying data from the system to media, virtual media, or a
save file, so that it can then be restored if needed. These commands can also be used for
exchange of information between like systems and to archive information no longer needed daily.

© Copyright IBM Corp. 1995, 2017 11-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

)DLOXUHVWKDWFDQRFFXU
‡ 6L[JHQHUDOW\SHV
ƒ 'LVNIDLOXUH
ƒ 6\VWHPIDLOXUH
ƒ 3RZHUIDLOXUH
ƒ 3URJUDPIDLOXUH
ƒ +XPDQHUURU
ƒ &RPSOHWHV\VWHPORVV

‡ 2EMHFWLYH*HW\RXUDSSOLFDWLRQVEDFNRQOLQHDVVRRQDVSRVVLEOH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-5. Failures that can occur

© Copyright IBM Corp. 1995, 2017 11-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
11.2. Topic 2: Media used to back up your
system

© Copyright IBM Corp. 1995, 2017 11-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7RSLF0HGLDXVHGWREDFN
XS\RXUV\VWHP

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-6. Topic 2: Media used to back up your system

© Copyright IBM Corp. 1995, 2017 11-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

0DQDJLQJWDSHV
‡ 7DSHPDQDJHPHQW
ƒ 5RWDWLQJWDSHV
ƒ 1DPLQJDQGODEHOLQJWDSHV
ƒ 3UHSDULQJWDSHVDQGWDSHGULYHV
ƒ 9HULI\LQJWDSHV
ƒ 6WRULQJWDSHV
ƒ 0RQLWRULQJWDSHVIRUHUURUV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-7. Managing tapes

Since tapes are the prevalent method of saving and recovering your system data, you should
institute a tape management process because managing your tapes is an important part of your
save operation. If you cannot easily locate tapes that are correct and undamaged when you need to
do a recovery, the time spent creating the save tape was wasted.
Make decisions about your procedures for managing tapes, write down those decisions, and
monitor the procedures regularly.
Tape management requires the following:
Rotating tapes: An important part of a good save procedure is to have more than one set of tapes.
When you perform a recovery, you might need to go back to an old or previous set of saved tapes.
If you discover that your most recent set of backup tapes is damaged, or if you discover that a
programming error damaged the data on the most recent backup tapes, you might need to use a
previous version or a previous set of the backup tapes.
Naming and labeling tapes: As a standard practice all tapes should always be labeled to assist
the system operator in loading the correct tape to perform a save. Use easy-to-identify labels to
define what information is contained on the tape and which tape set it is part of.

© Copyright IBM Corp. 1995, 2017 11-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Preparing tapes and tape drives: Tape drives need regular cleaning as the heads collect dust that
can cause data errors. Also, before you can use a tape it must be initialized with the Initialize Tape
(INZTAP) command.
Verifying that the correct tapes are loaded: This can be done manually by the system operator
or by the system with the VOL parameter (on the save or restore commands) which specifies a list
of volume identifiers that can be used to perform the requested operation. The system ensures that
the tapes that were loaded by the operator are the correct volumes and in the order specified on the
command. If an error occurs, a message is sent to the operator requesting the correct tape
volumes. At that point, the operator can either load the tape called for, or select the option to
override the request and use the tape currently loaded.
Storing tapes: Tapes should be stored in a safe but accessible location away from where the
system is located. Off-site storage is highly recommended to avoid problems due to site loss.
Monitoring for tape errors: You can determine whether a tape is wearing out by printing the error
log. Use the Print Error Log (PRTERRLOG) command and specify TYPE(*VOLSTAT). If you suspect
that a tape has problems and you want to check the integrity of saved information, use the Display
Tape (DSPTAP) or the Duplicate Tape (DUPTAP) command. These commands read the entire tape
and detect objects on the tape that cannot be read.

© Copyright IBM Corp. 1995, 2017 11-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7DSHDQGWDSHOLEUDU\V\VWHP
‡ 9DULRXVVL]HVDQGFDSDFLWLHVDUHDYDLODEOH
ƒ 'DWDFRPSUHVVLRQFRPSDFWLRQ
‡ 6XSSRUWIRUHQFU\SWLRQ
‡ 6XSSRUWIRUSDUDOOHOWDSHRSHUDWLRQVLV
ƒ $YDLODEOHRQV\VWHPV
ƒ 6XSSRUWHGDVDSDUWRIVWDQGDUGRSHUDWLRQVLQ%DFNXS5HFRYHU\DQG0HGLD
6HUYLFHV %506
ƒ $OORZVXVHRIPRUHWKDQRQHPHGLDGHYLFHVLPXOWDQHRXVO\
‡ )ROORZLQJFDWHJRULHVRIKDUGZDUHDUHDYDLODEOH
ƒ 7DSHOLEUDULHV
í &RPELQDWLRQRIKDUGZDUHDQGVRIWZDUH
í $OORZVIRUVWRULQJFDWDORJLQJDQGORDGLQJWDSHV
í 6XSSRUWHGE\%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV %506
ƒ 9LUWXDO7DSH/LEUDULHV 97/76
í %DVHGRQWKHH[WHUQDOVWRUDJH
í %DVHGRQFORXGUHVRXUFHV
ƒ 6LQJOHWDSHGHYLFHV
ƒ 86%VWRUDJH
í 5';86%

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-8. Tape and tape library system

The system offers many different types of tape drives to meet various requirements for cost,
capacity, and performance. In most cases, you can attach enough tape drives with sufficient
capacity to save your entire system without operator intervention.
For more information, refer to IBM i Knowledge Center website
[Link]
Single tape devices
This can be excellent for smaller companies that might not have much data to back up or to
retrieve.
Tape Libraries
Tape libraries provide automation solutions to hold multiple cartridges and perform unattended
backups.
Tape libraries can help you perform unattended save and restore operations, archival and retrieval
operations, spool archiving, and other tape-related tasks. Tape libraries are often used with some
form of automation software. They are able to support multiple systems across different platforms
and large quantities of cartridges. In these environments, a media management application often
maintains the cartridge inventory and handles most of the tape library tasks. However, you can also

© Copyright IBM Corp. 1995, 2017 11-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
use tape libraries without a media management application. Tape libraries are supported by Backup
Recovery and Media Services (BRMS).
RDX
The new IBM RDX USB 3.0 disk backup solution is designed to reliably and cost-effectively help
protect your business's valuable assets. It uses a rugged removable disk cartridge and docking
station to provide an easy-to-use, highly secure, fast, and portable answer to your data protection
concerns.
IBM RDX features high-capacity shock-resistant 320 GB, 500 GB, and 1 TB cartridges, making
your storage options extremely flexible. The RDX USB 3.0 docking stations are offered in external
stand-alone and internal 5.25-inch half height units to seamlessly integrate into your System x or
BladeCenter® environment. The USB interface ensures a simple installation while providing high
performance, with sustained transfer rates of up to 96 MBps.
VTL
A virtual tape library (VTL) is a data storage virtualization technology used typically for backup
and recovery purposes.
IBM TS7650G ProtecTIER Deduplication Gateway is designed to meet the disk-based data
protection needs of the enterprise data center while enabling significant infrastructure cost
reductions. The solution offers industry-leading inline deduplication performance and scalability up
to 1 petabyte (PB) of physical storage capacity per system, and can provide up to 25 PB or more
backup storage capacity. Combined with IBM or third-party storage, TS7650G ProtecTIER
Deduplication Gateway provides a powerful disk-based repository to improve the performance,
retention, and availability of backup and archive data in a small footprint for energy and cost
efficiency.
ProtecTier Deduplicator Gateway allows you to avoid access conflict to the tape library or drives
when you have an installation with many partitions and a small number of devices.

© Copyright IBM Corp. 1995, 2017 11-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

0DQDJHWDSHVDQGWDSHOLEUDULHVLQWHUIDFH

:5.0/%676

:5.&)*676 '(9 7$3

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-9. Manage tapes and tape libraries 5250 interface

You can manage stand-alone tape drives, virtual tape drives, and tape libraries with 5250 interface
using the following commands:
•WRKMLBSTS
•WRKCFGSTS *DEV TAP*
•WRKDEVD TAP*
Also, you can use the Menu Tape (GO TAPE). Here are the following options for working with tapes
available:
1. Display tape information
2. Initialize a tape
3. Print contents of a tape
4. Save
5. Restore
6. Work with tape device status
7. Verify tape

© Copyright IBM Corp. 1995, 2017 11-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Tape library devices are configured with tape library device descriptions for the tape library. There
are also separate tape device descriptions for the tape resources. These tape device descriptions
are the devices that are used for stand-alone operation. To use the tape resources in stand-alone
mode, the resource must be available to the tape device description. This is done by either
deallocating the tape resource from the tape library or varying off the tape library device. Once the
tape resource is available, you can vary on the tape device description, and issue commands to this
device. The tape resource on the WRKMLBSTS screen shows a status of UNAVAILABLE / VARIED
OFF. No tape library functions operate for this tape resource. The tape resource needs to have
cartridges mounted manually, by either a device mode or by device operator pane commands.

© Copyright IBM Corp. 1995, 2017 11-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%01DYLJDWRUIRUL0DQDJHWDSHVDQGWDSHOLEUDULHV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-10. IBM Navigator for i: Manage tapes and tape libraries

You can manage stand-alone tape drives, virtual tape drives, and tape libraries with IBM i
Navigator.
1. Log on to the IBM Navigator for i [Link] address or system name>>:2001 with
your user name and password.
2. On the left pane, expand Configuration and Service.
3. Then expand All Tasks and Tape Devices.
4. Click Tape libraries.
You can also use different options like working with Standalone tape devices or work with image
catalogs that can be used to save / restore as a device.

© Copyright IBM Corp. 1995, 2017 11-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,1=7$3,QLWLDOL]H7DSH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-11. INZTAP: Initialize Tape

The Initialize Tape (INZTAP) command is used to initialize magnetic tapes for use on the system.
This command is used to initialize a tape with a standard volume label for standard label magnetic
tape processing, or to initialize a tape with no labels for unlabeled magnetic tape processing.
The only required parameter is the DEV parameter.
Specifies the name of the device in which the volume to be initialized is placed. Specify the name of
the tape or media library device.
For 5250 interface run INZTAP command and put required parameters.
For IBM Navigator for i do:
1. Log on to the IBM Navigator for i [Link] address or system name>>:2001 with
your user name and password.
2. On the left pane, expand Configuration and Service.
3. Then expand All Tasks and Tape Devices.
4. Click Standalone devices.
5. On main pane right-click selected tape drive and from the pop-up menu select Format.

© Copyright IBM Corp. 1995, 2017 11-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
6. On format dialog you find two tabs General and Options where you can provide required
parameters.

© Copyright IBM Corp. 1995, 2017 11-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

9LUWXDOWDSHVXSSRUW
‡ .H\DGYDQWDJHV
ƒ 6XSSRUWHGRQDOOVDYHUHVWRUHFRPPDQGVYLUWXDO,2DQG$3,V ,QFOXGHG
6DYH(QWLUHRI6\VWHP
ƒ &DQEHIDVWHUWKDQVDYLQJGLUHFWO\WRWDSH
ƒ (OLPLQDWHVWKHIROORZLQJVDYHILOHOLPLWDWLRQV
ƒ (OLPLQDWHVPHGLDHUURUOLPLWDWLRQV
ƒ 2QFHFKHFNSRLQWLVUHDFKHGWKHVDYHRSHUDWLRQFDQEHUHVWDUWHG
ƒ 'XSOLFDWHVDYHVWRPHGLD DUPTAP RUDUPMEDBRM
ƒ 2QVLWHDQGRIIVLWHVWRUDJH
ƒ %DFNXSLQFORXG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-12. Virtual tape support

It is important to understand differences between Virtual Tape (virtual based on image catalog) and
Virtual Tape Library (devices with physical disks that offer you create tape libraries and virtual
cartridges and present it to the system using the Fibre Channel. All of these advantages presented
on the visual are available in both solution VT and VTL. VTL can offer deduplication that is not
available in image Virtual Tape.
Now we discuss Virtual Tapes based on image catalogs because in a small installation it could be
an immediate solution. This is easy to implement and cheap but not recommended for production
for two reasons.
1. Backup data still on the same disks as production unit is not duplicated to physical tapes
2. Because these same disks are used during save or duplication, it is possible some performance
issues
Virtual tape support provides “backup that are not available on simple SAVEFILE. You can backup
more than one library and almost no size limitation (you are limited by storage capacity) and save
whole system.
Virtual tape devices use virtual tape volumes that are created on a server's disk units. This allows
IBM i SAVxxx commands to be used to back up data to virtual tapes stored on disk rather than on
tapes.

© Copyright IBM Corp. 1995, 2017 11-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Key advantages
• Supported on all save/restore commands, virtual I/O, and APIs (included Save Entire of
System)
• Can be faster than saving directly to tape
• Similar performance to save files
• Best performance in separate ASP
• Eliminates the following save file limitations:
• One library per save file
• SAVSYS not supported on save file
• Parallel saves not supported on save file
• 2 TB size limitation on save file
• Eliminates media error limitations:
• Saves ending due to tape device or media errors
• Save-while-active checkpoint restriction
• Once checkpoint reached the save operation can be restarted
• Duplicate saves to media (DUPTAP or DUPMEDBRM)
• Save when tape devices are available
• At your convenience
• Onsite and off-site storage
• Keep virtual volumes on systems as needed
• Keep duplicated volumes off-site
• Backup in cloud

© Copyright IBM Corp. 1995, 2017 11-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

9LUWXDOWDSHLPSOHPHQWDWLRQ

CRTIMGCLG ADDIMGCLGE

 

LODIMGCLG

CRTDEVTAP

WRKCFGSTS


%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-13. Virtual tape implementation

The objective is to save to virtual tapes that are really storage areas on the IBM i partition. No
physical tape devices need to be attached during the backup (or restore). The numbers in this
visual represent the steps for implementing IBM i virtual tape support:
1. Create a tape device description with a “virtual attribute”.
2. Vary on your virtual tape device (use the WRKCFGSTS command, option 8 - Work with status,
then option 1- Vary on) and ensure that it is varied on before continuing.
3. Create a tape image catalog.
4. Add image catalog entries (up to 256) to the image catalog. Entries represent a virtual tape
volume
5. The Load / Unload Image Catalog (LODIMGCLG) command is used to associate an image
catalog and its images to a virtual device.
After this, you can save to the virtual tape or restore from it. You can also copy the virtual tape
image catalog entry data to an actual tape device or “media,” for example, sending it to a second
system. If the catalog is in an Independent Auxiliary Storage Pool (IASP), the IASP contents can be
switched to another system or mirrored to a second IASP on another system.

© Copyright IBM Corp. 1995, 2017 11-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
If you implemented 5733ICC IBM Cloud Storage Solutions for i, the backup can be sent to the
cloud.

© Copyright IBM Corp. 1995, 2017 11-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&UHDWHDYLUWXDOWDSHGHYLFHGHVFULSWLRQ RI
‡ &UHDWHZLWKWKHCRTDEVTAP FRPPDQG
‡ &DQFKDQJHH[LVWLQJGHYLFHGHVFULSWLRQWREHFRPHDYLUWXDOWDSHGHYLFH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-14. Create a virtual tape device description (1 of 2)

© Copyright IBM Corp. 1995, 2017 11-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&UHDWHDYLUWXDOWDSHGHYLFHGHVFULSWLRQ RI
‡ &UHDWHZLWK,%01DYLJDWRUIRUL

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-15. Create a virtual tape device description (2 of 2)

To create virtual tape device using IBM Navigator for i do following:


1. Logon to system using web browser [Link] or system name>:2001 using
your user name and password.
2. On the left pane, expand Configuration and Service and then expand Tape Devices.
3. On the left pane, click Stand-Alone Devices.
4. On the main pane click Actions menu and from pop-up menu click Create Virtual Device.

© Copyright IBM Corp. 1995, 2017 11-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&UHDWHWKHLPDJHFDWDORJIRUYLUWXDOWDSHVXSSRUW
• CRTIMGCLG FRPPDQG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-16. Create the image catalog for virtual tape support

The Create Image Catalog (CRTIMGCLG) command is used to create an image catalog object
(*IMGCLG) in the library QUSRSYS and associate the image catalog with a target directory.
This command also creates an image catalog object QIMGCLG of type stream file (*STMF) in the
directory specified on the Directory (DIR) parameter. This catalog object is used when
IMPORT(*YES) is specified on the Create Image Catalog (CRTIMGCLG) or Change Image Catalog
(CHGIMGCLG) commands to recover your image catalog from the image catalog directory.

© Copyright IBM Corp. 1995, 2017 11-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&UHDWHLPDJHFDWDORJWKURXJK,%01DYLJDWRUIRUL

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-17. Create image catalog through IBM Navigator for i

To create virtual tape device using IBM Navigator for i do following:


1. Logon to system using web browser [Link] or system name>:2001 using
your user name and password.
2. On the left pane, expand Configuration and Service and then expand Tape Devices.
3. On the left pane click Tape Image Catalogs.
4. On the main pane click Actions menu and from pop-up menu click Create Image Catalog.
5. On the Create Catalog dialog you have two tab General and Options provide required
parameters.

© Copyright IBM Corp. 1995, 2017 11-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

:RUNZLWK,PDJH&DWDORJ:5.,0*&/*

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-18. Work with Image Catalog WRKIMGCLG

The WRKIMGCLG command allows you to work with created image catalog. You can use option 12
Work with entries to work with entries that are image virtual tapes volumes.
If you want to add new one, you can choose option 1 Add alternative is running on command line
ADDIMGCLGE command that is described on the next screen.

© Copyright IBM Corp. 1995, 2017 11-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&UHDWHQHZYLUWXDOYROXPH$'',0*&/*(FRPPDQG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-19. Create new virtual volume: ADDIMGCLGE command

The Add Image Catalog Entry (ADDIMGCLGE) command is used to create a virtual image in the
image catalog directory (as specified by the Directory (DIR) parameter on the CRTIMGCLG
command). If the image is added successfully, the image is loaded and the image catalog
(*IMGCLG) in library QUSRSYS is updated.
The following parameters are only valid for tape image catalogs:
•ALCSTG
•VOLNAM
•VOLTYP
•DENSITY
•NEWOWNID
•CODE
When you create a new volume for the 'From image file (FROMFILE) parameter', you must type
*NEW.
Tape volume name (VOLNAM) parameter is the volume name that can be use by system or BRMS
during backup.

© Copyright IBM Corp. 1995, 2017 11-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Tape density (DENSITY): The format of the volume is *VRT256K. It is used to write data to a virtual
volume using a maximum data block size of 256 KB. Volumes written using this format can only be
duplicated to tape devices that support a maximum block size of 256 KB or greater.

© Copyright IBM Corp. 1995, 2017 11-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%01DYLJDWRUIRUL&UHDWHQHZYLUWXDOYROXPH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-20. IBM Navigator for i: Create new virtual volume

To create virtual tape volume using IBM Navigator for i do following:


1. Logon to system using web browser [Link] or system name>:2001 using
your user name and password.
2. On the left pane, expand Configuration and Service and then expand Tape Devices.
3. On the left pane click Tape Image Catalogs.
4. On the main pane, right-click selected image catalog and from pop-up menu select Add
Volume.
5. On the Add volume dialog, you have two tabs General and Options provide required
parameters.

Note

The “From tape image file” parameter must be set to New image when you create a new image.

© Copyright IBM Corp. 1995, 2017 11-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

/RDGLPDJHFDWDORJ/2',0*&/*FRPPDQG

:5.,0*&/*RSW/RDG

LODIMGCLG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-21. Load image catalog: LODIMGCLG command

To prepare your virtual tape library to work, you must load image catalog. To load, you must use
created earlier virtual tape device the device must be VARY ON before load.
You have two options to load the image catalog.
1. WRKIMGCLG command and option 8 Load
2. LOADIMGCLG command
In the load image catalog command 'LOADIMGCLG' you find the 'Library mode' parameter that is
irrelevant for a tape library.
The status of the image catalog changes based on the value specified for the Option (OPTION)
parameter as follows:
• *LOAD: This causes the status of the image catalog to change to ready. All image catalog
entries that are in mounted or loaded status are loaded in the specified virtual device. The allow
save attribute is set to not permit the save for all image catalog files.
• *UNLOAD: This causes the status of the image catalog to change to not ready. All image
catalog entries are removed from the specified virtual device. The allow save attribute is set to
not permit the save for all image catalog entries.

© Copyright IBM Corp. 1995, 2017 11-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Only one image catalog can be associated with a virtual device. If the virtual device already has an
image catalog associated with it, you can use OPTION(*UNLOAD) to unload the current image
catalog.

© Copyright IBM Corp. 1995, 2017 11-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

2SWLFDOVWRUDJH
‡ 2SWLFDOGHYLFH
ƒ '9'520GULYH
‡ 9LUWXDORSWLFDOVWRUDJH
ƒ $ELOLW\WRGXSOLFDWHWRSK\VLFDOPHGLD
ƒ 6DYHFXPXODWLYH37)UHFRUG
ƒ $ELOLW\WRLQVWDOOQHZV\VWHP
ƒ 6DYHWRYLUWXDORSWLFDO
í &UHDWHDYLUWXDORSWLFDOGHYLFH
í 9DU\RQWKHGHYLFH
í &UHDWHDQLPDJHFDWDORJ
í $GGDQHZLPDJHFDWDORJHQWU\
í /RDGWKHLPDJHFDWDORJ
í ,QLWLDOL]HWKHQHZYROXPH
í 5XQWKHsave FRPPDQG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-22. Optical storage

Virtual optical storage


When you use virtual optical storage, you create virtual images, CD, or DVD images, that exist on
your server disk units. You can use virtual images to perform various tasks:
• Install software such as Licensed Internal Code, program temporary fixes (PTFs), IBM i, and
licensed programs
• Distribute software
• Perform backups
• Create distribution media for central site
• Create save licensed programs media
Ability to duplicate to physical media
When a save is complete to virtual optical, you can transfer it to physical media at any time. You
also have the capability to send the stream files from the virtual optical save to another system
using FTP. If you have multiple servers, your strategy could be to save each system to virtual
optical and then FTP the stream files to a single server where the save to physical media could take
place. You can save the virtual images to tape in optical format, or you can use the Duplicate
Optical (DUPOPT) command to save the image to optical media.

© Copyright IBM Corp. 1995, 2017 11-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Save cumulative PTF record
You can install your fixes from an image catalog. To maintain a complete record of all of the fixes
that you apply, you can save these virtual PTF images to media. Then, in a recovery situation, you
can restore all of the cumulative PTF images and automatically install them from the image catalog.
Ability to install new system
You can use image catalogs to install new system for this you can use host client relation.

© Copyright IBM Corp. 1995, 2017 11-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%0L,QVWDOOLQJ3DUWLWLRQIURPDQ,PDJH&DWDORJ RI
 &UHDWHDQLPDJHFDWDORJ
ƒ CRTIMGCLG IMGCLG(INSTALL) DIR('/home/install')
 $GGPHGLDLPDJHVWRWKHFDWDORJ
ƒ $GGHDFKRIWKH,%0LLQVWDOODWLRQ'9'&'VWRWKHLPDJHFDWDORJ
ƒ ADDIMGCLGE IMGCLG(INSTALL) FROMDEV(OPT01)
TOFILE(ibase) ,%0L ,%0L
 &UHDWHDGHSHQGHQWLPDJHFDWDORJIRUHDFKFOLHQWSDUWLWLRQ
ƒ CRTIMGCLG IMGCLG(CP7) DIR(*refimgclg) IMPORT(*YES) +\SHUYLVRU
REFIMGCLG(INSTALL)
32:(5
 &UHDWHDQGYDU\RQDYLUWXDORSWLFDOGHYLFH % IRUHDFK
GHSHQGHQWLPDJHFDWDORJ
ƒ &UHDWHYLUWXDORSWLFDOGHYLFH % 
ƒ CRTDEVOPT DEVD(OPTVRTCP7) RSRCNAME(*VRT)
ƒ 9DU\RQYLUWXDORSWLFDOGHYLFH % 
ƒ VRYCFG CFGOBJ(OPTVRTCP7) CFGTYPE(*DEV) STATUS(*ON)
6HUYHU6XSSRUW &OLHQW6XSSRUW
 0RXQWWKHPHGLDLPDJH
ƒ 7KHPRXQWHGYLUWXDOLPDJHLVWKHDYDLODEOHYLUWXDOLPDJHWKDWFDQEH  
VHHQE\XVLQJWKH:RUNZLWK&DWDORJ(QWULHV WRKIMGCLGE RU
:RUNZLWK2SWLFDO9ROXPHV WRKOPTVOL FRPPDQG2QO\RQH
YLUWXDOLPDJHFDQEHPRXQWHGDWDWLPH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-23. IBM i: Installing Partition from an Image Catalog (1 of 3)

Step 3 is not necessary if the installation is for only one system.

© Copyright IBM Corp. 1995, 2017 11-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%0L,QVWDOOLQJ3DUWLWLRQIURPDQ,PDJH&DWDORJ RI
 /RDGWKHLPDJHFDWDORJ
ƒ /RDGLPDJHFDWDORJWR%%YLUWXDORSWLFDO
GHYLFH7KLVPXVWEHGRQHDIWHUHYHU\,3/
ƒ LODIMGCLG IMGCLG(CP7)
DEV(OPTVRTCP7)

 &UHDWH1:6' 1HWZRUN6HUYHU
'HVFULSWLRQ CRTNWSD NWSD(CP7)
RSRCNAME(CTL05) TYPE(*GUEST
*OPSYS) PWRCTL(*NO)
 9DU\RII9DU\RQWKH1:6'
ƒ 2SWLFDOGHYLFHVDUHQRWDGGHGG\QDPLFDOO\
WRWKH1:6'<RXPXVWYDU\LWRIIDQG
WKHQEDFNRQ
ƒ 1RWH$IWHUDQ,3/WKHLPDJHFDWDORJ
PXVWEHORDGHGDJDLQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-24. IBM i: Installing Partition from an Image Catalog (2 of 3)

© Copyright IBM Corp. 1995, 2017 11-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%0L,QVWDOOLQJ3DUWLWLRQIURPDQ,PDJH&DWDORJ RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-25. IBM i: Installing Partition from an Image Catalog (3 of 3)

In the command CRTNWSD NWSD(CP7) RSRCNAME(CTL05) TYPE(*GUEST *OPSYS)


PWRCTL(*NO) you should provide the resource name which is the controller name that is created
when you create vSCSI connection between host and client partitions. The Host Client relation is
required only for installation process. To create it, you must logon to HMC and do following:
a. In the navigation pane open Systems Management > Servers, and click the managed
system on which the server IBM i server partition resides.
b. Select the IBM i server partition, click the Tasks button, and choose Dynamic Logical
Partitioning > Virtual Adapters.
c. Click Actions and choose Create > SCSI Adapter.
d. Use the default VSCSI Adapter number or provide your own. Write down the VSCSI
Adapter number as you need it in a later step. In the Type of adapter field, select Server,
and click OK.
e. Create the VSCSI adapter within the partition profile for the IBM i server partition so that the
VSCSI adapter continues to exist after you restart the partition.

© Copyright IBM Corp. 1995, 2017 11-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Determine the correct VSCSI server resource name by entering the WRKHDWRSC *CMN command
on the command line of the IBM i server partition. Look at the controller resources with type 290B.
Use option 7 to display the resource details (the newly created resource from step d is at the bottom
of the page).
Look at the last digits of the location code listed as Cxx where x corresponds to the virtual adapter
number you wrote down on step 1d. Write the Resource Name (CTLxx) as it will be used to specify
the VSCSI Server Resource Name (more you can find IBM i 7.2 Technical Overview Redbooks)

© Copyright IBM Corp. 1995, 2017 11-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%0LQHWZRUNLQVWDOOLQJXSJUDGLQJPXOWLSOHV\VWHPV

,%0

'9'
(OHFWURQLF
VRIWZDUH
GLVWULEXWLRQ
6FUDWFKLQVWDOORIQHZV\VWHP
‡ ,%0L

1)66HUYHU
,QVWDOO5HVWRUH

6DYH,%0RU
&XVWRP,PDJH
6$96<66$92%- 32:(5VHUYHU
6$9/,&3*0«WR1)6'HYLFH 32:(5VHUYHU

,%0L &57'(9237 659/$1

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-26. IBM i network installing / upgrading multiple systems

If you trying to install system outside of your server, you can use for this NFS (Network File Server).
Configuration is similar like was described using NWSD.

© Copyright IBM Corp. 1995, 2017 11-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

([HUFLVH0HGLDGHYLFHVDQGYLUWXDOWDSH
‡ ,VVXHWKHFRPPDQGVWRGLVSOD\ZKDWEDFNXSGHYLFHVDUH
UHFRJQL]HGE\WKH26
‡ 3HUIRUPWKHVWHSVQHFHVVDU\WRFUHDWHDQGORDGYLUWXDOWDSHV
WREHSUHSDUHGIRUDVDYHRSHUDWLRQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-27. Exercise: Media devices and virtual tape

© Copyright IBM Corp. 1995, 2017 11-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
11.3. Topic 3: Save operations

© Copyright IBM Corp. 1995, 2017 11-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7RSLF6DYHRSHUDWLRQV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-28. Topic 3: Save operations

© Copyright IBM Corp. 1995, 2017 11-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9FRPPDQGVDQGPHQXRSWLRQV
2SWLRQVIURP &RPPDQGV
6DYHPHQX

/LFHQVHG,QWHUQDO&RGH
 L26REMHFWVLVQSYS SAVSYS

8VHUSURILOHV SAVSECDTA

 3ULYDWHDXWKRULWLHV
SAVCFG
&RQILJXUDWLRQREMHFWV
SAV
,%0VXSSOLHGGLUHFWRULHV

L26RSWLRQDOOLEUDULHV
 QHLPSYS QUSRTOOL SAVLIB
*IBM
/LFHQVHGSURJUDPOLEUDULHV
QRPG QCBL Qxxxxx SAVLIB
*NONSYS
,%0OLEUDULHVZLWKXVHUGDWD
QGPL QUSRSYS QS36F /LEUDU\ SAVLIB
*ALLUSR
$OOXVHUOLEUDULHV

 'RFXPHQWVDQGIROGHUV SAVDLO
'LVWULEXWLRQREMHFWV
SAV
8VHUREMHFWVLQGLUHFWRULHV
%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-29. SAV commands and menu options

You can access the save commands either from the menu GO SAVE or CL commands. Which
method you use depends upon the type of save strategy you use. If you are using a simple save
strategy, the GO SAVE menu options 21, 22, or 23 probably suffice. The graphic above depicts the
parts of your system that are saved when you use options 21, 22, or 23 from the Save menu.
If you chose to use a medium, a save strategy, or both, there are additional steps to consider when
determining your SAV strategy. Draw a picture of your system similar to the one above. In your
picture, break the section called All User Libraries into smaller segments that match the way you
plan to save user libraries.
To determine how and when you plan to save each part of your system, review the System i Backup
and Recovery.

© Copyright IBM Corp. 1995, 2017 11-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6DYHPHQX

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-30. Save menu

Option 20 - Define save system and user data defaults. Select this option to define the save system
and user data defaults. These defaults are used by SAVE options 21, 22, and 23.
Following are the commands the system runs for the menu options 21, 22, and 23. In parentheses
() following the description is the name of the program for the menu option.
You might want to change this program if you need different values than the system-supplied
default values for the program.

Important

Option 21 Entire system to obtain a complete save of your system.

Save and Restore menu options that bring the system to restricted state, end TCP/IP servers, Host
servers, and TCP/IP before ending to restricted state. Save menu options 21 (Save entire system),
22 (Save system data only), 23 (Save all user data) and 40 (Save all libraries other than the system
library) and Restore menu options 21 (Restore entire system), 22 (Restore system data only), 23
(Restore all user data) and 40 (Restore all libraries other than the system library) now include the
following commands:

© Copyright IBM Corp. 1995, 2017 11-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
ENDTCPSVR
ENDHOSTSVR
DLYJOB JOB(300)
ENDTCP
DLYJOB JOB(300)
Before the ENDSBS SBS(*ALL) OPTION(*IMMED) command is issued

© Copyright IBM Corp. 1995, 2017 11-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9(RSWLRQ(QWLUHV\VWHP

ENDSBS SBS(*ALL) OPTION(*IMMED)


CHGMSGQ MSGQ(QSYSOPR) DLVRY(*BREAK OR *NOTIFY)
SAVSYS
SAVLIB LIB(*NONSYS) ACCPTH(*YES)
SAVDLO DLO(*ALL) SAVFLR(*ANY)
SAV DEV( ' /[Link]/TAPxx. DEVD' )
OBJ( ( ' / *' ) ( ' /[Link]' *OMIT)
( ' /QDLS' *OMIT) ) (1) UPDHST(*YES)
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-31. SAVE option 21: Entire system

SAVE Option 21 runs program QMNSAVE in QSYS. You can use RTVCLSRC to retrieve the
source and modify it.

© Copyright IBM Corp. 1995, 2017 11-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9(RSWLRQ6\VWHPGDWDRQO\

ENDSBS SBS(*ALL) OPTION(*IMMED)


CHGMSGQ MSGQ(QSYSOPR) DLVRY(*BREAK OR *NOTIFY)
SAVSYS
SAVLIB LIB(*IBM) ACCPTH(*YES)
SAVDLO DLO(*ALL) SAVFLR(*ANY)
SAV DEV( ' /[Link]/TAPxx. DEVD' )
OBJ( ( ' / QIBM/ProdData' )
( ' /QOpenSys/QIBM/ProdData‘ ) )
UPDHST(*YES)
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-32. SAVE option 22: System data only

SAVE Option 22 runs program QSRSAVI in QSYS. You can use RTVCLSRC to retrieve the source
and modify it.

© Copyright IBM Corp. 1995, 2017 11-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9(RSWLRQ$OOXVHUGDWD

ENDSBS SBS(*ALL) OPTION(*IMMED)


CHGMSGQ MSGQ(QSYSOPR) DLVRY(*BREAK OR *NOTIFY)
SAVSECDTA
SAVCFG
SAVLIB LIB(*ALLUSR) ACCPTH(*YES)
SAVDLO DLO(*ALL) SAVFLR(*ANY)
SAV DEV( ' /[Link]/TAPxx. DEVD' )
OBJ( ( ' / *' ) ( ' /[Link]' *OMIT)
( ' /QDLS' *OMIT) ) (1)
( ' /QIBM/ProdData' *OMIT )
( ' /QOpenSys/QIBM/ProdData' *OMIT) )
UPDHST(*YES)
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH
%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-33. SAVE option 23: All user data

SAVE Option 23 runs program QSRSAVU in QSYS. You can use RTVCLSRC to retrieve the source
and modify it.

© Copyright IBM Corp. 1995, 2017 11-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

+RZWKHV\VWHPSHUIRUPVVDYHSURFHVVLQJ
6WDUW
3UHSURFHVVLQJ
%XLOGVDYHOLVW 3RVWSURFHVVLQJ
IRUOLEUDU\/,%$
&RS\WKHREMHFWVLQ
OLEUDU\/,%$WRWDSH

%XLOGVDYHOLVW
IRUOLEUDU\/,%%
&RS\WKHREMHFWVLQ
OLEUDU\/,%%WRWDSH

%XLOGVDYHOLVW
IRUOLEUDU\/,%&
&RS\WKHREMHFWVLQ
OLEUDU\/,%&WRWDSH

%XLOGVDYHOLVW
IRUOLEUDU\/,%'
&RS\WKHREMHFWVLQ
OLEUDU\/,%'WRWDSH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-34. How the system performs save processing

The system performs a save by processing a list of objects (by library) to be saved, then saving
those objects to the media.

© Copyright IBM Corp. 1995, 2017 11-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

:KHUHWRSHUIRUPWKHVDYHWR"

7DSH
'LVN
3K\VLFDORUYLUWXDO DEV WDSHQDPHV

2SWLFDOGULYH DEV(OPTxx)

SAVLIB SAVFDTA(*YES) 7DSH


'LVN SAVSAVFDTA
SNDNETF
6DYHILOHDEV(*SAVF) SAVF(name)

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-35. Where to perform the save to?

Normally, tape is the media of choice for save and restore operations. However, you can use either
tape, diskette, save files (SAVF), or optical media.
The chart below shows the types of media supported by the various SAVxxx commands.

© Copyright IBM Corp. 1995, 2017 11-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9/,%6DYH/LEUDU\ RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-36. SAVLIB: Save Library (1of 2)

The Save Library (SAVLIB) command allows you to save a copy of one or more libraries.
When saving to a save file, only one library can be specified.
This command saves the entire library, including the library description, the object descriptions, and
the contents of the objects in the library. For job queues, message queues, and logical files, only
the object definitions are saved, not the contents. However, logical file access paths can be saved
by specifying *YES for the Save access paths (ACCPTH) parameter. The contents of spooled files
on output queues can be saved by specifying *ALL for the Spooled file data (SPLFDTA) parameter.
The contents of a save file can be saved by specifying *YES for the Save file data (SAVFDTA)
parameter or using the Save SaveFile Data (SAVSAVFDTA) command. The contents of a data
queue can be saved by specifying *DTAQ for the Queue data (QDTA) parameter. The libraries and
their objects are not affected in the system unless the command specifies that the storage is to be
freed. However, unless *NO is specified for the Update history (UPDHST) parameter, the description
of each library and each object is updated with the date, place, and time it was last saved. If a
group of libraries is saved by specifying *NONSYS, *ALLUSR, or *IBM for the LIB parameter, the
date, time, and place are updated in the history information for a data area in QSYS (data area
QSAVLIBALL, QSAVALLUSR, or QSAVIBM).

© Copyright IBM Corp. 1995, 2017 11-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Certain operating system objects that are not contained in user libraries (such as user profiles) are
not saved by this command. They can be saved by the Save System (SAVSYS) or Save Security
Data (SAVSECDTA) commands.

© Copyright IBM Corp. 1995, 2017 11-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9/,%6DYH/LEUDU\ RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-37. SAVLIB: Save Library (2 of 2)

Additional parameters for SAVLIB command.

© Copyright IBM Corp. 1995, 2017 11-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$92%-6DYH2EMHFW RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-38. SAVOBJ: Save Object (1 of 2)

The Save Object (SAVOBJ) command saves a copy of a single object or a group of objects located
in the same library. When *ALL is specified for the Objects (OBJ) parameter, objects can be saved
from a list of libraries. When saving to a save file, only one library can be specified. The system
saves the specified objects by writing a copy of each object on tape or optical media, or in a save
file.
The objects are not affected in the system unless the command specifies that the storage should be
freed. However, the description of each object is changed with the date, time, and place when it
was last saved, unless *NO is specified for the Update history (UPDHST) parameter.
For job queues, user queues, message queues, and logical files, only the object descriptions are
saved, and the contents of the objects are not saved. However, logical file access paths can be
saved by specifying *YES for the Save access paths (ACCPTH) parameter. The contents of spooled
files on output queues can be saved by specifying *ALL for the Spooled file data (SPLFDTA)
parameter. The contents of a save file can be saved by specifying *YES for the Save file data
(SAVFDTA) parameter or using the Save SaveFile Data (SAVSAVFDTA) command. The contents of
a data queue can be saved by specifying *DTAQ for the Queue data (QDTA) parameter.

© Copyright IBM Corp. 1995, 2017 11-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$92%-6DYH2EMHFW RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-39. SAVOBJ: Save Object (2 of 2)

Additional parameters for the SAVOBJ command.

© Copyright IBM Corp. 1995, 2017 11-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9&+*2%-6DYH&KDQJHG2EMHFWV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-40. SAVCHGOBJ: Save Changed Objects

The Save Changed Object (SAVCHGOBJ) command saves a copy of each changed object or group
of objects located in the same library.
When *ALL is specified for the Objects (OBJ) parameter, objects can be saved from all user libraries
or from a list of libraries. When saving to a save file, only one library can be specified. For database
files, only the changed members are saved.

© Copyright IBM Corp. 1995, 2017 11-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

)LOHV\VWHPV6DYHFRPPDQGV

)LOHV\VWHP 6DYHFRPPDQGV
5RRW  SAV

SAVSYS,
QSYS..LIB SAVCFG,
/LEUDU\ SAVSECDTA,
SAVLIB, SAVOBJ
SAVCHGOBJ, SAV
QDLS
SAVDLO
'RFXPHQWOLEUDU\
VHUYLFHV SAV

QOpenSys
SAV
2SHQV\VWHPV

2WKHUILOH
V\VWHPV SAV

8VHUGHILQHGILOH
6\VWHP GHY4$63[[ SAV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-41. File systems: Save commands

The SAV command is used to save objects in the Integrated File System (IFS). You must include
the SAV command to your save strategy to back up the objects in directories. This is very important
because IBM i Access, your configurations for DHCP, DNS, the HTTP Server, and many other
applications have objects in directories and also maybe users have documents and other files
stored in the IFS. Otherwise, objects in directories are not backed up, and you cannot recover them
if you do not use the SAV command.
You can reach directly to the IFS using green screen with the WRKLNK command or in IBM
Navigator for i, open the File System > Integrated File System.
The following file systems cannot be saved using the SAVxxx commands:
• NFS
• QFileSvr.400
• QOPT - directory for the CD-ROM
The Objects (OBJ) parameter on the SAV command supports the use of wildcard characters and the
directory hierarchy. When you have a specific subset of similar objects within a directory subtree
that you want to save, you can use the Name pattern (PATTERN) parameter to further define the
objects that are identified in the (OBJ) parameter.

© Copyright IBM Corp. 1995, 2017 11-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Another feature that the SAV command offers is the Scan objects (SCAN) parameter for purposes
such as virus protection. If exit programs are registered with any of the integrated file system
scan-related exit points, you can specify whether objects are scanned while being saved. This
parameter also allows you to indicate whether objects that previously failed a scan should be
saved.

© Copyright IBM Corp. 1995, 2017 11-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$96<6,1)FRPPDQG
‡ 3HUIRUPVDSDUWLDOVDYHRIGDWDVDYHGE\VDYHV\VWHP SAVSYS 
FRPPDQG
‡ &XPXODWLYHVDYHVLQFHODVWSAVSYS
‡ 5HVWULFWHGVWDWHQRWHUHTXLUHG
‡ 6DYHV
ƒ 6HOHFWHGREMHFWVLQOLEUDU\QSYS
ƒ 6\VWHPUHSO\OLVWHQWULHV
ƒ &HUWDLQV\VWHPYDOXHV
ƒ 6HUYLFHDWWULEXWHV
ƒ 1HWZRUNDWWULEXWHV
ƒ (QYLURQPHQWYDULDEOHV
ƒ &HUWDLQ37)V

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-42. SAVSYSINF command

The Save System Information (SAVSYSINF) command saves a subset of system data and objects
saved by the Save System (SAVSYS) command.
The system data and objects can be restored by the Restore System Information (RSTSYSINF)
command.
The history information for the data area QSYSINF in QSYS is updated with the date, time, and
place where the system information is saved.
SAVSYSINF is not to be considered a replacement for the SAVSYS command and is not to be used
for system upgrades or migrations.
Objects saved from QSYS include:
• *JOBD
• *JOBQ
• *EDTD
• *JRN
• *SBSD
• *CLS

© Copyright IBM Corp. 1995, 2017 11-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
• *MSGQ
• *TBL
• *IGCTBL
• *DTAARA
• *CMD objects changed since the last SAVSYS
• *MSGF objects changed since the last SAVSYS
Additional items saved include:
• System reply list
• Service attributes
• Environment variables
• Certain system values
• Network attributes
• PTFs applied since the last SAVSYS
Some items NOT saved as part of SAVSYSINF command:
• Licensed Internal Code
• QSYS library
• Security objects (use the SAVSECDTA command)
• Configuration objects (use the SAVCFG command)
• User profiles (use the SAVSECDTA command)
• Some system values (for example related to date/time)
• System values that cannot be changed. For system values that can be changed, refer to the
IBM i Knowledge Center at [Link]
• QPWDLVL (Password level) system value

© Copyright IBM Corp. 1995, 2017 11-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$96<6,1)FRPPDQGFRQVLGHUDWLRQV
‡ %DVHSAVSYS UHTXLUHG
ƒ SAVSYSINF QRWDUHSODFHPHQWIRUSAVSYS
‡ ALLOBJ RU SAVSYS VSHFLDODXWKRULW\UHTXLUHG
‡ &DQQRWEHXVHGIRU
ƒ 5HVWRULQJWRDQRWKHUH[LVWLQJV\VWHP
ƒ 6\VWHPXSJUDGHVRUPLJUDWLRQV
‡ ,QWHQGHGIRUFXVWRPHUVZKR
ƒ &DQQRWEULQJV\VWHPWRUHVWULFWHGVWDWHIRUSAVSYS
ƒ &DQQRWWDNHGRZQWLPHIRUSAVSYS
‡ 37)VDYHILOHVPXVWUHPDLQRQV\VWHPXQWLOQH[WSAVSYS
ƒ 'RQRWUXQ'HOHWH3URJUDP7HPSRUDU\)L[ DLTPTF FRPPDQGXQOHVV
í 5LJKWEHIRUHSAVSYS
í 5LJKWDIWHUSAVSYS
ƒ ,QVWDOOLQJ37)6GHIDXOWLVQRWWRUHVWRUHVDYHILOHV
í &KDQJHV\VWHPGHIDXOWCPYPTF(*YES) RUCHGSRVA FRPPDQGRU
í 8VHCPYPTF(*YES) LQINSPTF FRPPDQGFRQVLVWHQWO\

‡ 6\VWHPUHFRYHU\
ƒ SAVSYS DQGSAVSYSINF QHHGWREHUHFRYHUHG
ƒ RSTSYSINF DGGLWLRQDOVWHSSHUEDFNXSDQGUHFRYHU\FKHFNOLVWV
ƒ ,QFUHDVHVWLPHDQGFRPSOH[LW\

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-43. SAVSYSINF command considerations

It is recommended that a save of the entire system, including a SAVSYS be done in restricted state.
This can be accomplished by performing a Go Save Option 21, a combination of an Option 22 and
23, or by using the equivalent functions within BRMS.
It is difficult to save whole data system or SAVSYS when is not possible to set system to restricted
state. If you use external storage, you can use quiesce+FlashCopy, then it is possible to make a
backup from this copy. You can do this very easy with Full System Copy Services Manager
(FSFCSM - product created by IBM Lab Services Rochester.)

© Copyright IBM Corp. 1995, 2017 11-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$96<6,1)EDFNXSVWUDWHJ\
‡ $IWHUEDVHSAVSYSSHUIRUPWKHIROORZLQJFRPPDQGVWRVDYHV\VWHP
FKDQJHV
ƒ SAVLIB LIB(*IBM)
ƒ SAV OBJ(('/QIBM/ProdData')('/QOpenSys/QIBM/ProdData'))
UPDHST(*YES)
ƒ SAVSYSINF
‡ 7KHIROORZLQJDUHFRPPDQGVXVHGWRVDYHXVHUGDWD
ƒ SAVSECDTA
ƒ SAVCFG
ƒ SAVLIB LIB(*ALLUSR)
ƒ SAVDLO DLO(*ALL) FLR(*ANY)
ƒ SAV OBJ(('/*') (*/[Link]' *OMIT) ('/QDLS' *OMIT))
UPHST(*YES)
‡ +HUHLVDQH[DPSOHSAVSYSINF FRPPDQGWRVDYHILOH
ƒ SAVSYSINF DEV(*SAVF) SAVE(QGPL/SAVF) CLEAR(*ALL)
OUTPUT(*OUTFILE) OUTFILE(QGPL/OUPUT)

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-44. SAVSYSINF backup strategy

This slide shows a process for backing up save system information. The command example saves
the system information to the save file named SAVF in library QGPL. The save file is cleared
automatically. Information about what was saved is written to the first member of the file name
OUTPUT in library QGPL. The file and member are created if they do not exist.

© Copyright IBM Corp. 1995, 2017 11-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

3DUDPHWHU6DYHZKLOHDFWLYH
‡ &DQEHXVHGZLWKWKHIROORZLQJFRPPDQGV
ƒ SAV
í 6DYHWKHLQWHJUDWHGILOHV\VWHP ,)6
ƒ SAVLIB
í 6DYHRQHOLEUDU\RUPXOWLSOHOLEUDULHV
ƒ SAVOBJ
í 6DYHRQHREMHFWRUPXOWLSOHREMHFWV
ƒ SAVCHGOBJ
í 6DYHFKDQJHGREMHFW
ƒ SAVDLO
í 6DYHGRFXPHQWOLEUDU\REMHFW IROGHUV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-45. Parameter: Save-while-active

You can use the save-while-active function, along with your other backup and recovery procedures,
to reduce or eliminate your outage for particular save operations. The amount of time during the
backup process that you cannot use the server is the save-outage time.
The save-while-active function allows you to use your server during all or part of the save process,
that is, save your server while it is active. This allows you to reduce or eliminate your save-outage
time. In contrast, other save functions allow no access, or only allow read access, to the objects as
you are saving them.

© Copyright IBM Corp. 1995, 2017 11-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6DYHZKLOHDFWLYHSDUDPHWHUV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-46. Save-while-active parameters

Synchronization
When you save more than one object, you must choose when the objects reach a checkpoint in
relationship to each other. This is synchronization. There are three kinds of synchronization:
*SYNCLIB (Full synchronization): With full synchronization, the checkpoints for all of the objects
(across multiple libraries) occur at the same time. The checkpoints occur during a time period in
which no changes can occur to the objects. IBM strongly recommends that you use full
synchronization, even when you are saving objects in only one library.
*LIB (Library synchronization): With library synchronization, the checkpoints for all of the objects
within a specific library occur at the same time. Objects in a library can be saved while they are in
use by another job. All of the objects in a library reach a checkpoint together and are saved in a
consistent state in relationship to each other.
*SYSDFN (System-defined synchronization): With system-defined synchronization, the server
decides when the checkpoints for the objects occur. The checkpoints for the objects might occur at
different times resulting in complex restore procedures.
SAVACT parameter has the following choices:
• *NO Objects that are in use are not saved. Objects cannot be updated while being saved.

© Copyright IBM Corp. 1995, 2017 11-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
• The Wait time SAVACTWAIT parameter has three elements:
▪ Element 1: Object locks: The default value is 120 seconds. For each object that is in use, it
specifies the amount of time to wait for the object to become available. If an object remains
in use for the specified time, the object is not saved.
▪ Element 2: Pending record changes: The default value is *LOCKWAIT. For each group of
objects that are checkpointed together, specifies the amount of time to wait for transactions
with pending record changes to reach a commit boundary. The Save active (SAVACT)
parameter determines which objects are checkpointed together. You use *NOCMTBDY to
save objects without waiting for commit boundaries.
▪ Element 3: Other pending changes The default value is *LOCKWAIT. For each library,
specifies the amount of time to wait for transactions with other pending changes to reach a
commit boundary. Other pending changes include the following:
- Data Definition Language (DDL) object level changes for that library.
- Any API commitment resource that was added without the option to allow normal save
processing.
• If a commit boundary is not reached for a library in the specified time, the library is not saved.
Checkpoint notification (SAVACTMSGQ): You can specify the checkpoint notification on the
SAVACTMSGQ parameter. The specified message queue receives a message after checkpoint
processing is complete. An operator or a job can monitor this message queue and restart
applications when checkpoint processing is complete.
Synchronization ID (SYNCID): Specifies the name of the synchronized checkpoint in which this
'save while active' operation participates. The synchronized checkpoint must already be started by
the Start Save Synchronization (STRSAVSYNC) command.

© Copyright IBM Corp. 1995, 2017 11-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6DYHRXWDJHWLPH
‡ 7KHVDYHZKLOHDFWLYHIXQFWLRQDOORZV\RXWR
ƒ 5HGXFH\RXUVDYHRXWDJHWLPH
í (QGWKHDSSOLFDWLRQV
í 5HVWDUWZKHQWKHFKHFNSRLQWLVGRQH
í 1RDGGLWLRQDOUHFRYHU\SURFHGXUHIRUUHVWRUH
ƒ (OLPLQDWH\RXUVDYHRXWDJHWLPH
í 1RWZDLWLQJWRHQGWKHDSSOLFDWLRQV
í 3URWHFWREMHFWVZLWKMRXUQDOLQJDQGFRPPLWPHQWFRQWURO
í 0RUHFRPSOH[DQGORQJHUUHFRYHU\SURFHGXUHIRUUHVWRUH
í SAVACTWAIT SDUDPHWHUVSHFLILHVWKUHHZDLWWLPHHOHPHQWV
2EMHFWORFNV
&RPPLWUHFRUGFKDQJHV
&RPPLWREMHFWFKDQJHV
í 6DYLQJZLWKSDUWLDOWUDQVDFWLRQVRUZLWKRXWZDLWLQJIRUFRPPLWPHQWERXQGDULHV
SAVACTWAIT(30 *NOCMTBDY 30)

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-47. Save-outage time

Reducing your save-outage time


Reducing your save-outage time is the easiest way to use the save-while-active function. When you
use this option, the restore procedure is the same as when you perform a standard save. In
addition, you can use the save-while-active function to reduce your save-outage time without using
journaling or commitment control. Unless you have no tolerance for a save-outage time, you should
use the save-while-active function to reduce your save outage.
To reduce your save-outage time, you can end the applications that makes changes to the objects
you are saving. You can restart the applications when the server establishes a checkpoint for
application-dependent objects.
Eliminating your save-outage time
You can use the save-while-active function to eliminate your save outage. Use this option only if
you have no tolerance for a save-outage time. You should use the save-while-active function to
eliminate your save-outage time only for objects that you protect with journaling or commitment
control. In addition, you have considerably more complex recovery procedures. You should
consider these more complex recovery procedures in your disaster recovery plan.

© Copyright IBM Corp. 1995, 2017 11-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Saving objects with partial transactions
Although there are three potential reasons for stopping a rapid save operation, the new support
(Ragged SWA) focuses on only one of the three: keeping a commitment control transaction open
for a long period.
Use of the *NOCMTBDY value is the key for instructing the SAVLIB command that you want to
capitalize on the new Ragged style of Save While Active.
Extra information consists of a list of the specific open transactions that are still in flight. The
transactions are identified by the journal sequence number corresponding to the SC flavored
journal entry associated with the beginning of each such open transaction.
Just because you give the SAVLIB command permission to capture a file in a ragged state, if need
be, this does not mean that when SAVLIB is ready to process a particular file that it will truly have
in-flight transactions.
Only the files that were truly caught and saved in a so-called ragged state will be flagged as ragged.
The rest appears as though they were saved with the classic SWA approach (that is, in a clean
state).
With a little detective work on your part (some from the job log, some from the specified queries
against your outfiles), you can find and list those files that were saved and restored in a ragged
state.
Since proper recovery of a ragged file is so dependent upon having the appropriate journal
receivers once you being to employ nightly Ragged SWA saves, you need to take it upon yourself
to be sure you also have the discipline to save and also hang onto a sufficient set of past journal
receivers.

© Copyright IBM Corp. 1995, 2017 11-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

&KHFNSRLQWSURFHVVLQJ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-48. Checkpoint processing

How it works
IBM i objects consist of units of storage that are called pages. When you use the save-while-active
function to save an object, the server creates two images of the pages of the object:
• The first image contains the updates to the object with which normal server activity works.
• The second image is an image of the object at a single point in time. The save-while-active job
uses this image to save the object to the media.
In other words, when an application makes changes to an object during a save-while-active job, the
server uses one image of the object&escape_backslash;xd5 s pages to make the changes. At the
same time, the server uses the other image to save the object to the media. The image that the
server saves does not have the changes you made during the save-while-active job. The image on
the media is as it existed when the server reached a checkpoint.
Checkpoints
The checkpoint for an object is the instant in time that the server creates an image of that object.
The image that the server creates at that instant in time is the checkpoint image of the object.
Creating a checkpoint image is similar to taking a photograph of a moving automobile. The point in
time that you took the photograph would equate to the checkpoint. The photograph of the moving
automobile would equate to the checkpoint image. When the server finishes making the checkpoint

© Copyright IBM Corp. 1995, 2017 11-68


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
image of the object, the object has reached a checkpoint. Despite the name save-while-active, you
cannot change objects while the server obtains their checkpoint images. The server allocates (or
locks) objects as it obtains checkpoint images. After the server obtains the checkpoint images, you
can change the objects.
When more than one object is being saved, you can choose whether the checkpoint images for the
objects should be synchronized. With full synchronization, the checkpoints for all of the objects
occur at the same time (actually, during a time period in which no changes can occur to the
objects). With library synchronization, the checkpoints for all of the objects in a library occur at the
same time. With system-defined synchronization, the checkpoints for the objects can occur at
different times.
The amount of time that the system is unavailable to users during the backup process is referred to
as the save outage. The easiest and recommended way to use the save-while-active function is to
reduce your save outage by ending your applications that change objects until after the checkpoint
images are obtained. You can choose to have the save-while-active function send a notification
when the checkpoint processing is complete and it is safe to start your applications again. When
the save-while-active function is used in this way, the save outage can be much less than with
normal save operations.
The image of the object saved to the media is the conceptual image of the object after checkpoint
processing is complete.
• Time #1 - Is the save preprocessing phase of the save-while-active function. At the end of #1,
the object reaches a checkpoint.
• Time #2 - Shows an update of the object while it is being saved.
• A request is made to update C1.
• A copy of the original page is made first.
• The change is made to the object.
• The original page copied is then part of the checkpoint image for the object.
• Time #3 - Shows two additional changes, C2 and C3, were made to the object.
• Each changed page is marked so that additional changes to that page do not require additional
processing.
• Time #4 - (save post-processing) Shows that the copied pages for the checkpoint image are no
longer needed and are discarded.
• Time #5 - Shows that the object on the system has the C1, C2, and C3 changes, but the copy of
the object saved to the media does not contain these changes.

© Copyright IBM Corp. 1995, 2017 11-69


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9)6DYLQJXVLQJDVDYHILOH

RSTOBJ

*FILE
CUSTMAST *file [Link] SFxx *file [Link]
SAVOBJ SAVSAVFDTA
DEV(*SAVF) SAVF(SFxx)
SAVF(SFxx) DEV(TAP01) CUSTMAST
CUSTMAST
CUSTMAST

2QFH\RXKDYHVDYHGWRVDYHPHGLD
CLRSAVF FILE(SAVE-FILE-NAME)

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-49. SAVF: Saving using a save file

Using a save file allows you to save and restore objects without first placing save media into your
save media device. You can also use a save file to send objects from one IBM i server to another
over communications lines. You can use the save file as an online container to save the contents of
a single library to run overnight. The next day, save the contents of the save file to storage media
with the Save SaveFile Data (SAVSAVFDTA) command. Objects saved to a save file can be
restored directly from save media, using the RSTLIB or RSTOBJ command.
If you save to save files or optical media, you also have three choices available for software
compression: low, medium, and high. If you choose a higher form of compression, your save takes
longer, but the resulting save data is usually smaller.
Considerations for using save files are:
• Performance
▪ Performance can vary, depending on other disk activity. Save files can be created on or
moved to an ASP for improved performance and additional protection from system disk
device failures.

© Copyright IBM Corp. 1995, 2017 11-70


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
• Storage capacity
▪ The maximum amount of data that a save file can contain is approximately 2 terabytes. A
message appears when the file is full. Specify data compression on the save commands to
reduce the space for the save file and the amount of media needed for the SAVSAVFDTA
command.
• Preparing save files for use
▪ When saving to a save file that already contains data, use the Clear Save File (CLRSAVF)
command or specify CLEAR(*ALL) on the save command, or reply to an inquiry message
sent during the save operation.
• Saving the save file data: There are two ways to save the save file data:
▪ With the SAVSAVFDTA command, only the data is saved. The description of the save file
object is not saved. The save date and time of the save file are not updated. When you use
the Save Object (SAVOBJ) or the Save Library (SAVLIB) command with SAVFDTA(*YES)
specified, both the object description and the data are saved. The save date and time are
updated for the save file.
▪ The DSPSAVF command displays the contents of a save file. The information includes a
description of each object saved and summary information.

© Copyright IBM Corp. 1995, 2017 11-71


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6$9)6DYH)LOH&RPPDQGV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-50. SAVF: Save File Commands

Use the following CL commands with save files:


CRTSAVF: The Create Save File (CRTSAVF) command creates a save file that can be used with
save and restore commands to store data. The save file stores data that would otherwise be written
to save media. A save file can also be used as a container to send objects to another System i.
CHGSAVF: The Change Save File (CHGSAVF) command changes one or more of the attributes of a
save file, such as the maximum number of records.
OVRSAVF: The Override Save File (OVRSAVF) command overrides or replaces certain attributes of
a save file, or overrides any file with a save file.
DSPFD: The Display File Description (DSPFD) command displays the attributes of the save file.
CLRSAVF: The Clear Save File (CLRSAVF) command clears the contents of a save file.
DSPSAVF: The Display Save File (DSPSAVF) command displays the save and restore information in
a save file, or the contents of the save file.
SAVSAVFDTA: The Save SaveFile Data (SAVSAVFDTA) command writes the contents of a save file
to tape.
DLTF: The Delete File (DLTF) command deletes the save file object.

© Copyright IBM Corp. 1995, 2017 11-72


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
SNDNETF: Objects (such as programs or commands) must be saved in a save file before they can
be sent using the SNDNETF command.

© Copyright IBM Corp. 1995, 2017 11-73


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

0LVFHOODQHRXV6$9FRPPDQGV
‡ 6DYH,)6REMHFWV SAV FRPPDQG
‡ 6DYH'RFXPHQW/LEUDU\2EMHFW SAVDLO FRPPDQG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-51. Miscellaneous SAV commands

The SAV command enables you to save the following data:


• A specific object
• A directory or subdirectory
• An entire file system
• Objects that meet search value
The Objects (OBJ) parameter on the SAV command supports the use of wildcard characters and the
directory hierarchy. When you have a specific subset of similar objects within a directory subtree
that you want to save, you can use the Name pattern (PATTERN) parameter to further define the
objects that are identified in the (OBJ) parameter. For example, you could have a directory /MyDir
that contains 100 subdirectories. Dir1 - Dir100 that each contains 100 .jpg files, and [Link]
- [Link], with corresponding backup [Link] through [Link]. To save all of the
.jpg files in /MyDir, but omit the backup files, you could issue the following command:
SAV OBJ(('/MyDir')) PATTERN(('*.bkp' *OMIT))
When you use the SAV command to save the current directory SAV OBJ(’*’) and the current
directory is empty (it has no files or subdirectories), the system does not save anything. The
command does not save the one *DIR object that represents the current directory. However, when
you explicitly specify the directory by name SAV OBJ(’/mydir’) you include the *DIR object in
your save operation. The same applies to the home directory.

© Copyright IBM Corp. 1995, 2017 11-74


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Another feature that the SAV command offers is the Scan objects (SCAN) parameter for purposes
such as virus protection. If exit programs are registered with any of the integrated file system
scan-related exit points, you can specify whether objects are scanned while being saved. This
parameter also enables you to indicate whether objects that previously failed a scan should be
saved.
When you use the SAV command, you can specify OUTPUT(*PRINT) to receive a report of what
the system saved. You can also direct the output to a stream file or to a user space. The SAV
command does not provide the option to create an output file.
IBM i provides the capability to store documents and folders in a hierarchy (documents within a
folder within another folder). Documents and folders are called document library objects (DLOs).
The Save Document Library Object (SAVDLO) command is used to save one or more documents.
Documents are not affected by this unless you specify that storage is to be freed or deleted. You
can save a single document or more than one document with this command.

© Copyright IBM Corp. 1995, 2017 11-75


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

8VLQJ2SHUDWLRQDO$VVLVWDQW
‡ *2$66,67
ƒ 6HOHFW &XVWRPL]H\RXUV\VWHPXVHUVDQGGHYLFHV 
ƒ 6HOHFW %DFNXSWDVNV 

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-52. Using Operational Assistant

To access the Backup Tasks menu from Operational Assistant menu, select option 11
Customize your system, users, and devices then select option 5 Backup tasks or type GO BACKUP
on the command line. From the Backup menu, you can Run backup, Display backup status, Set up
backup, Initialize a tape, or Initialize a tape set.
To access the RunBackup menu from Operational Assistant, select option 10 Manage your
system, users, and devices then select option 2 Run a backup or type GO RUNBCKUP on the
command line. The Run Backup menu can also be accessed from the Backup Tasks menu,
option 1. The Run Backup menu allows you to Run daily backup, Run weekly backup, Run
monthly backup, Back up IBM-supplied libraries, or Back up the entire system.
To access the SetUp Backup menu, select option 10 Setup backup from the Backup Tasks menu
or type GO SETUP from the command line. The Set Up Backup menu provides options that enable
you to change backup options, lists, and schedules.

© Copyright IBM Corp. 1995, 2017 11-76


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

8VLQJ%506
‡ *2%506

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-53. Using BRMS

Very useful product is BRMS Backup Recovery and Media Services that offers you full backup
automation and tape devices and media management. BRMS allows you also data movement
between different type tier of disks speed (HDD to SSD and back), full automated archive, and
recovery data or whole system. BRMS allows to make backup in a cloud.
To work with BRMS you can use many commands or go to main BRMS menu using GO BRMS
command and select options.
More you can learn on course AS28G BRMS for IBM i, including Cloud Storage Solutions for i you
can find it at:
[Link]
rseCode=AS28G

© Copyright IBM Corp. 1995, 2017 11-77


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

,%01DYLJDWRUIRUL%506SOXJLQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-54. IBM Navigator for i BRMS plugin

If Backup Recovery and Media Services (BRMS) software is installed on the system then you can
automatically will be installed the plug-in for BRMS for IBM Navigator for i.
IBM Navigator for i offers you run Enterprise Services where you can manage backup on many IBM
i systems (or partitions) in one place.

© Copyright IBM Corp. 1995, 2017 11-78


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6DYHWLSVDQGKLQWV
‡ 'HWHUPLQLQJZKDWKDVEHHQVDYHG
‡ 'HWHUPLQLQJZKDWKDVQRWEHHQVDYHG
‡ 'HWHUPLQLQJZKHQDQREMHFWZDVODVWVDYHG
‡ 'DPDJHGREMHFWV
‡ 3DUDOOHOHGWDSHVDYHV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-55. Save tips and hints

There are some tips and hints you might find useful:
Determining what has been saved: You can use the job log to display what objects have been
saved or you can direct the output of the save operation to a printer (OUTPUT(*PRINT)), a
database file (OUTPUT(*OUTFILE)), a stream file, or a user space.
Determining what has not been saved: If an object cannot be saved, the system skips that object
and writes an entry to the job log. You can specify OUTPUT(*OUTFILE) INFTYPE(*ERR) on the
SAVLIB, SAVOBJ, and SAVCHGOBJ commands. This creates an output file that only contains
entries for those objects that were not saved. Also, you can look in the history file with the
command DSPLOG. It is easier to find messages from the backup job if you have additional time and
date from the backup time for the PERIOD parameter (for example, DSPLOG PERIOD((060000
130803)).
Determining when an object was last saved: You can use the Display Object Description
(DSPOBJD) command to find out when an object was last saved in a library. For objects that are
stored in directories, you can use the output from the SAV command to maintain save history
information. To use the output, you must elect to retain the save history information to either
*PRINT or a stream file or user space path name on the OUTPUT parameter of the SAV command.
Damaged objects: What the system does with damaged objects depends on when the damage is
detected.

© Copyright IBM Corp. 1995, 2017 11-79


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Objects damaged before the save operation cannot be saved but the save operation continues with
the next object. The operation completes with an indication of how many objects were saved and
how many were not.
If an object is damaged by the save operation, the object is marked as damaged, the save
operation ends and diagnostic messages are sent.
If an object is damaged but the system does not detect it, the object is restored normally and you
might not be able to detect the damage until you try to use the object.
Parallel tape save operations: You can perform save operations while using more than one tape
device simultaneously. The data that is produced on the save media by these parallel save
operations have a save format that is referred to as parallel.
Data in parallel format is spread across a set of tape files, called media files. The entire set of these
media files is referred to as a parallel save/restore file. A media file is identified on save (or restore)
operations by the device (DEV), sequence number (SEQNBR), volume identifiers (VOL), and file label
(LABEL) parameters. These parameters only allow one media file to be identified. However, a
parallel save (or restore) operation uses more than one media file. This problem is solved by using
a media definition.
A media definition (*MEDDFN) allows more than one media file to be identified. A media definition
defines the devices, sequence numbers, and volume identifiers that should be used by a parallel
save operation.
The devices that you specify in a media definition must be compatible stand-alone tape devices or
tape media library devices. The tape volumes that you specify must have compatible media
formats.

© Copyright IBM Corp. 1995, 2017 11-80


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
11.4. Topic 4: Restore operations

© Copyright IBM Corp. 1995, 2017 11-81


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7RSLF5HVWRUHRSHUDWLRQV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-56. Topic 4: Restore operations

© Copyright IBM Corp. 1995, 2017 11-82


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HODWLRQVKLSEHWZHHQVDYHDQGUHVWRUHFRPPDQGV
6DYH 5HVWRUH
SAVSECDTA RSTUSRPRF
RSTAUT
SAVCFG RSTCFG
5HVWRUH/LFHQVHG,QWHUQDO&RGH VHHFKDSWHURI
SAVSYS 6\VWHP0DQDJHPHQW5HFRYHULQJ\RXV\VWHP 
5HFRYHULQJWKH/LFHQVHG,QWHUQDO&RGHDQG5HVWULQJ
WKHRSHUDWLQJV\VWHP VHHFKDSWHURI6\VWHP
0DQDJHPHQW5HFRYHULQJ\RXV\VWHP
RSTUSRPRF
RSTCFG
RSTAUT
SAVLIB RSTLIB
SAVOBJ RSTOBJ
SAVDLO RSTDLO

SAV RST
SAVSYSINF RSTSYSINF
%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-57. Relationship between save and restore commands

A restore of the system requires the installation of the operating system and might also include the
installation of the Licensed Internal Code (distributed on DVD, labeled I_Base_01 provided by IBM
or on the first volume of the most recent SAVSYS tapes). Installation of LIC requires an IPL type D
of the system. The installation of the operating system is performed through options in the IPL or
Install display, which follows a manual IPL.
The next two graphics show which restore commands can be used, based on how the objects were
saved.
For more look at: SC41-5304-12 System Management Recovering your System 7.3 you can find
the publication at:
[Link]

© Copyright IBM Corp. 1995, 2017 11-83


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HVWRUHRYHUYLHZ
5HVWRUH 3DUWVRIWKHV\VWHPPHQX 3URFHGXUHIRUUHVWRULQJ
2SWLRQRQLQVWDOO/LFHQVHG
/LFHQVHG,QWHUQDO&RGH ,QWHUQDO&RGH /,& VFUHHQ

,%0L26REMHFWVLQQSYS ,3/RULQVWDOOWKHV\VWHPPHQX

8VHUSURILOHV RSTUSRPRF

&RQILJXUDWLRQREMHFWV RSTCFG

,%0VXSSOLHGGLUHFWRULHV RST

,%0L26RSWLRQDOOLEUDULHV
QHLPSYS QUSRTOOL RSTLIB
/LFHQVHGSURJUDPOLEUDULHV *IBM RSTLIB
QRPG QCBL Qxxxxx
 *NONSYS
,%0OLEUDULHVZLWKXVHUGDWD
QGPL QUSRSYS QS36F #LIBRARY RSTLIB
8VHUOLEUDULHV *ALLUSR
LIBA LIBB LIBC LIBxxx

)LOHGGRFXPHQWVDQGIROGHUV RSTDLO
'LVWULEXWLRQREMHFWV
8VHUREMHFWVLQGLUHFWRULHV RST

6DYHGFKDQJHVLQOLEUDULHV RSTLIB, RSTOBJ,


GRFXPHQWVDQGGLUHFWRULHV RSTDLO, RST

-RXUQDOHGFKDQJHV APYJRNCHG

$OO 3ULYDWHDXWKRULWLHV RSTAUT

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-58. Restore overview

The graphic shows the menu options and commands that are available for restoring information. It
also shows the normal sequence for restoring information, working from top to bottom.

© Copyright IBM Corp. 1995, 2017 11-84


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HVWRUHPHQX RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-59. Restore menu (1 of 3)

In order to have this menu displayed, the LIC, and the operating system must be installed.

© Copyright IBM Corp. 1995, 2017 11-85


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5(6725(RSWLRQ6\VWHPDQGXVHUGDWD

ENDSBS SBS(*ALL) OPTION(*IMMED)


RSTUSRPRF USRPRF(*ALL)
RSTCFG OBJ(*ALL)
RSTLIB SAVLIB(*NONSYS)
RSTDLO DLO(*ALL) SAVFLR(*ANY)
RST DEV( ' /[Link]/TAPxx. DEVD' )
OBJ( ( ' / *' ) ( ' /[Link]' *OMIT)
( ' /QDLS' *OMIT) )
RSTAUT
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-60. RESTORE option 21: System and user data

RESTORE option 21 runs program QMNRSTE in QSYS. You can use RTVCLSRC to retrieve the
source and modify it.

© Copyright IBM Corp. 1995, 2017 11-86


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HVWRUHPHQX RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-61. Restore menu (2 of 3)

Additional restore options are displayed on this second of three RESTORE menus from the IBM i
menu interface.

© Copyright IBM Corp. 1995, 2017 11-87


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5(6725(RSWLRQ6\VWHPGDWDRQO\

ENDSBS SBS(*ALL) OPTION(*IMMED)


RSTUSRPRF USRPRF(*ALL)
RSTCFG OBJ(*ALL)
RSTLIB SAVLIB(*IBM)
RST DEV( ' /[Link]/TAPxx. DEVD' )
OBJ( ( ' /QIBM/ProdData ' )
( ' /QOpenSys/QIBM/ProdData ' ))
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-62. RESTORE option 22: System data only

RESTORE option 22 runs program QSRRSTI in QSYS.


If necessary, you can use the RTVCLSRC command to retrieve the source code for this program and
then make any necessary modifications.

© Copyright IBM Corp. 1995, 2017 11-88


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5(6725(RSWLRQ$OOXVHUGDWD

ENDSBS SBS(*ALL) OPTION(*IMMED)


RSTUSRPRF USRPRF(*ALL)
RSTCFG OBJ(*ALL)
RSTLIB SAVLIB(*ALLUSR)
RSTDLO DLO(*ALL) SAVFLR(*ANY)
RST DEV( ' /[Link]/[Link] ' )
OBJ( ( ' / * ' ) ( ' /[Link]' *OMIT)
( ' /QDLS ' *OMIT)
( ' /QIBM/ProdData ' *OMIT)
( ' /QOpenSys/QIBM/ProdData' *OMIT))
RSTAUT USRPRF(*ALL)
STRSBS SBSD (controlling subsystem)

:KHUHxx LVWKHQDPHRIWKHWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-63. RESTORE option 23: All user data

RESTORE option 23 runs program QSRRSTU in library QSYS. You can use RTVCLSRC to retrieve
its source, then modify it.

© Copyright IBM Corp. 1995, 2017 11-89


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HVWRUHPHQX RI

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-64. Restore menu (3 of 3)

Additional restore options are displayed on the third of three RESTORE menus from the IBM i
menu interface. Also pictured is the menu that appears when option 70, Related commands, is
selected.

© Copyright IBM Corp. 1995, 2017 11-90


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

:KDWKDSSHQVZKHQ\RXUHVWRUHGDWD"
‡ :KDWKDSSHQVGHSHQGVRQ
ƒ :KHWKHUWKHREMHFWDOUHDG\H[LVWVRQWKHV\VWHP
ƒ 7KHALWOBJDIF SDUDPHWHUVHWWLQJ
ƒ :KHWKHUWKHREMHFWZDVVDYHGRQDQRWKHUV\VWHP

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-65. What happens when you restore data?

An object on this system is like a container. The object has information about the container itself,
such as the owner of the object and the last time it was saved. This is the information you see when
you display the object description (DSPOBJD command). The object also has contents, such as the
records in a database file or the instructions in a program.
When you restore an object, the system takes different actions depending on the following:
• Whether the object to be restored already exists
• The allow object differences (ALWOBJDIF) parameter on the restore command
• Whether the object was saved on a different system (serial number of the processor)
With a few exceptions that relate to security, the contents of the object are always restored. If the
object exists, the system compares the object description information on the system copy and the
media copy and then makes decisions. For most information, the media version of the information
is restored. For security relevant information, such as the public authority and the object owner, the
system version is left unchanged. In a few cases, such as the size of the object and the date it was
restored, the system determines a value when the object is restored.

© Copyright IBM Corp. 1995, 2017 11-91


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
The allow object differences (ALWOBJDIF) parameter on the restore commands is primarily for
security protection and integrity protection. For example, if system security is important to you, you
might want to take special action if someone attempts to restore an object whose owner has been
changed. If the member information about a database file does not match, you might have
problems with the integrity of your data. You can use the ALWOBJDIF parameter to prevent this.
The default value for the ALWOBJDIF parameter is *NONE. This means that if important differences
exist between the media version and the system version of an object, you want the system to take
special action. Normally, you should use the default value. However, when you are restoring your
information to a different system, such as during a disaster recovery, you should specify
ALWOBJDIF(*ALL).
You can specify a combination of up to four values on the ALWOBJDIF parameter to allow specific
types of differences for the restore operation: *FILELVL, *AUTL, *OWNER, and *PGP. The
*FILELVL value attempts to restore physical file data when the file level ID or the member level ID
of the physical file on the system is different than that of the physical file on the save media. The
*AUTL value allows differences in authorization lists. The *OWNER value allows differences in object
ownership. The *PGP value allows differences in the primary group.
The advantage that ALWOBJDIF(*FILELVL *AUTL *OWNER *PGP) has over
ALWOBJDIF(*ALL) is that in addition to allowing all object differences, it attempts to restore
physical files when the file level ID or member level ID of the physical file on the system is different
than that for the physical file on the save media.
Since IBM i 7.1 a new value *COMPATIBLE has been added to the ALWOBJDIF (allow object
differences) parameter to make restores less confusing and less error prone for database files.
Using ALWOBJDIF(*ALL) for database files is undesirable because: When a file-level difference
occurs, the original file is renamed and the saved file is restored. When a member level difference
occurs, the existing member is renamed and the saved member is restored. Because of the
duplicated files and members, system resources are wasted and applications might produce
unpredictable results. This leaves the user with a perplexing choice between the renamed data or
the restored data and leaves some clean up activities to perform. For database objects,
ALWOBJDIF(*COMPATIBLE) is equivalent to specifying ALWOBJDIF(*AUTL *OWNER *PGP
*FILELVL) which allows the following differences:
• All authorization list differences.
• All ownership differences.
• All primary group differences.
• File level differences where different file level and member levels are restored ONLY when the
format level identifiers of the file on media match format level identifiers of the file on the
system. In brief, the file formats must match.
• For non-database objects, ALWOBJDIF(*COMPATIBLE) performs like ALWOBJDIF(*ALL)
which allows all object differences to be restored.
• The *COMPATIBLE value for the ALWOBJDIF parameter is supported on:
• RSTLIB (Restore Library) and RSTOBJ (Restore Object) commands.
• QSRRSTO (Restore object) API.
• Restore menu options, which use RSTLIB and RSTOBJ commands.

© Copyright IBM Corp. 1995, 2017 11-92


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
• RSTLIBBRM (Restore Library using BRM), RSTOBJBRM (Restore Object using BRM), and
STRRCYBRM (Start Recovery using BRM) commands.
• SAVRSTLIB (Save Restore Library), SAVRSTOBJ (Save Restore Object), and SAVRSTCHG
(Save Restore Changed Objects) commands.
The restore menu options:
• 21 - Restore entire system
• 22 - Restore system data only
• 23 - Restore all user data
now default to ALWOBJDIF(*COMPATIBLE) when restoring to a different system.
The RSTLICPGM (Restore Licensed Program) command now internally uses
ALWOBJDIF(*COMPATIBLE), but does not include them on the command interface

© Copyright IBM Corp. 1995, 2017 11-93


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6HTXHQFHIRUUHVWRULQJGDWD
‡ 5HVWRUHREMHFWVHTXHQFH
ƒ -RXUQDOVEHIRUHMRXUQDOHGILOHV
ƒ -RXUQDOVEHIRUHMRXUQDOHGUHFHLYHUV
ƒ 3K\VLFDOILOHVEHIRUHORJLFDOILOHV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-66. Sequence for restoring data

When related objects are in the same library, the system restores them in the correct order. If
related objects are in different libraries, you must restore them in the correct order to perform
additional recovery steps after they are restored.
You should restore objects in this sequence:
• Journals before journaled files: If you restore a journaled file when the journal is not on the
system, you must start journaling again after the journal is restored. Use the STRJRNPF
command or the STRJRNAP command.
• Journals before journal receivers: If you restore a journal receiver when the journal is not on
the system, you must associate the journal receivers with the journal after it is restored. Use the
WRKJRN command.
• Physical files before logical files: You cannot restore a logical file if the based-on physical
files are not on the system.

© Copyright IBM Corp. 1995, 2017 11-94


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

3XWWLQJ\RXUV\VWHPLQDUHVWULFWHGVWDWH
‡ 6LJQRIIDOOXVHUV

‡ (QDEOHQRWLILFDWLRQ

‡ (QGDOOVXEV\VWHPV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-67. Putting your system in a restricted state

Many recovery procedures require that your system have no other activity on it. When no
subsystems except the controlling subsystem are active on your system, it is in a restricted state.
Use the End Subsystem (ENDSBS) command to put your system in a restricted state. You specify
how you want the subsystems to end with the Options parameter:
• *CNTRLD: Allow active jobs to end themselves. If you specify *CNTRLD, you can use the delay
parameter to set a time for the system to wait before ending subsystems immediately.
• *IMMED: End the subsystem immediately. Use this option if there are no users on the system
and no batch jobs running.
• To put your system in a restricted state:
▪ Ensure that all users are signed off and all jobs are ended
▪ Enter the following command to ensure you receive notification of the SBS ending:
CHGMSGQ MSGQ(QSYSOPR) DLVRY(*BREAK) SEV(60)
• To end all subsystems, enter the following command:
ENDSBS SBS(*ALL) OPTION(*CNTRLD) DELAY(600)

© Copyright IBM Corp. 1995, 2017 11-95


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
For the delay parameter, specify a number of seconds to allow your system time to bring most jobs
to a normal end. On a large, busy system, you might need a longer delay. A message is sent that
indicates that the procedure for ending subsystems is in progress. A final message will be sent to
the message queue QSYSOPR when the system is in a restricted state. If this message is not
received in the message queue from the system operator, you can use the ENDSYS command.
The End System (ENDSYS) command ends most activity on the system and leaves the system in a
condition in which only the console is active in the controlling subsystem. This is done so that the
operator can do things like backing up the system or loading new programs. This condition is called
the restricted state and is required for operations like saving the system or reclaiming storage. If
two jobs are active in the controlling subsystem at the console, neither of the jobs is forced to end.
The End System (ENDSYS) command cannot complete running until you end one of the jobs either
by signing off in one job or by ending one job from the other.
All active subsystems are notified that an end system operation is in process. No new jobs or
routing steps can be accepted by the subsystems. This command also specifies what happens to
all active work.
Interactive jobs that are transferred to a job queue by the Transfer Job (TFRJOB) command are
ended as part of subsystem ending. If an initial program load (IPL) occurs while either a batch or
interactive job is on a job queue (because of the TFRJOB command), that job is removed from the
job queue during IPL and its job log is produced.
Since IBM i 7.1 Save and Restore menu options that bring the system to restricted state have been
enhanced to gracefully end TCP/IP servers.
Save menu options 21 (Save entire system), 22 (Save system data only), 23 (Save all user data)
and 40 (Save all libraries other than the system library) and Restore menu options 21 (Restore
entire system), 22 (Restore system data only), 23 (Restore all user data) and 40 (Restore all
libraries other than the system library) now include the following commands:
•ENDTCPSVR
•ENDHOSTSVR
•DLYJOB JOB(300)
•ENDTCP
•DLYJOB JOB(300)
before the ENDSBS SBS(*ALL) OPTION(*IMMED) command is issued

© Copyright IBM Corp. 1995, 2017 11-96


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HFRYHU\IURPDQXQVXFFHVVIXOUHVWRUH
‡ 5HVWRUHRSHUDWLRQIDLOXUHV

ƒ 5HVWRUHRSHUDWLRQHUURU

Or

ƒ 5HVWRUHRSHUDWLRQLQWHUUXSWHG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-68. Recovery from an unsuccessful restore

A restore operation can be unsuccessful either because an error was encountered when trying to
restore an object or because the operation was interrupted. If the object existed on the system
before the restore operation, it might be damaged by the unsuccessful restore operation.
An object is not restored when an error is encountered. The error is either recoverable or not.
If an object cannot be restored and the error is recoverable, the following occurs:
• A diagnostic message is sent to the job log for each object that is not restored. The message ID
can vary, depending on why the object was not restored.
• Each object that is associated with the errors is not restored. However, other objects not
associated with the errors but involved in the same restore operation are restored.
• Only the save and restore status information for the objects that were successfully restored is
updated.
• A count of the number of objects successfully restored and a count of the number of objects not
restored are sent to the user in a diagnostic message.

© Copyright IBM Corp. 1995, 2017 11-97


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
If the error is not recoverable, the following occurs:
• Diagnostic messages are sent to the job log for each object.
• The save and restore status information for each object is not updated.
• A diagnostic message that identifies the error condition is sent to the user.
• The restore command ends immediately. No other objects are restored.

© Copyright IBM Corp. 1995, 2017 11-98


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6SHFLDOFRQVLGHUDWLRQV
‡ 5HFRYHULQJ/,&

‡ 5HVWRULQJWKHRSHUDWLQJV\VWHP

‡ 6WDUWLQJWKHV\VWHPDIWHULWHQGVDEQRUPDOO\

‡ 5HFODLPLQJVWRUDJH

‡ 3DUDOOHOUHVWRUHRSHUDWLRQV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-69. Special considerations

Recovering Licensed Internal Code: Licensed Internal Code is the layer of IBM i architecture just
above the hardware. You must have the Licensed Internal Code on your machine before you can
restore the operating system. You must use the control panel on your system unit to start the
recovery of the Licensed Internal Code.
Restoring the Operating System: There might be situation where you must reload the operating
system. Some situations when you might have to reload the OS are when:
• You encounter problems with the operating system, such as damaged objects
• The System i software support center recommends it
• You replaced a disk unit in the system ASP
• You are updating your system to a new version or a new release
You need to retrieve the latest SAVSYS tapes from your storage location. Or, if these are
unavailable, you need original installation media. It is preferable that you use \SAVSYS tapes as
installing from the original media places your system back in a state without any of the previously
installed PTFs and also resets a number of system values and passwords.

© Copyright IBM Corp. 1995, 2017 11-99


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Starting the System after it ends abnormally: If your system stops without having time to shut
down normally, it is called an abnormal end. Your system might end abnormally for the following
reasons:
• A power failure
• A disk failure, if you do not have mirrored protection or device parity protection
• A failure in the processor
• Failure of a critical operating system program
• Operator action (forced power down)
You will need to determine what causes your system to abnormally shut down. Once you have
solved the problem that caused your system to stop, you must start it again. In some cases, you
start the initial program load (IPL) yourself. In other cases, such as a power loss, the system starts
automatically. When you start your system again after it ends abnormally, the system tries to put
things back in order. It closes files that were in use, rebuilds access paths that were open, and
verifies file constraints. This process can take a long time. If you want the system to determine
when to rebuild and verify, perform a normal (automatic) IPL to restart your system. If you want to
view and change the schedules for rebuilding access paths and verifying referential constraints,
follow the steps in System i Backup and Recovery Guide.
Reclaiming Storage: Use the reclaim storage procedure (RCLSTG command) to recover the
addressability of lost or damaged objects. This allows you to identify and then restore those objects
that were damaged. The RCLSTG command has two parameters, SELECT and OMIT that allow you
to perform reclaim functions in one of the following ways:
• All reclaim functions are performed
• The database cross-reference table reclaim function is performed
• All reclaim functions are performed, except for the database cross-reference table reclaim
function
Parallel Restore Operations: You can perform restore operations while using more than one tape
device simultaneously. The data that you restore in this manner must have been saved in parallel
format. You can use the Restore Library (RSTLIB) or Restore Object (RSTOBJ) commands in
conjunction with a media definition to perform a parallel restore.
It is possible to restore from a parallel save if you are using fewer devices than the save operation
used. Whenever possible, the same number of devices that were used during the save operation
should be used during a restore operation.

© Copyright IBM Corp. 1995, 2017 11-100


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

([HUFLVH6DYH5HVWRUH
‡ 8VHWKHSAVLIB FRPPDQGDQGH[SODLQZKDWWKHSUHFKHFN
SDUDPHWHULVXVHGWRFRQWURO
‡ 3HUIRUPWKHVDYHRI\RXUWHDPOLEUDU\XVLQJERWKWKH*Yes DQG
WKH*No LQWKHPRECHK SDUDPHWHU
‡ 3HUIRUPDVDYHXVLQJDYLUWXDOWDSHGULYH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-70. Exercise: Save/Restore

© Copyright IBM Corp. 1995, 2017 11-101


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
11.5. Topic 5: LPAR save/restore considerations

© Copyright IBM Corp. 1995, 2017 11-102


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

7RSLF/3$5VDYHUHVWRUH
FRQVLGHUDWLRQV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-71. Topic 5: LPAR save/restore considerations

© Copyright IBM Corp. 1995, 2017 11-103


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

/RJLFDOSDUWLWLRQV2YHUYLHZ
‡ Logical partitioning LVWKHDELOLW\WRPDNHDVHUYHUUXQ
DVLILWZHUHWZRRUPRUHLQGHSHQGHQWVHUYHUV
‡ %HQHILWV
ƒ &RQVROLGDWLQJVHUYHUV
ƒ 6KDULQJUHVRXUFHV
ƒ 0DLQWDLQLQJLQGHSHQGHQWVHUYHUV
ƒ &UHDWLQJDPL[HGSURGXFWLRQDQGWHVWHQYLURQPHQW
ƒ 0HUJLQJSURGXFWLRQDQGWHVWHQYLURQPHQWV
ƒ 5XQQLQJLQWHJUDWHGFOXVWHUV
‡ 7RROV
ƒ +0&
ƒ ,QWHJUDWHG9LUWXDOL]DWLRQ0DQDJHU VXSSRUWHGRQO\RQVSHFLILFVHUYHUPRGHOV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-72. Logical partitions: Overview

Logical partitioning is the ability to make a server run as if it were two or more independent servers.
When you logically partition a server, you divide the resources on the server into subsets called
logical partitions. You can install software on a logical partition, and the logical partition runs as an
independent logical server with the resources that you have allocated to the logical partition.
Consolidating servers: A logically partitioned server can reduce the number of servers that are
needed within an enterprise. You can consolidate several servers into a single logically partitioned
system. This eliminates the need for, and expense of, additional equipment.
Sharing resources: You can quickly and easily move hardware resources from one logical
partition to another as needs change. Technologies such as the Micro-Partitioning technology allow
for processor resources to be shared automatically among logical partitions that use a shared
processor pool. Similarly, the PowerVM Active Memory Sharing technology allows for memory
resources to be shared automatically among logical partitions that use the shared memory pool.
Other technologies, such as dynamic logical partitioning, allow for resources to be manually moved
to, from, and between running logical partitions without shutting down or restarting the logical
partitions.

© Copyright IBM Corp. 1995, 2017 11-104


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty
Maintaining independent servers: Dedicating a portion of the resources (disk storage unit,
processors, memory, and I/O devices) to a logical partition achieves logical isolation of software. If
configured correctly, logical partitions also have some hardware fault tolerance. Batch and 5250
online transaction processing (OLTP) workloads, which might not run well together on a single
machine, can be isolated and run efficiently in separate partitions.
Creating a mixed production and test environment: You can create a combined production and
test environment on the same server. The production logical partition can run your main business
applications, and the test logical partition is used to test software. A failure in a test logical partition,
while not necessarily planned, will not disrupt normal business operations.
Merging production and test environments: Partitioning enables separate logical partitions to be
allocated for production and test servers, eliminating the need to purchase additional hardware and
software. When testing has been completed, the resources allocated to the test logical partition can
be returned to the production logical partition or elsewhere as required. As new projects are
developed, they can be built and tested on the same hardware on which they will eventually be
deployed.
Running integrated clusters: Using high-availability application software, your partitioned server
can run as an integrated cluster. You can use an integrated cluster to protect your server from most
unscheduled failures within a logical partition.
Tools
Hardware Management Console: The Hardware Management Console (HMC) is a hardware or
virtual appliance that you can use to configure and control one or more managed systems. You can
use the HMC to create and manage logical partitions and activate Capacity Upgrade on Demand.
Using service applications, the HMC communicates with managed systems to detect, consolidate,
and send information to service and support for analysis. The HMC also provides terminal
emulation for the logical partitions on your managed system. You can connect to logical partitions
from the HMC itself, or you can set up the HMC so that you can connect to logical partitions
remotely through the HMC. Partition profile: A partition profile is a record on the Hardware
Management Console (HMC) that specifies a possible configuration for a logical partition. When
you activate a logical partition using a partition profile, the managed system attempts to start the
logical partition using the configuration information in the partition profile.
The Integrated Virtualization Manager is a browser-based system management interface for the
Virtual I/O Server. The Integrated Virtualization Manager provides you with the ability to create and
manage logical partitions on a single server. Virtual I/O Server is software that provides virtual
storage and shared Ethernet resources to the other logical partitions on the managed system.
Virtual I/O Server is not a general purpose operating system that can run applications. Virtual I/O
Server is installed on a logical partition in the place of a general purpose operating system, and is
used solely to provide virtual I/O resources to other logical partitions with general purpose operating
systems. You use the Integrated Virtualization Manager to specify how these resources are
assigned to the other logical partitions. The IVM is included with the Virtual I/O Server, but it is
available and usable only on certain platforms, and where no Hardware Management Console
(HMC) is present

© Copyright IBM Corp. 1995, 2017 11-105


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

+0&%DFNXS

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-73. HMC: Backup

To backup HMC data:


1. Logon to HMC with your user name and password.
2. On the left pane click HMC Management.
3. On the main pane click Backup Management Console Data.
4. Select destination for backup.
The HMC data stored on the HMC hard drive can be saved to a USB flash memory device on a
local system, a remote system mounted to the HMC file system (such as NFS), or sent to a remote
site using File Transfer Protocol (FTP).
To back up the HMC, you must have access as an operator, super administrator, or service
representative.
Back up the HMC after you make changes to the HMC or to the information associated with logical
partitions. In the case of a non-recoverable hard disk failure, the HMC needs to be reinstalled from
the HMC recovery CD.
As a part of this re-installation, you might be prompted to insert the back up media to restore the
HMC to the state that existed at the time of the last backup or access the remote restore functions.

© Copyright IBM Corp. 1995, 2017 11-106


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

+0&5HVWRUH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-74. HMC: Restore

To restore HMC data:


1. Logon to HMC with your user name and password.
2. On the left pane click HMC Management.
3. On the main pane click Restore Management Console Data.
4. Select source where from data will be restored.
Use this window to select the repository option to restore critical backup data for this HMC. Click
Next to continue.
Restore from remote NFS server: Select this option to restore your critical backup data from the
remote Network File System (NFS) server.
Restore from remote FTP server: Select this option to restore your critical backup data by using
the remote File Transfer Protocol (FTP) server.
Restore from remote SFTP server: Select this option to restore your critical backup data by using
the remote Secure Shell File Transfer Protocol (SFTP) server.
Restore from USB: Select this option to restore your critical backup data using USB device.

© Copyright IBM Corp. 1995, 2017 11-107


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

/3$5VDYHFRQVLGHUDWLRQV
‡ (DFKSDUWLWLRQEHKDYHVIXQFWLRQDOO\OLNHDVLQJOHV\VWHPRULQGLYLGXDO
V\VWHP
‡ (DFK/3$5PXVWEHVDYHGLQGLYLGXDOO\
‡ /3$5FRQILJXUDWLRQGDWDFDQQRWEHVDYHGXVLQJ,%0Lsave FRPPDQGV

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-75. LPAR save considerations

You can save all the partitions at the save time if sufficient hardware resources are available in
each partition.
The Hardware Management Console (HMC), must be backed up in addition to saving the individual
logical partitions.

© Copyright IBM Corp. 1995, 2017 11-108


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

6DYLQJ/3$5V&RQVLGHUDWLRQV
‡ (DFK/3$5EHKDYHVDVDQLQGLYLGXDO
VWDQGDORQHV\VWHPLQFOXGLQJ/,&DQG
RSHUDWLQJV\VWHP SAVSYS 

‡ <RXFDQSHUIRUPVDYHVRIGLIIHUHQW
SDUWLWLRQVRQWKHVDPHV\VWHPDWWKH
VDPHWLPH
ƒ $VVXPLQJHDFKSDUWLWLRQKDVWKH
UHVRXUFHVVXFKDVDQDYDLODEOHWDSHGULYH
ƒ <RXFRXOGVHWXSDQGXVHDYLUWXDOWDSH )LUVWSDUWLWLRQ
GULYH

6HFRQGSDUWLWLRQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-76. Saving LPARs: Considerations

© Copyright IBM Corp. 1995, 2017 11-109


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

/3$5UHVWRULQJ&RQVLGHUDWLRQV
‡ 7KHVDYHGGDWDRIIRIDSDUWLWLRQFDQEHUHVWRUHGWR
ƒ 6DPHSDUWLWLRQRQWKHVDPHV\VWHP
ƒ $QRWKHUSDUWLWLRQRQWKHVDPHV\VWHP
ƒ $QRWKHUSDUWLWLRQRQDQRWKHUV\VWHP
ƒ $QRQSDUWLWLRQHGV\VWHP

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-77. LPAR restoring: Considerations

© Copyright IBM Corp. 1995, 2017 11-110


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HVWRUHIRU/3$5V
‡ 5HVWRUHLVGRQHRQDSDUWLWLRQE\SDUWLWLRQEDVLV
ƒ 7KHUHLVQRV\VWHPZLGHUHVWRUHRSWLRQIRUDOO/3$5V

‡ 5HVWRULQJPXOWLSOHSDUWLWLRQVFDQEHGRQHLQSDUDOOHO
ƒ 7KLVLVDVVXPLQJQHFHVVDU\GHYLFHV IRUH[DPSOHWDSHGULYHV DUHDYDLODEOH

‡ 5HFRYHU\IRU/3$5VLVDWZRVWDJHSURFHVV
ƒ 6WHS 5HFRYHUWKHSDUWLWLRQ DW+0&EHVXUHWRDFWLYDWHWKHFRUUHFW
SURILOH 
ƒ 6WHS 5HVWRUHWKHV\VWHPDQGXVHUGDWDIRUHDFK/3$5

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-78. Restore for LPARs

© Copyright IBM Corp. 1995, 2017 11-111


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

',3/RISDUWLWLRQIURP+0&

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-79. D: IPL of partition from HMC

To start partition from tape or DVD you have to:


1. Logon to HMC with your user name and password.
2. On the left pane expand System Management and then expand Servers.
3. On the left pane select and click your server.
4. From the partition on the main pane select yours and click double arrow next to the name.
5. From the pop-up menu select Operations and then Activate and Profile.
6. On the Activate Logical Partition dialog click Advanced button.
7. For keylock position setup Manual for IPL type D: IPL from the alternate load
source (CD or tape) for install.
Note you have to open the 5250 console to avoid receiving a SRC A6005008 - DST console failed
to respond.

© Copyright IBM Corp. 1995, 2017 11-112


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH,GHDOO\REMHFWVRQ\RXUV\VWHPVKRXOGEH
VDYHGIUHTXHQWO\ZKLOHWKH\DUHRQO\UHVWRUHGLQIUHTXHQWO\

 7KHFRPPDQGXVHGWRPDQDJHWKHVWDWXVRI\RXUWDSH
GHYLFHVLV EODQN 
a. WRKMLBSTS
b. WRKTAPSTS
c. WRKCFGSTS
d. MNGTAPSTS

 7KHFRPPDQGXVHGWRPDQDJHWKHVWDWXVRI\RXUWDSHOLEUDU\
GHYLFHVLV EODQN 
a. WRKMLBSTS
b. WRKTAPSTS
c. WRKCFGSTS
d. MNGTAPSTS

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-80. Review questions (1 of 3)

© Copyright IBM Corp. 1995, 2017 11-113


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH,GHDOO\REMHFWVRQ\RXUV\VWHPVKRXOGEH
VDYHGIUHTXHQWO\ZKLOHWKH\DUHRQO\UHVWRUHGLQIUHTXHQWO\
7KHDQVZHULVWUXH

 7KHFRPPDQGXVHGWRPDQDJHWKHVWDWXVRI\RXUWDSH
GHYLFHVLVWRKCFGSTS
a. WRKMLBSTS
b. WRKTAPSTS
c. WRKCFGSTS
d. MNGTAPSTS
7KHDQVZHULVWRKCFGSTS

 7KHFRPPDQGXVHGWRPDQDJHWKHVWDWXVRI\RXUWDSH
OLEUDU\GHYLFHVLVWRKMLBSTS
a. WRKMLBSTS
b. WRKTAPSTS
c. WRKCFGSTS
d. MNGTAPSTS
7KHDQVZHULVWRKMLBSTS
%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-81. Review answers (1 of 3)

© Copyright IBM Corp. 1995, 2017 11-114


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH7KHSAVCHGOBJ FRPPDQGGRHVQRWUHTXLUH
WKDWDQ\RWKHUFRPPDQGKDVEHHQSUHYLRXVO\XVHGLIWKLV
FRPPDQGLVXVHGLQ\RXUVDYHVWUDWHJ\

 7UXHRUIDOVH7KHSAVSYSINF FRPPDQGLVWKHQHZ
FRPPDQGWKDWLVDUHSODFHPHQWIRUWKHSAVSYS FRPPDQG

 7KHFRPPDQGSDUDPHWHUWKDWDOORZV\RXWRVDYHGDWDZKLOH
XVHUVDUHVWLOOZRUNLQJZLWKWKDWGDWDLV EODQN 
a. ACTDTA
b. SYSDTA
c. ACTSAV
d. SAVACT

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-82. Review questions (2 of 3)

© Copyright IBM Corp. 1995, 2017 11-115


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH7KHSAVCHGOBJ FRPPDQGGRHVQRWUHTXLUH
WKDWDQ\RWKHUFRPPDQGKDVEHHQSUHYLRXVO\XVHGLIWKLV
FRPPDQGLVXVHGLQ\RXUVDYHVWUDWHJ\
7KHDQVZHULVIDOVH

 7UXHRUIDOVH7KHSAVSYSINF FRPPDQGLVWKHQHZ
FRPPDQGWKDWLVDUHSODFHPHQWIRUWKHSAVSYS FRPPDQG
7KHDQVZHULVIDOVH

 7KHFRPPDQGSDUDPHWHUWKDWDOORZV\RXWRVDYHGDWDZKLOH
XVHUVDUHVWLOOZRUNLQJZLWKWKDWGDWDLVSAVACT
a. ACTDTA
b. SYSDTA
c. ACTSAV
d. SAVACT
7KHDQVZHULVSAVACT

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-83. Review answers (2 of 3)

© Copyright IBM Corp. 1995, 2017 11-116


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH7KH5HVWRUHPHQXRSWLRQZLOOSHUIRUPD
GLUHFWRSSRVLWHRIWKH6DYHPHQXRSWLRQ5HVWRUHRSWLRQ
ZLOOUHVWRUHWKHHQWLUHV\VWHP

 7UXHRUIDOVH,WLVSRVVLEOHWRVDYHDOORIWKHXVHUGDWD
DFURVVDOORIWKH/3$5VRQDV\VWHPXVLQJRQHVLQJOH
FRPPDQG

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-84. Review questions (3 of 3)

© Copyright IBM Corp. 1995, 2017 11-117


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH7KH5HVWRUHPHQXRSWLRQZLOOSHUIRUPD
GLUHFWRSSRVLWHRIWKH6DYHPHQXRSWLRQ5HVWRUHRSWLRQ
ZLOOUHVWRUHWKHHQWLUHV\VWHP
7KHDQVZHULVIDOVH

 7UXHRUIDOVH,WLVSRVVLEOHWRVDYHDOORIWKHXVHUGDWDDFURVV
DOORIWKH/3$5VRQDV\VWHPXVLQJRQHVLQJOHFRPPDQG
7KHDQVZHULVIDOVH

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-85. Review answers (3 of 3)

© Copyright IBM Corp. 1995, 2017 11-118


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 11. Backup and recovery strategy using save/restore

Uempty

8QLWVXPPDU\
‡ /LVWWKHGLIIHUHQWW\SHVRIIDLOXUHVWKDWFDQRFFXURQWKHV\VWHP
‡ /LVWWKHGLIIHUHQWPHGLDW\SHVWKDWFDQEHXVHGIRUEDFNXSRI\RXUGDWD
‡ 3HUIRUPWKHVWHSVUHTXLUHGWRVHWXSDQGXVHDYLUWXDOWDSHGULYH
‡ ([SODLQZKLFKFRPPDQGVDUHXVHGWRVDYHZKLFKW\SHVRIGDWD
‡ ([SODLQWKHGLIIHUHQFHEHWZHHQWKHSAVSYS DQGSAVSYSINF FRPPDQG
‡ ,GHQWLI\WKHSURFHGXUHVXVHGWRVDYHDQGUHVWRUHGLIIHUHQWW\SHVRI
V\VWHPLQIRUPDWLRQ

%DFNXSDQGUHFRYHU\VWUDWHJ\XVLQJVDYHUHVWRUH ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 11-86. Unit summary

© Copyright IBM Corp. 1995, 2017 11-119


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

Unit 12. Journal management


Estimated time
01:30

Overview
Journal management is a very valuable and powerful tool, which is an integral part of the operating
system. When used properly as part of a comprehensive recovery plan, it significantly improves the
ability of the administrator to recover from many types of job and system failures.

How you will check your progress


• Review questions
• Exercise

© Copyright IBM Corp. 1995, 2017 12-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHKRZMRXUQDOPDQDJHPHQWFDQEHXVHGWRUHFRYHUGDWDORVW
GXULQJDIDLOXUH
‡ ,PSOHPHQWMRXUQDOPDQDJHPHQWRQ,%0LDVSDUWRIDFRPSUHKHQVLYH
UHFRYHU\SODQ
‡ /LVWWKHDGYDQWDJHVDQGFRQVLGHUDWLRQVRIMRXUQDOPDQDJHPHQW
‡ /LVWWKHDGYDQWDJHVDQGFRQVLGHUDWLRQVRIMRXUQDOLQJDFFHVVSDWKV
‡ 'HVFULEHUHPRWHMRXUQDOLQJDQGKRZLWFDQEHXVHGWRUHSOLFDWHGDWDRU
WRLPSOHPHQWDKRWEDFNXSHQYLURQPHQWRQDUHPRWHV\VWHP

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 12-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.1. Topic 1: Journal management concepts

© Copyright IBM Corp. 1995, 2017 12-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF-RXUQDOPDQDJHPHQW
FRQFHSWV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-2. Topic 1: Journal management concepts

© Copyright IBM Corp. 1995, 2017 12-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7KLQNDERXW\RXUPRVWLPSRUWDQWGDWDILOH

'DWDILOH

‡ :KDWLILWGLVDSSHDUHG"
‡ +RZZRXOG\RXJHWLWEDFN"
ƒ RSTOBJ
ƒ 5HNH\DOOGDWDIURPODVWVDYHSOXVGDWDVLQFHODVWVDYH
‡ +RZPXFKWLPHZRXOGLWWDNH"
‡ 'R\RXQHHGWRVKRUWHQWKHUHFRYHU\WLPHIRUGDWDILOHV"

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-3. Think about your most important data file

© Copyright IBM Corp. 1995, 2017 12-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6LQJOHOHYHOVWRUDJH
21

2))

9RODWLOHVWRUDJH
0DLQPHPRU\ 1 6

*PGM 0DJQHWLFVWRUDJH 2UVROLGVWDWH


GLVNGULYHV GLVNGULYHV
'HOHWH
8SGDWH
:ULWH 

*JRNRCV
*JRN
%XIIHU 'LVN )LOH$ )LOH$ )LOH$
,2
 

'DWDILOH
VFDWWHUORDGLQJ
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-4. Single-level storage

Journal management enables you to recover the changes to an object that have occurred since the
object was last saved. You can also use journal management to provide an audit trail or to help
replicate an object. You use a journal to define what objects you want to protect with journal
management. The system keeps a record of changes you make to objects that are journaled and of
other events that occur on the system.
1. Journal management intercepts the database record (add, update, or delete).
2. Journal entry is forced to the journal receiver on a disk with a force ratio of one.
3. The database record is given to database data management.
4. The database record is written to disk FRCRATIO(*NONE) is recommended for journaled files.

© Copyright IBM Corp. 1995, 2017 12-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

-RXUQDOREMHFWV
-RXUQDOLQJGDWDIORZ

3*0; 3*0<

2EMHFW$ 2EMHFW% 2EMHFW% 2EMHFW&


FKDQJH FKDQJH FKDQJH FKDQJH

-RXUQDO
UHFHLYHU

2EMHFW$FKDQJH
2EMHFW%FKDQJH
2EMHFW%FKDQJH
2EM$ 2EM% 2EM&

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-5. Journal objects

The system keeps a record of changes you make to objects that are journaled and of other events
that occur on the system. These records are called journal entries. You can also write journal
entries for events that you want to record, or for objects other than the object that you want to
protect with journaling.
Contents of a journal entry:
• Information identifying the type of change
• Information identifying the record that was changed
• After image of the record
• Before image of the record (optional) (this is a separate journal entry)
• Information identifying the job, the user, the time of change, and so forth
• Information that identifies whether the file was opened, closed, reorganized, cleared, or saved
• The journal identifier of the object

© Copyright IBM Corp. 1995, 2017 12-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

2EMHFWVWKDWFDQEHMRXUQDOHG
‡ $ELOLW\WRUHFRUGFKDQJHVLQWRDMRXUQDORI
ƒ $FFHVVSDWKV
ƒ /LEUDULHV
ƒ 2EMHFWV
í 'DWDDUHD DTAARA
í 'DWDTXHXH DTAQ
ƒ 'DWDEDVHSK\VLFDOILOHV PF
ƒ ,)6REMHFWV
í 6WUHDPILOHV STMF
í 'LUHFWRULHV DIR
í 6\PEROLFOLQN SYMLNK 
ƒ 1RWH ,)6REMHFWVPXVWEHLQWKHURRW / 42SHQV\VXVHUGHILQHGILOH
V\VWHP

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-6. Objects that can be journaled

An interface is available to start and stop the replication of byte stream files. The changes to these
objects are recorded in a local journal. With remote journal support, the changes will also be
transported to a backup system. The primary target is for those environments needing synchronous
replication of the objects for continuous availability. The targeted usage represents an autonomous
operation from the end user perspective. The overall goal is to support replication, which is defined
as trapping changes, recording those changes, transporting changed data to a backup system, and
then replaying the changes on the backup system. This enhancement in order to support
synchronous or asynchronous replication of a byte stream file, contains the following capabilities:
• Function to start replication and end replication
• Means of knowing which objects are being replicated
• Means of associating the recorded and transported changes with the appropriate object hooks
at relevant points to record and transport changes
• Transport mechanism
• Repository for recording the changes to the object
• Mechanism for selectively pulling the recorded changes out of the repository (so, for example,
they can be replayed against a replicate)

© Copyright IBM Corp. 1995, 2017 12-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
For IFS the Start Journal (STRJRN) command is used to start journaling changes (made to an
object or list of objects) to a specific journal. The object types, which are supported through this
interface are Data Areas (*DTAARA), Data Queues (*DTAQ), Stream Files (*STMF), Directories
(*DIR), and Symbolic Links (*SYMLNK).
Only objects of type *STMF, *DIR or *SYMLNK that are in the “root” (/), QOpenSys, and permanent
user-defined file systems are supported.

© Copyright IBM Corp. 1995, 2017 12-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO(QWULHV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-7. Display Journal Entries

The Display Journal (DSPJRN) command allows you to convert journal entries (contained in one or
more receivers) into a form suitable for external representation. Output of the command can be
displayed or printed with the job's spooled printer output or directed to a database output file. If the
database output file exists, records can either replace or be added to the current data in the
indicated file member. The system creates the specified database file and member if they do not
exist. Database files created by the system have a standard format. A warning message is sent and
the records are truncated if any of the entries are longer than the specified maximum record length
of the output files.
The Display Journal display shows a list of the journal entries that you requested to be displayed.
Only basic information about the journal entry is shown on this display. From this display, you can
request to see all of the information for a specific journal entry.
To see all of the information for a specific journal entry, type 5 next to the journal entries that you
want more information about, and press Enter.

© Copyright IBM Corp. 1995, 2017 12-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO(QWU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-8. Display Journal Entry

The Display Journal Entry display shows all of the information about a specific journal entry. The
journal entry shown is one that you requested on the Display Journal display.
Sequence - The journal sequence number
The sequence number is initially 1. Each journal entry is sequentially numbered without any breaks
until the Change Journal (CHGHRN) command resets the sequence number. However, when journal
entries are converted and displayed, there might be breaks in the sequence numbers. The system
uses some journal entries only internally and combines some entries into one during conversion.
Incomplete data
Indicates whether this entry has entry specific data, which is not being displayed for one of the
following reasons.
• The length of the entry-specific data exceeds 32,766 bytes.
• The entry is associated with a database file that has one or more fields of data type BLOB
(binary large object), CLOB (character large object), or DBCLOB (double-byte character large
object).
• The possible values are:
▪ No - This entry has all possible data

© Copyright IBM Corp. 1995, 2017 12-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
▪ Yes - This entry has incomplete data
The data, which is not visible through this interface can only be accessed by using the Retrieve
Journal Entries (QjoRetreiveJournalEntries) API or by specifying ENTFMT (*TYPEPTR) on the
RCVJRNE command.
Entry-specific data
This is additional information about the entry. The contents of this field are dependent on the kind of
journal entry. If there is no entry-specific data for the kind of entry being shown, the message No
Entry specific data is shown in this field. The information shown in this field is not formatted.

© Copyright IBM Corp. 1995, 2017 12-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

) 'LVSOD\RQO\HQWU\GHWDLOV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-9. F10 = Display only entry details

The Display Journal Entry Details display shows only the detail entry data for a specific journal
entry. The journal entry shown is one that you requested on the Display Journal display.
If you see More... on the lower right side of your display, there is more information to view. Press
Page Down (or Roll Up) to move toward the end of the information. Press Page Up (or Roll Down)
to move toward the beginning of the information.

© Copyright IBM Corp. 1995, 2017 12-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.2. Topic 2: Steps to implement journaling

© Copyright IBM Corp. 1995, 2017 12-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF6WHSVWRLPSOHPHQW
MRXUQDOLQJ

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-10. Topic 2: Steps to implement journaling

© Copyright IBM Corp. 1995, 2017 12-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

,PSOHPHQWLQJMRXUQDOLQJ
‡ )RUH[DPSOH,PSOHPHQWDWLRQRIREMHFWMRXUQDOLQJ

 &UHDWHWKHMRXUQDOUHFHLYHU
CRTJRNRCV JRNRCV( )

 &UHDWHWKHMRXUQDO
CRTJRN JRN( ) JRNRCV( )

 6WDUWMRXUQDOLQJIRUVHOHFWHGREMHFWV
STRJRNOBJ OBJ( ) JRN( )

 6DYHWKHREMHFWV

‡ 7KDWLVLW

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-11. Implementing journaling

The Create Journal Receiver (CRTJRNRCV) command creates a journal receiver. Once a journal
receiver is attached to a journal (with the Create Journal (CRTJRN) or Change Journal (CHGJRN)
command), journal entries can be placed in it. A preferred auxiliary storage pool (ASP), and a
storage space threshold value can be specified for the journal receiver.
The Create Journal (CRTJRN) command creates a journal as a local journal with the specified
attributes, and attaches the specified journal receiver to the journal. Once a journal is created,
object changes can be journaled to it or user entries can be sent to it. The journal state of the
created journal is *ACTIVE.
The different types of objects that can be journaled and the commands that you will use are:
• Start to Journal an Access Path (STRJRNAP) command is used to start journaling the access
paths for all members of a database file to a specified journal. Any new member that is later
added to the file also has its access path journaled.
• Start to Journal a Library (STRJRNLIB) command is used to start journaling changes (made to a
library or list of libraries) to a specific journal, and optionally to start journaling changes to
objects within the library or list of libraries. Objects created in, moved into, or restored into a
journaled library can be automatically journaled to the same journal the library is journaled to.

© Copyright IBM Corp. 1995, 2017 12-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
• Start to Journal an Object (STRJRNOBJ) command is used to start journaling changes (made to
an object or list of objects) to a specific journal. The object types, which are supported through
this interface are Data Areas (*DTAARA) and Data Queues (*DTAQ).
• Start to Journal a Physical File (STRJRNPF) command is used to start journaling changes made
to a specific database physical file to a specific journal. Changes in new members added to the
file are also journaled.
• Start to Journal IFS Objects (STRJRN) command is used to start journaling changes (made to
an object or list of objects) to a specific journal. The object types, which are supported through
this interface are Stream Files (*STMF), Directories (*DIR), and Symbolic Links (*SYMLNK).
Only objects of type *STMF, *DIR, or *SYMLNK that are in the “root” (/), QOpenSys, and
user-defined file systems are supported.

© Copyright IBM Corp. 1995, 2017 12-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHS&57-515&9FRPPDQG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-12. Step 1: CRTJRNRCV command

It is recommended that the journal receiver name should be unique for your system, not unique
within a library. If you have two journal receivers with the same name in different libraries and they
both become damaged, RCLSTG renames both journal receivers when they are placed in the
QRCL library.
The Create Journal Receiver (CRTJRNRCV) command creates a journal receiver. Once a journal
receiver is attached to a journal (with the Create Journal (CRTJRN) or Change Journal (CHGJRN)
command), journal entries can be placed in it. A preferred auxiliary storage pool (ASP), and a
storage space threshold value can be specified for the journal receiver.
Restrictions
• A Journal receiver cannot be created in library QTEMP.
• This command cannot be used to create a journal receiver for a remote journal.
• If the library to contain the journal receiver is on an independent ASP, then ASP(*LIBASP) must
be specified.

© Copyright IBM Corp. 1995, 2017 12-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHS&57-51FRPPDQG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-13. Step 2: CRTJRN command

The Create Journal (CRTJRN) command creates a journal as a local journal with the specified
attributes, and attaches the specified journal receivers to the journal. Once a journal is created,
object changes can be journaled to it or user entries can be sent to it. The journal state of the
created journal is *ACTIVE.
Restrictions
1. A journal cannot be created in the library QTEMP.
2. The specified journal receivers must be created before the running of this command and they
must be empty. That is, the receivers must not have been previously attached to a journal or
have been in the process of being attached to a journal.
3. This command cannot be used to create a remote journal. See the Add Remote Journal
(QjoAddRemoteJournal) API in the IBM i Knowledge Center at
[Link]
4. If the library to contain the journal is on an independent ASP, then the journal receiver specified
must be located on an independent ASP that is in the same ASP group as the journal's library.
Likewise, if the library to contain the journal is not on an independent ASP, then the journal
receiver specified cannot be located on an independent ASP.
5. If the library to contain the journal is on an independent ASP, then ASP(*LIBASP) must be
specified

© Copyright IBM Corp. 1995, 2017 12-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHSD$FFHVVSDWKFRPPDQG 675-51$3

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-14. Step 3a: Access path command (STRJRNAP)

The Start Journal Access Path (STRJRNAP) command is used to start journaling the access paths
for all members of a database file to a specified journal. Any new member that is later added to the
file also has its access path journaled.
If a physical file is specified, journaling can be started for its access paths. When access path
journaling is started for a physical file, only the access paths for the physical file members are
journaled. Journaling for any logical file access paths is started only when access path journaling is
started for the logical file.
The journal entries created after running this command cannot be used in any apply or remove
journaled changes operation. These entries are used only to recover the access path without
rebuilding it after an abnormal system operation ending.
If you do not want the overhead of managing the access path journaling yourself, consider taking
advantage of the system-managed access-path protection support SMAPP, which will be covered
later in this unit.

© Copyright IBM Corp. 1995, 2017 12-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHSE/LEUDU\FRPPDQG 675-51/,%

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-15. Step 3b: Library command (STRJRNLIB)

The Start Journal Library (STRJRNLIB) command is used to start journaling changes (made to a
library or list of libraries) to a specific journal, and optionally to start journaling changes to objects
within the library or list of libraries. Objects created in, moved into, or restored into a journaled
library might be automatically journaled to the same journal the library is journaled to.
After journaling begins for the object, the user should save the journaled object to preserve its
journal attribute information. Also, the object must be saved because, for example, journaled
changes cannot be applied to a version of the object that was saved before journaling was in effect.
Objects created, moved, or restored into the library that are eligible for journaling might
automatically start journaling to the same journal as the library. Which objects inherit the journal
state of the library and what journaling attributes they start journaling with are determined by the
inherit journaling attributes of the library.

© Copyright IBM Corp. 1995, 2017 12-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHSF2EMHFWFRPPDQG 675-512%-

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-16. Step 3c: Object command (STRJRNOBJ)

The Start Journal Object (STRJRNOBJ) command is used to start journaling changes (made to an
object or list of objects) to a specific journal. The object types, which are supported through this
interface are Data Areas (*DTAARA) and Data Queues (*DTAQ).
Additionally, the user can specify that only the after image or both the before and the after images
of an object of type *DTAARA be journaled. Before images are necessary to remove journaled
changes using the Remove Journaled Changes (RMVJRNCHG) command.
After journaling begins for the object, the user should save the journaled object to preserve its
journal attribute information. Also, the object must be saved because, for example, journaled
changes cannot be applied to a version of the object that was saved before journaling was in effect.

© Copyright IBM Corp. 1995, 2017 12-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHSG3K\VLFDOILOHFRPPDQG 675-513)

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-17. Step 3d: Physical file command (STRJRNPF)

The Start Journal Physical File (STRJRNPF) command is used to start journaling changes made to
a specific database physical file to a specific journal. Changes in new members added to the file
are also journaled.
The user can specify that only the after image or both the before and after images of records in the
journaled physical file be journaled. Before images are necessary to remove journaled changes
using the Remove Journaled Changes (RMVJRNCHG) command. In addition, the system will
automatically capture the before images for a database file if the file is opened under commitment
control.
After journaling begins for the file, and after any new members are added to the file, the user should
run the Save Changed Object (SAVCHGOBJ) command with OBJTYPE(*FILE) and OBJJRN(*YES)
specified. The file must be saved because journaled changes cannot be applied to a version of the
file that was saved before journaling was in effect.
When the file being journaled is a distributed file, the STRJRNPF command is also distributed, if
journaling was successfully started locally. Even if the distribution request fails, the local file
remains journaled.

© Copyright IBM Corp. 1995, 2017 12-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6WHSH,)6REMHFWFRPPDQG 675-51

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-18. Step 3e: IFS object command (STRJRN)

The Start Journal (STRJRN) command is used to start journaling changes (made to an object or list
of objects) to a specific journal. The object types, which are supported through this interface are
Stream Files (*STMF), Directories (*DIR), and Symbolic Links (*SYMLNK). Only objects of type
*STMF, *DIR or *SYMLNK that are in the “root” (/), QOpenSys, and user-defined file systems are
supported.
The user can specify that only the after image or both the before and the after images of an object
of type *DTAARA be journaled. Before images are necessary to remove journaled changes using
the Remove Journaled Changes (RMVJRNCHG) command.
After journaling begins for the object, the user should save the journaled object to preserve its
journal attribute information. Also, the object must be saved because, for example, journaled
changes cannot be applied to a version of the object that was saved before journaling was in effect.

© Copyright IBM Corp. 1995, 2017 12-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

,%01DYLJDWRUIRUL-RXUQDOLQJ0DQDJHPHQW RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-19. IBM Navigator for i: Journaling Management (1 of 2)

You can also create or manage journaling using IBM Navigator for i to do this you have to:
1. Log on to system using web browser [Link] address or system name>:2001.
2. On the left pane, click Journal Management - here you can manage journals.
3. On the left pane under Journal Management, you can expand All Tasks - here you can find
option to create receivers.

© Copyright IBM Corp. 1995, 2017 12-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

,%01DYLJDWRUIRUL-RXUQDOLQJ0DQDJHPHQW RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-20. IBM Navigator for i: Journaling Management (2 of 2)

You can also create or manage journaling for selected schema using IBM Navigator for i to do this
you have to:
1. Log on to system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Database and then expand Databases and expand your database -
the name can be the same as the system name. If you have Independent ASP the second
database will be named with IASP name.
3. Under database click Schemas and in the main pane click Action and from pop-up menu
select Select Schemas to Display and using Add button add your schema.
4. On the left pane under Schemas click your schemas name.
5. On the main pane you will see different type of objects there you can find Journals and
Journal Receivers link to manage them.

© Copyright IBM Corp. 1995, 2017 12-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6DYHREMHFWV
‡ :KHQ"
ƒ ,PPHGLDWHO\DIWHUSTRJRNxx RULIDQHZPHPEHULVDGGHGWRWKHILOH

‡ :K\"
ƒ &KHFNSRLQWIRUUHFRYHU\ )06MRXUQDOHQWU\
í 5HVWRUHGDPDJHGREMHFW
í $SSO\MRXUQDOHGFKDQJHVIURP LASTSAVE

‡ 0XVWKDYHWKHV\VWHPDVVLJQHGMRXUQDOLGHQWLILHU -,' LQHYHU\VDYHG


PHPEHUXVHGIRUUHFRYHU\DIWHUDUHVWRUH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-21. Save objects

When you start journaling for a physical file, the system assigns a unique journal identifier (JID) to
every member. The JID is part of every journal entry for the file.
The JID is used to associate the journal entry with the file. If a file is saved before journaling is
started, it does not have a JID, and if the file is restored it does not have a JID.
It is critical to save a journaled file every time a member has been added to it.

© Copyright IBM Corp. 1995, 2017 12-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.3. Topic 3: Journal receiver considerations

© Copyright IBM Corp. 1995, 2017 12-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF-RXUQDOUHFHLYHU
FRQVLGHUDWLRQV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-22. Topic 3: Journal receiver considerations

© Copyright IBM Corp. 1995, 2017 12-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

0DQDJLQJWKHUHFHLYHUFKDLQ

CHGJRN JRN(name) JRNRCV(*GEN) MNGRCV(*USER)


SEQOPT(*CONT or*RESET)

3*0

5&9
2OG
UHFHLYHU
5&9
&XUUHQW
UHFHLYHU
)LOH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-23. Managing the receiver chain

The Change Journal (CHGJRN) command changes the journal receiver, the journal message queue,
the manage receiver attribute, the delete receiver attribute, the receiver size options, the journal
state, allowing minimized entry specific data, journal caching, the journal receiver's threshold, the
journal object limit, the journal recovery count, or the text associated with the specified journal. The
command allows one journal receiver to be attached to the specified journal. This replaces the
previously attached journal receiver. The newly attached journal receiver begins receiving journal
entries for the journal immediately.
The sequence numbering of journal entries can be reset when the receiver is changed. If the
sequencing is not reset, an informational message is sent indicating the first sequence number in
the newly attached receiver.
The Manage receivers (MNGRCV) parameter is used to specify how the changing of journal
receivers (detaching the currently attached journal receiver and attaching a new journal receiver) is
managed. You can specify a value for the MNGRCV parameter for both the CRTJRN and the CHGJRN
commands.

© Copyright IBM Corp. 1995, 2017 12-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
For this parameter you can specify:
*USER
The user manages the changing of journal receivers by issuing the Change Journal (CHGJRN)
command to attach new receivers and detach old receivers.
*SYSTEM
• The system manages the changing of journal receivers. This function is called system
change-journal management.
• When an attached journal receiver reaches its size threshold, the system detaches the attached
journal receivers and creates and attaches new journal receivers. Message CPF7020 is sent to
the journal message queue when the journal receivers are detached.
• Additionally, during an initial program load (IPL), the system performs a CHGJRN command to
create and attach new journal receivers and to reset the journal sequence number of journals
that are not needed for commitment control recovery for that IPL.
• Also, the system attempts to perform a CHGJRN command to reset the sequence numbers
when the journal receiver's sequence number exceeds 9,900,000,000 for
RCVSIZOPT(*MAXOPT1 or *MAXOPT2) or 18,446,644,000,000,000,000 for
RCVSIZOPT(*MAXOPT3). For all other journal receivers, the system attempts this CHGJRN
when the sequence number exceeds 2,147,000,000.

© Copyright IBM Corp. 1995, 2017 12-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6\VWHPFKDQJHMRXUQDOPDQDJHPHQW
• CRTJRN ... MNGRCV(*SYSTEM)
ƒ 7KUHVKROG5HFHLYHUFKDQJHGDXWRPDWLFDOO\DQGPHVVDJHVHQW
ƒ ,3/5HFHLYHUFKDQJHGDXWRPDWLFDOO\ZLWKVHTXHQFHQXPEHUUHVHW

• CRTJRN ... MNGRCV(*SYSTEM) DLTRCV(*YES)


ƒ 'HWDFKHGUHFHLYHUDXWRPDWLFDOO\GHOHWHGDVVRRQDVLWLVQRWQHHGHGIRU
UHFRYHULQJDFFHVVSDWKVRUUROOLQJEDFNXQFRPPLWWHGFKDQJHV
ƒ &DXWLRQ -RXUQDOUHFHLYHUVGHOHWHGDXWRPDWLFDOO\DQGZLWKRXWVHQGLQJWKH
XVXDOLQTXLU\PHVVDJHWKDWLWKDVQRWEHHQVDYHG

• DLTRCV(*YES) XVHV
ƒ -RXUQDOLQJIRUFRPPLWPHQWFRQWURORUH[SOLFLWDFFHVVSDWKSURWHFWLRQ
ƒ -RXUQDOUHFHLYHULVEHLQJUHSOLFDWHGWKURXJKUHPRWHMRXUQDO

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-24. System change journal management

The Manage receivers (MNGRCV) parameter is used to specify how the changing of journal
receivers (detaching the currently attached journal receivers and attaching new journal receivers) is
managed. The possible values are *USER or *SYSTEM.
The Delete receivers (DLTRCV) parameter is used to specify whether the system deletes journal
receivers when they are no longer needed or leaves them on the system for the user to delete after
they have been detached by system change-journal management or by a user-issued CHGJRN
command.

Note

This parameter can be specified only if MNGRCV(*SYSTEM) is specified.

The possible values are:


*NO
The journal receivers are not deleted by the system. It is underlined because it is the default value
for this parameter.

© Copyright IBM Corp. 1995, 2017 12-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
*YES
The journal receivers are deleted by the system.
When the journal has the DLTRCV(*YES) attribute, the following conditions can prevent the system
from deleting the receiver. When one of these conditions occurs, the system sends message
CPI70E6 to the journal message queue, and then retries the delete operation every 10 minutes
until the operation is successful.
• A lock conflict occurs for either the journal receiver or its journal
• An exit program that was registered by way of the QIBM_QJO_DLT_JRNRCV exit point
indicates that a receiver is not eligible for deletion
• A journal has remote journals associated with it and one or more of the associated remote
journals do not yet have full copies of this receiver

Important

Use automatic deletion of journal receivers with care if you use save-while-active operations to
save objects before they reach a commitment boundary. Ensure that you save the journal receivers
before the system deletes them. If an object is saved before it reaches a commitment boundary it
can have partial transactions. To avoid data loss, you must have access to the journal receivers that
were attached during the save-while-active operation when you restore the objects with partial
transactions.

© Copyright IBM Corp. 1995, 2017 12-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

-RXUQDOUHFHLYHUFKDLQ

- 35 5&9

5&9
- 15 5&9

- 35 5&9

5&9
- 15 5&9

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-25. Journal receiver chain

Journal receivers that are associated with a journal (that is presently or previously attached to the
journal) are linked in one or more receiver chains. Each journal receiver, except the first one, has
a previous receiver that was detached when the current receiver was attached. Each journal
receiver, except the one that is currently attached, also has a next receiver.
PR stands for previous receiver.
NR stands for next receiver.
The PR and NR entries are automatically added when a receiver is created or changed. They are
used by the system to make recovery seamless across a journal receiver chain.

© Copyright IBM Corp. 1995, 2017 12-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

:5.-51$FRPPDQG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-26. WRKJRNA command

The Work with Journal Attributes display shows the current attributes of this journal and the names
of the journal receivers that are currently attached to this journal, if any.
You can use function keys to display lists of objects associated with this journal. You can request
the following lists:
• F13 - Files journaled to this journal
• F14 - Access paths journaled to this journal
• F15 - Receivers that have been used or are being used by this journal
• F16 - Remote journal information
Some of these lists or options are not available when working with an internal system journal
(*INTSYSJRN for JRN).
The type of journal, the possible values are:
• *LOCAL - A local journal
• *REMOTE - A remote journal

© Copyright IBM Corp. 1995, 2017 12-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Journal state
The journal state describes an attribute for a journal. The attribute value can be *ACTIVE,
*INACTIVE (remote journal only), or *STANDBY (local journal only). For a local journal, *ACTIVE
indicates that journal entries are currently allowed to be deposited into the journal. *STANDBY
indicates that most journal entries are not deposited.
The state of the journal, the possible values are:
• *ACTIVE: If this is a local journal, this means journal entries can be deposited to this journal. If
this is a remote journal, this means journal entries can be received from a source journal.
• *INACTIVE: If this is a local journal, this means journal entries cannot be deposited to this
journal, unless they have been designated as journal entries, which must be deposited. If this is
a remote journal, this means journal entries cannot be received from a source journal.
• *FAILED: If this is a remote journal, this means journal entries cannot be received from a
source journal due to a remote journal function failure, such as a communication line failure.
Before deactivating the remote journal by issuing the Change Remote Journal (CHGRMTJRN) or
the Change Journal (CHGJRN) command or by calling the Change Journal State
(QjoChangeJournalState) API, you might want to receive, retrieve, or display any unconfirmed
entries from the journal.
• *STANDBY: This is the state of a local journal after the Change Journal (CHGJRN) command
specifying JRNSTATE(*STANDBY) is used to not allow deposits into the local journal. The local
journal can also be in *STANDBY state after an IPL if the local journal is in *STANDBY state
when the system ends. Objects journaled to the local journal can be restored or changed, but
most journal entries are not deposited until the journal state for the local journal is again
changed to *ACTIVE. This can be performed by using the Change Journal (CHGJRN) command
specifying JRNSTATE(*ACTIVE).
• This value does not apply to local journals.

© Copyright IBM Corp. 1995, 2017 12-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

) :RUNZLWK5HFHLYHU'LUHFWRU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-27. F15 = Work with Receiver Directory

The Work with Receiver Directory display shows a list of all journal receivers that are associated
with this journal, if any. The list of receivers is ordered from the oldest (first attached) at the top of
the list, to the newest (currently attached) at the bottom of the list.
You can make selections on the list to:
• 8 - Display the attributes of the selected receivers
• 4 - Delete the selected receivers
Number column
A number is associated with a journal receiver and assigned by the system which is relative to all
other receivers in the receiver directory at a given time. The first two digits identify the journal chain
number and the last three digits identify the receiver number within the chain.
A chain identifies a group of receivers that are contiguous allowing the system to process entries
across receivers within the same chain.
The chain number starts with zero and is incremented sequentially each time a new chain is
needed. New chains are started when a damaged receiver is recovered by restoring a partial
version.

© Copyright IBM Corp. 1995, 2017 12-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Status column
The status of the receiver can be one of the following:
• ATTACHED: The receiver is currently attached to the journal.
• ONLINE: The receiver is online. The receiver has not been saved and it has been detached
from the journal.
• SAVED: The receiver was saved after it was detached. The receiver storage was not freed
when it was saved.
• FREED: The receiver was saved after it was detached. The receiver storage was freed when it
was saved.
• PARTIAL: The receiver status is partial for one of the following reasons:
▪ It was restored from a version that was saved while it was attached to the journal. Additional
journal entries might have been written that were not restored.
▪ It was one of a pair of dual receivers, and it was found damaged while attached to the
journal. The receiver has since been detached. This receiver is considered partial because
additional journal entries might have been written to the dual receiver.
▪ It is associated with a remote journal and it does not contain all the journal entries that are in
the associated journal receiver attached to the source journal.
• DELETED: The receiver has been deleted. This status is shown after option 4 (Delete)
completes. If you refresh (F5) the list, deleted receivers are removed from the list.

© Copyright IBM Corp. 1995, 2017 12-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.4. Topic 4: Determining the recovery points

© Copyright IBM Corp. 1995, 2017 12-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF'HWHUPLQLQJWKH
UHFRYHU\SRLQWV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-28. Topic 4: Determining the recovery points

© Copyright IBM Corp. 1995, 2017 12-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'HWHUPLQHWKHEHVWUHFRYHU\SRLQWV
DSPJRN
-51

FILE(names)

RCVRNG &855(17
5&9
Start(*CURRENT/name)
End(name/*CURRENT) 5&9

5&9
FROMENT(*FIRST/seq#) 5HFHLYHUVDYHG
WRWDSH

TOENT(*LAST/seq#)

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-29. Determine the best recovery points

Before starting a recovery, use the DSPJRN command to examine the journal receiver entries to find
the best starting and stopping recovery points.
To recover an object by applying or removing journaled changes, the object must be currently
journaled. The journal entries must have the same journal identifier (JID) as the object. To ensure
that the journal identifiers are the same, save the object immediately after journaling is started for
the object.
If you need to recover objects that were journaled to a journal that you deleted, restore the journal
from a saved copy or create a new journal with the same name in the same library. Then restore the
object and all the needed receivers before applying or removing journaled changes with that
journal. You can use an option on the Work with Journals display to reassociate any journal
receivers that are still on the system. To use the Work with Journals display, use the Work with
Journals (WRKJRN) command.

© Copyright IBM Corp. 1995, 2017 12-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-30. Display Journal (1 of 5)

The Display Journal (DSPJRN) command allows you to convert journal entries (contained in one or
more receivers) into a form suitable for external representation. Output of the command can be
displayed or printed with the job's spooled printer output or directed to a database output file.
The contents of selected entries in the journal receivers can be converted for output. It is also
possible to selectively limit the entries that are displayed. If no journal entries satisfy the selection
or limitation criteria, an escape message is sent indicating that fact.
Gaps might exist in the sequence numbers of the entries converted. These occur because some of
the journal entries represent internal IBM i information. These entries are not converted.
It is possible to show journal entries whose journal sequence numbers are reset in the chain of
receivers being specified.
The FILE, JRNCDE, ENTTYP, JOB, PGM, USRPRF, CMTCYCID, and DEPENT parameters can be used
to specify a subset of all available entries within a range of journal entries.
Journaled physical file (FILE)
This specifies a maximum of 300 qualified file names whose journal entries are converted for
output.

© Copyright IBM Corp. 1995, 2017 12-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Journaled object (OBJ)
This specifies a maximum of 300 qualified object names (*FILE, *DTAARA and *DTAQ) whose
journal entries are converted for output.

© Copyright IBM Corp. 1995, 2017 12-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-31. Display Journal (2 of 5)

Objects (OBJPATH) specifies a maximum of 300 objects whose journal entries are converted for
output. Only objects whose path name identifies an object of type *STMF, *DIR or *SYMLNK that
are in the root (/), QOpenSys, and user-defined file systems are supported. All other objects are
ignored. This parameter is not valid for remote journals. Either the FILE parameter might be
specified, or one or more of the object parameters (OBJ, OBJPATH, OBJFID, or OBJJID) might be
specified, but not both.
Directory subtree (SUBTREE) specifies whether the directory subtrees are included in determining
the objects for which journal entries are converted for output.
Name pattern (PATTERN) specifies a maximum of 20 patterns to be used to include or omit objects
for which journal entries are converted for output.

© Copyright IBM Corp. 1995, 2017 12-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-32. Display Journal (3 of 5)

Range of journal receivers (RCVRNG) specifies the starting (first) and ending (last) journal
receivers (the receiver range) that contain the journal entries being converted for output. The
system starts with the starting journal receiver (as specified by the first value) and proceeds through
the receiver chain until the ending receiver (as specified by the last value) is processed.
Starting large sequence number (FROMENTLRG) specifies the first journal entry that is being
considered for conversion for external representation.
Starting date and time (FROMTIME) specifies the date and time of the first journal entry being
converted for external representation.
Ending large sequence number (TOENTLRG) specifies the last journal entry being converted for
external representation.
Ending date and time (TOTIME) specifies the creation date and time of the last journal entry being
converted for external representation.
Number of journal entries (NBRENT) specifies the total number of journal entries that are being
converted for output.

© Copyright IBM Corp. 1995, 2017 12-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-33. Display Journal (4 of 5)

Journal codes (JRNCDE) specifies the journal codes for which journal entries are converted for
output.
Journal entry types (ENTTYP) specifies whether to limit the conversion of journal entries to those of
a specified entry type.
Job name (JOB) specifies that the journal entries being converted for external representation are
limited to the journal entries for a specified job. Only journal entries for the specified job are
converted for external representation.
Program (PGM) specifies that the journal entries being converted for external representation are
limited to the journal entries created by a specified program.
User profile (USRPRF) specifies that the journal entries being considered for conversion for
external representation are limited to the journal entries created for the specified user profile name.
The user name identifies the user profile under which the job was run that deposited the journal
entries.
Commit cycle large identifier (CCIDLRG) specifies the journal entries considered for conversion
based on their associated commit cycle identifier. A commit cycle consists of all journal entries
sharing the same commit cycle identifier.

© Copyright IBM Corp. 1995, 2017 12-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Dependent entries (DEPENT) specifies whether the journal entries to be converted for output
include the journal entries recording actions:
• That occur as a result of a trigger program
• On records that are part of a referential constraint
• That will be ignored during an Apply Journaled Changes (APYJRNCHG) or Remove Journaled
Changes (RMVJRNCHG) operation
Output format (OUTFMT) specifies whether the entry-specific data portion of the journal entry
information appears in character format or hexadecimal format. This keyword is ignored if
*OUTFILE is specified for the Output (OUTPUT) parameter.
Include hidden entries (INCHIDENT) specifies whether hidden journal entries should be returned.
Hidden entries are generated and used by the system. When hidden entries are returned, it will be
possible to display all journal entries such that no sequence numbers will be unaccounted for.

© Copyright IBM Corp. 1995, 2017 12-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

'LVSOD\-RXUQDO RI

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-34. Display Journal (5 of 5)

File identifier (OBJFID) specifies a maximum of 300 file identifiers (FID) for which journal entries
are converted for output. FIDs are a unique identifier associated with integrated file system related
objects. This field is input in hexadecimal format. Only objects whose FID identifies an object of
type *STMF, *DIR, or *SYMLNK that are in the “root” (/), QOpenSys, and user-defined file systems
are supported. All other objects are ignored.
Object journal identifier (OBJJID) specifies a maximum of 300 journal identifiers for which journal
entries are converted for output. This field is input in hexadecimal format. Hexadecimal zero is not
valid. Either the FILE parameter might be specified, or one or more of the object parameters (OBJ,
OBJPATH, OBJFID, or OBJJID) might be specified, but not both.
Output (OUTPUT) specifies whether the output from the command is shown at the requesting work
station, printed with the job's spooled printer output, or sent to the database file specified on the File
to receive output (OUTFILE) parameter.

© Copyright IBM Corp. 1995, 2017 12-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

-RXUQDOFRGHV
6HOHFWHGHQWU\FODVVLILFDWLRQV
-RXUQDOFRGH 7\SH 'HVFULSWLRQ

- 35 3UHYLRXVUHFHLYHU
15 1H[WUHFHLYHU
56 5HFHLYHUVDYHG
BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB

) -0 -RXUQDOLQJVWDUWHG
06 0HPEHUVDYHG
66 6DYHZKLOHDFWLYHJURXSVDYHG

23 )LOHRSHQHG
&/ )LOHFORVHG
5 37 5HFRUGDGGHG
8% ,PDJHEHIRUHXSGDWH
83 ,PDJHDIWHUXSGDWH
'/ 5HFRUGGHOHWHG

8 ;; 8VHUHQWU\
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-35. Journal codes

The system creates different types of journal entries in the journal receiver for different kinds of
activities. On the visual you can see journal codes entry:
• Journal Code J - Journal or Receiver Operation
• Journal Code F - Database File Member Operation
• Journal Code R - Operation on Specific Record Journal entries
• Journal Code U - User-Generated Entry
For more information go to the IBM Knowledge Center at
[Link]

© Copyright IBM Corp. 1995, 2017 12-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

)LQGLQJWKHUHFRYHU\SRLQW

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-36. Finding the recovery point

The DSPJRN command is used to examine the activity against your files to determine at what point
the good data ends, and at what point the bad (erroneous or incomplete) data begins. At this time,
application knowledge is very helpful if not required.

© Copyright IBM Corp. 1995, 2017 12-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

&RPPDQGWRVHQGDXVHUHQWU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-37. Command to send a user entry

The Send Journal Entry (SNDJRNE) command is used to write a single journal entry to a specific
journal. The entry can contain any information. The user can assign an entry type to the journal
entry and can also associate the journal entry with a specified journaled object.
If the journal currently has a state of *STANDBY, then the journal entry will not be deposited unless
OVRSTATE(*STANDBY) is specified.
The journal code for the entry is U, which indicates a user-specified journal entry.

Note

The Send Journal Entry (QJOSJRNE) application programming interface (API) can also be used to
write a user-specified journal entry to a specific journal. Using this API can improve performance
and can provide additional function that is not available with this command.

© Copyright IBM Corp. 1995, 2017 12-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.5. Topic 5: Performing a recovery

© Copyright IBM Corp. 1995, 2017 12-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF3HUIRUPLQJD
UHFRYHU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-38. Topic 5: Performing a recovery

© Copyright IBM Corp. 1995, 2017 12-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

:RUNZLWK-RXUQDOV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-39. Work with Journals

The Work with Journals (WRKJRN) command display shows a list of journals you can work with. You
can select tasks to be performed on specific journals.
Option
Type the option you want.
2=Forward recovery
Select this option to reconstruct an object from a particular point by restoring a saved version of the
object and then applying journaled changes to the object in the same order that they were originally
made. This option is not valid for remote journals.
3=Backout recovery
Select this option to restore an object to a previous state by removing changes to the object in the
reverse order from which the changes were originally made. This option is not valid for remote
journals.
5=Display journal status
Shows you the current status of the selected journal. You will be shown journal information
concerning:
• The last system end status

© Copyright IBM Corp. 1995, 2017 12-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
• Object synchronization status
• Journal and receiver damage
This option is not valid for remote journals.
6=Recover damaged journal
Select this option to recover a journal that has been damaged. Journaling will be ended and
restarted for all objects journaled to the journal. Existing journal receivers are reassociated with the
recovered journal, so it is not necessary to save and restore the receivers to associate them again
with the journal. This option is not valid for remote journals.
7=Recover damaged journal receivers
Select this option to recover journal receivers that have been damaged. This option is not valid for
remote journals.
8=Work with journal attributes
Select this option to run the Work with Journal Attributes (WRKJRNA) command for this journal.
9=Associate receivers with journal
Select this option to associate existing journal receivers with the journal.

© Copyright IBM Corp. 1995, 2017 12-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

)RUZDUGUHFRYHU\
‡ ,VVXH WRKJRN
‡ 6HOHFWRSWLRQ )RUZDUGUHFRYHU\ 
‡ 6HOHFWRSWLRQ $SSO\MRXUQDOHGFKDQJHV  DOO3)VWRUHFRYHU 
ƒ 6\VWHPGHOHWHVGHSHQGHQW/)V
ƒ 6\VWHPGHOHWHV3)VWREHUHFRYHUHG
ƒ 3URPSWVUHVWRUHRI3)VDQGDOORFDWHV EXCL XQWLOUHFRYHU\FRPSOHWH
ƒ 3URPSWVIRUUHVWRUHRI/)V
ƒ APYJRNCHG SURPSWHGZLWKFROMENT(*LASTSAVE)DQGTOENT(*LASTRST)
ƒ 3URPSWVIRUUHFHLYHUVQRWRQOLQH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-40. Forward recovery

When the recovery process is complete, the status field for the member indicates RECOVERED (if
the operation was successful). If the operation failed, the status field remains unchanged, and
messages appear indicating why the operation failed.
To perform forward recovery by entering the commands yourself, do the following:
1. Restore the files: RSTOBJ
2. Allocate the files: ALCOBJ
3. Restore receivers: RSTOBJ
4. APYJRNCHG...FROMENT(*LASTSAVE) TOENT(*LASTRST)
5. Deallocate the files: DLCOBJ

© Copyright IBM Corp. 1995, 2017 12-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6HOHFWRSWLRQWRVWDUWIRUZDUGUHFRYHU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-41. Select option 2 to start forward recovery

Option 2 (Forward recovery) on the Work with Journals screen initiates a prompted interface to
restoring and recovering an object.

© Copyright IBM Corp. 1995, 2017 12-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

)RUZDUGUHFRYHU\REMHFWW\SH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-42. Forward recovery object type

Select the object type of the journaled objects you want to recover. The system will then display the
list of objects of that object type currently being journaled to the journal you identified on the Work
with Journals screen.

© Copyright IBM Corp. 1995, 2017 12-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

:RUNZLWK)RUZDUG5HFRYHU\IRU)LOHV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-43. Work with Forward Recovery for Files

The Work with Forward Recovery display shows a list of the database file members that you have
specified for forward recovery. From this display, you can select the type of action you want to
perform with each member.
The options you can select are:
1=Add member to list causes the entry typed on the line above the existing members to be added
to the list. Once added to the list, the other options can be used on the new member.
2=Apply journaled changes applies journaled changes and changes the status to RECOVERED
(if the apply operation was successful). If the apply operation was not successful, messages
appear indicating why, and the status remains the same. If any required receivers are missing or
damaged while running the APYJRNCHG command, the system displays prompts for the restore
procedures for the missing or damaged receivers. This option can be used on an entry typed into
the empty line above the list entries, if the typed entry already exists in the list.
3=Restore, use this option if any members have a status of NOT FOUND. This option prompts you
for the files to restore. Members that are restored successfully have a status of RESTORE
COMPLETE. Members that are not restored keep their old status. A message is sent indicating that
the restore did not complete successfully. All members that are restored are included in the list of
members to recover. This option can be used on an entry typed into the empty line above the list
entries, if the typed entry already exists in the list.

© Copyright IBM Corp. 1995, 2017 12-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
4=Remove member from list causes the member to be removed from the recovery list. This
option can be used on an entry typed into the empty line above the list entries, if the typed entry
already exists in the list.
Status column shows the status of the member relative to its recovery process. The status of each
member can change as the recovery process progresses.
The status definitions are:
Blank: The member and the journal objects are all usable and everything is synchronized. None of
the journal objects need to be recovered prior to continuing recovery of the member.
Not synchronized: The journal receivers used for this member are damaged and will need to be
recovered before the member can be recovered. To recover a member with this status, first go back
to the Work with Journals menu (F3=Exit) and take the option to recover damaged journal
receivers.
Damaged: The member is damaged and will need to be restored as part of the recovery process.
The system ensures you go through the restore step as you continue the recovery process.
Not found: The system cannot locate the specified database file. The system will ensure that the
file has been restored before proceeding with the recovery.
Different journal: The member is not journaled to the journal you are working with. You will need to
work with the correct journal to recover this database file. Use the Display File Description (DSPFD)
command to determine the correct journal.
Not journaled: The member is not journaled to any journal. It cannot be recovered.
Restore complete: When the recovery process requires a restore of the database file, this status
is shown once the restore has successfully completed. If a restore is unsuccessful, messages will
be displayed and the status remains unchanged.
Recovered: When the recovery completes successfully, this status is shown. If the recovery is
unsuccessful, messages are displayed and the status will remain unchanged.

© Copyright IBM Corp. 1995, 2017 12-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

%DFNRXWUHFRYHU\
‡ ,VVXH WRKJRN

‡ 6HOHFWRSWLRQ %DFNRXWUHFRYHU\ 

‡ 6HOHFWRSWLRQ 5HPRYHMRXUQDOHGFKDQJHV 
ƒ RMVJRNCHG SURPSWHG
ƒ 3URPSWVIRUUHVWRUHRIUHFHLYHUVQRWRQOLQH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-44. Backout recovery

To remove journaled changes with the Work With Journal (WRKJRN) command, select option 3
(Backout recovery). The Work with Backout Recovery display shows a list of the file members that
are being journaled.
The same options on the Work with Forward Recovery display are available on the Work with
Backout Recovery display. However, the option to restore the file is not valid for backout recovery.
The status field that is shown on the Work with Backout Recovery display is either blank or it
indicates the same status as for forward recovery, except for restore complete.

© Copyright IBM Corp. 1995, 2017 12-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6HOHFWRSWLRQWRVWDUWEDFNRXWUHFRYHU\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-45. Select option 3 to start backout recovery

Select the type of object you are recovering.

© Copyright IBM Corp. 1995, 2017 12-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

%DFNZDUGUHFRYHU\REMHFWW\SH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-46. Backward recovery object type

Select the type of object you are recovering.

© Copyright IBM Corp. 1995, 2017 12-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

:RUNZLWK%DFNRXW5HFRYHU\IRU)LOHV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-47. Work with Backout Recovery for Files

The Work with Backout Recovery display shows a list of the data file members you have specified
for backout recovery. From this display, you can select the type of action you want to perform with
each member.
The options you can select are:
1=Add member to list
This option causes the entry entered on the line above the existing members to be added to the list.
Once added to the list, the other options can be used on the new member.
2=Remove journaled changes
This option causes the Remove Journaled Changes (RMVJRNCHG) command prompt to be shown
with known values already assigned. You can then run the command to remove the specified
changes. This option can be used on an entry entered into the empty line above the list entries, if
the entry already exists in the list.
4=Remove member from list
This option causes the member to be removed from the recovery list. This option can be used on
an entry entered into the empty line above the list entries, if the entry already exists in the list.

© Copyright IBM Corp. 1995, 2017 12-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

$3<-51&+*FRPPDQG IRUZDUGUHFRYHU\
JRN QDPH

FILE /,%/ CURLIB QDPH ALL QDPH

RCVRNG 6WDUW 1DPH LASTSAVE CURRENT

(QG1DPH CURRENT

FROMENT /$676$9( QXPEHU FIRST

TOENT /$67567 QXPEHU LAST

TOTIME 'DWH 7LPH

TOJOBO MREQDPH

TOJOBC MREQDPH

CMTBDY NO YES

OBJERROPT CONTINUE END

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-48. APYJRNCHG command (forward recovery)

The Apply Journaled Changes (APYJRNCHG) command applies the changes that are journaled (for
a particular member of a database file) to a saved version of the file to recover the file after an
operational error or some form of damage.
The journaled changes are applied from the specified starting point, either the point at which a file
was last saved or a particular entry on the journal until the specified ending point has been reached.
The ending point can be the point at which the file has had all changes applied, the file was last
restored. A specified entry has been reached, a specified time has been reached, or the file was
opened or closed by a job (the CMTBDY parameter is used for handling changes that are still
pending in the file).
A list of physical files and members can be specified. The journaled changes for physical file
members are applied in the order that the journal entries are found on the journal, which is the
same order in which the changes are made to the physical file members.
The difference between APYJRNCHG and APYJRNCHGX, is that with APYJRNCHGX, you can only
specify database files and *ALL files in a library. However, the APYJRNCHGX command can apply
journal entries resulting from the following SQL statements:
• CREATE INDEX
• CREATE TABLE

© Copyright IBM Corp. 1995, 2017 12-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
• CREATE VIEW
The values which are underlined are the defaults for the associated parameter.

© Copyright IBM Corp. 1995, 2017 12-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

509-51&+*FRPPDQG EDFNRXWUHFRYHU\

JRN QDPH

FILE LIBL QDPH CURLIBQDPH ALL

RCVRNG 6WDUW CURRENT QDPH

(QG QDPH

FROMENT LAST QXPEHU LASTSAVE

TOENT FIRST QXPEHU

TOJOBO MREQDPH

CMTBDY NO YES

OBJERROPT CONTINUE END

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-49. RMVJRNCHG command (backout recovery)

The Remove Journal Changes (RMVJRNCHG) command removes the changes that have been
journaled for a particular member of a database file.
The journaled changes are removed from the file from the specified starting point to the ending
point. The journal entries are processed in reverse of the order in which they were placed into the
journal receiver, from the most recent to the oldest.
The starting point can be identified as the last journal entry in the specified journal receiver range,
the point at which a file was last saved, or a particular entry in the receiver range.
The ending point can be the first journal entry or a particular entry in the specified journal receiver
range, or the point at which a file was opened by a specified job. The CMTBDY parameter can be
used for handling changes that are pending in the file.

© Copyright IBM Corp. 1995, 2017 12-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

2SHUDWLRQVWKDWFDXVHLQFRPSOHWHUHFRYHU\
&RGH 7\SH 2SHUDWLRQ APYJRNCHG RMVJRNCHG

) $< -RXUQDOFKDQJHVDSSOLHG (QGV (QGV

) &5 0HPEHUFOHDUHG &OHDUHG (QGV

) (- (QGMRXUQDOLQJ (QGV ,JQRUHV

) ,8 )LOHQRWV\QFKURQL]HG (QGV (QGV

) -0 6WDUWMRXUQDOLQJPHPEHU ,JQRUHV (QGV

) 0' 0HPEHUGHOHWHG ,JQRUHV (QGV

) 0) SAVxx STG(*FREE) (QGV (QGV

) 02 0HPEHUFKDQJHG (QGV (QGV

) 05 0HPEHUUHVWRUHG (QGV (QGV

) 5& -RXUQDOHGFKDQJHVUHPRYHG (QGV (QGV

) 5* 0HPEHUUHRUJDQL]HG ,JQRUH (QGV

) 6$ 6WDUWAPYJRNCHG (QGV (QGV

) 65 6WDUWRMVJRNCHG (QGV (QGV

([DPLQHFRXQW551DQGIODJRI)$<RU)5&
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-50. Operations that cause incomplete recovery

Some types of entries in the journal receiver cause the apply or remove process to possibly stop.
These entries are written by events that the system cannot reconstruct. Certain illogical conditions,
such as a duplicate key in a database file defined as unique, can also cause processing to end.
Error handling: When the system encounters a journal entry it cannot process, it ends apply
processing either for that specific object or for the entire apply operation. You can specify how the
system behaves when it encounters a journal entry it cannot process with the Object Error Option
(OBJERROPT) parameter on the APYJRNCHG or APYJRNCHGX command.
• If you specify OBJERROPT(*CONTINUE), the system ends apply processing for the specific
object that has an error, but it continues apply processing for the other objects in the apply
operation.
• If you specify OBJERROPT(*END), the system ends processing for the entire apply operation.
The OBJERROPT parameter is also available for the Remove Journaled Changes (RMVJRNCHG)
command. Actions of applying or removing journaled changes by journal code shows which entry
types cause processing to end for an object.

© Copyright IBM Corp. 1995, 2017 12-68


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
After using APYJRNCHG or RMVJRNCHG, the journal receiver should be examined to see the status
or results of the operation. The journal receiver has an F/AY entry to hold the status or results of an
APYJRNCHG and likewise, an F/RC entry to hold the status or results of an RMVJRNCHG. Look in
the Count/PRN and flag fields of the entries.
Count/RRN
This field displays either the relative record number (RRN) of the record which caused the journal
entry to be written, or a count which is pertinent to the specific type of journal entry. This field is
blank except for the journal code/type combinations that follow:
F/AY
This is the number of journal entries applied by the Apply Journal Changes (APYJRNCHG)
command.
F/RC
This is the number of journal entries removed by the Remove Journal Changes (RMVJRNCHG)
command.
Flag
This field displays additional information for certain kinds of journal entries. This field is blank
except for the journal code/type combinations that follow:
F/AY, F/RC
This indicates the completion status.
• 0 - Apply or remove of journal changes completed normally
• 1 - Apply or remove of journal changes completed abnormally

© Copyright IBM Corp. 1995, 2017 12-69


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

,OORJLFDOFRQGLWLRQVWKDWVWRS$3<-51&+*RU509-51&+*
‡ $WWHPSWVWRGRWKHIROORZLQJ
ƒ 7RDGGDUHFRUGWRDQH[LVWLQJUHODWLYHUHFRUGQXPEHU
ƒ 7RDGGDUHFRUGEH\RQGWKHQH[WUHFRUGSRVLWLRQDIWHUWKHHQGRIWKHILOH
ƒ 7RDGGDUHFRUGWKDWKDVDGXSOLFDWHNH\
ƒ 7RGHOHWHDGHOHWHGUHFRUG
ƒ 7RXSGDWHDQRQH[LVWHQWUHFRUG
‡ ([DPLQHFRXQW551DQGIODJRI)$<RU)5&

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-51. Illogical conditions that stop APYJRNCHG or RMVJRNCHG

Most illogical conditions are caused by starting the apply journaled changes operation at the wrong
place in the journal with respect to the current contents of the file members.

© Copyright IBM Corp. 1995, 2017 12-70


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.6. Topic 6: Additional journaling topics

© Copyright IBM Corp. 1995, 2017 12-71


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF$GGLWLRQDOMRXUQDOLQJ
WRSLFV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-52. Topic 6: Additional journaling topics

© Copyright IBM Corp. 1995, 2017 12-72


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6$9&+*2%--RXUQDOLQJFRQVLGHUDWLRQV RI

SAVCHGOBJ....OBJJRN(*NO)

:HHNO\ 'DLO\
SAVIB LIB(LIBA LIBB) CHGJRN JRN(name) JRNRCV(*GEN)
SAVCHGOBJ OBJ(*ALL) LIB(LIBA LIBB) OBJJRN(*NO)
/,%$

),/($
),/(% &KDQJHV
),/(& RFFXUWR ),/($
),/($RQ
5&95
7XHVGD\ ),/($
-51$ 5&95
5&95 5&95
),/($
/,%% 5&95
5&95
5&95
5&95
5&95

0RQGD\ 7XHVGD\ :HGQHVGD\7KXUVGD\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-53. SAVCHGOBJ: Journaling considerations (1 of 3)

The Save Changed Object (SAVCHGOBJ) command saves a copy of each changed object or group
of objects located in the same library. When *ALL is specified on the Objects prompt (OBJ
parameter), objects can be saved from all user libraries or from up to 300 specified libraries. When
saving to a save file, only one library can be specified. For database files, only the changed
members are saved.
Objects changed since the specified date and time are saved with the following exceptions:
• If OBJJRN(*NO) is specified, database files currently being journaled are not saved, unless
journaling was started after the specified date and time. This ensures that changes made to a
physical file before journaling starts are not lost because they were not journaled in a journal
receiver.
• Freed objects (programs, files, journal receivers, and so forth) are not saved.
• User-defined messages, job and output queue definitions, logical file definitions, and data
queue descriptions are saved, but the contents of those objects are not saved. Logical file
access paths are saved if ACCPTH(*YES) is specified.
Specified objects that were changed and the libraries where they reside remain locked during the
save operation.
Saved objects can be restored with the Restore Object (RSTOBJ) command.

© Copyright IBM Corp. 1995, 2017 12-73


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
To determine the date and time that an object was changed, run the Display Object Description
(DSPOBJD) command with DETAIL(*FULL) specified. For database file members that were
changed, run the Display File Description (DSPFD) command.
Journaled objects (OBJJRN) specifies whether changes to objects currently being entered in a
journal as specified in the Start Journal Physical File (STRJRNPF) command are saved.
Reference date (REFDATE) specifies the reference date. Objects that have been changed since
this date are saved.
Reference time (REFTIME) specifies the reference time. Objects that have been changed since
this time on the specified date are saved.

© Copyright IBM Corp. 1995, 2017 12-74


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6$9&+*2%--RXUQDOLQJFRQVLGHUDWLRQV RI
SAVCHGOBJ....OBJJRN(*YES)

:HHNO\ 'DLO\
SAVIB LIB(LIBA LIBB) CHGJRN JRN(name) JRNRCV(*GEN)
SAVCHGOBJ OBJ(*ALL) LIB(LIBA LIBB) OBJJRN(*YES)
/,%$

),/($
),/(% &KDQJHV
),/(&
RFFXUWR
&KDQJHV
),/(%RQ
RFFXUWR
-51$ :HGQHVGD\
),/($RQ ),/($
7XHVGD\ ),/(%
),/($
/,%%
),/(%
5&95 ),/($
5&95
5&95 5&95 5&95
5&95
5&95 5&95 5&95

0RQGD\ 7XHVGD\:HGQHVGD\7KXUVGD\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-54. SAVCHGOBJ: Journaling considerations (2 of 3)

By specifying OBJJRN(*YES) on the SAVCHGOBJ command, a user is requesting that the journal
objects should be saved as well as any other objects that have changed since the last save. This
will alter your restore strategy.

© Copyright IBM Corp. 1995, 2017 12-75


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6$9&+*2%--RXUQDOLQJFRQVLGHUDWLRQV RI
‡ )RUZDUGUHFRYHU\DIWHUGDWDORVVRQ)ULGD\
 /RDGSAVLIB WDSH
 RSTLIB
 /RDGSAVCHGOBJ WDSHIRU7KXUVGD\
 RSTOBJ OBJ(*ALL)
 APYJRNCHG
 5HNH\GDWDVLQFH7KXUVGD\ VSAVCHGOBJ WDSH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-55. SAVCHGOBJ: Journaling considerations (3 of 3)

© Copyright IBM Corp. 1995, 2017 12-76


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

:KLFKILOHVVKRXOGEHMRXUQDOHG"
‡ +RZPXFKGRHVWKHILOHFKDQJH"

‡ +RZGLIILFXOWZRXOGLWEHWRUHFRQVWUXFWILOHFKDQJHV"

‡ +RZFULWLFDOLVWKHILOH"

‡ +RZGRHVWKHILOHUHODWHWRRWKHUILOHV"
ƒ $OOILOHVLQDQDSSOLFDWLRQ
ƒ $OOILOHVLQDUHIHUHQWLDOFRQVWUDLQWQHWZRUN
ƒ $OOILOHVDIIHFWHGE\WULJJHUSURJUDPV

‡ 1RWVRXUFHILOHV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-56. Which files should be journaled?

• High change volume files are good candidates.


• Files whose changes have no written records, such as those used for telephone order entry are
good candidates.
• Consider the effect on your business during a delay to reconstruct a file.
• If you journal one file, you should journal all files related to it.
• Do not journal source files, since when a member is updated, every record is considered
changed and therefore written to the journal.

© Copyright IBM Corp. 1995, 2017 12-77


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

+RZVKRXOGILOHVEHDVVLJQHGWRMRXUQDOV"
‡ 2QHMRXUQDO6LPSOHPDQDJHPHQWDQGUHFRYHU\

‡ $SSOLFDWLRQ VILOHVLQVDPHMRXUQDOVLPSOLILHVUHFRYHU\

‡ %DFNXSVHFXULW\RUDXGLWLQJUHTXLUHPHQWV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-57. How should files be assigned to journals?

© Copyright IBM Corp. 1995, 2017 12-78


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6KRXOGMRXUQDOUHFHLYHUVEHLQDXVHU$63"
‡ 6\VWHP$632SHUDWLQJV\VWHPDQGXVHUREMHFWV
‡ /LEUDU\XVHU$63 OLEUDU\LVILUVWREMHFWLQ$63
ƒ JRN PXVWEHLQDOLEUDU\$63ZLWKDMRXUQDOHGILOHV
ƒ JRNRCV FDQEHLQGLIIHUHQW$63
‡ 1RQOLEUDU\XVHU$63 QRWUHFRPPHQGHG
ƒ )LUVWREMHFWLQ$63LVDMRXUQDOMRXUQDOUHFHLYHURUVDYHILOH

$63 $63
$63
8VHU$63 8VHU$63
6\VWHP$63
/LEUDU\XVHU$63 1RQOLEUDU\XVHU$63
*LIB CUSTLIB *LIB LIBJRNB *JRNRCV JRCVB
*FILE *JRN JRNB
*FILE *SAVF ORDSAV

*LIB LIBJRNA
*JRNRCV JRCVA
*JRN JRNA

*LIB SAVFLIB

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-58. Should journal receivers be in a user ASP?

If you are journaling many active files to the same journal, the journal receiver can become a
performance bottleneck. One solution is to put the receiver in a user ASP. This also provides
additional protection.
The system spreads journal receivers across multiple disk units to improve performance. The
journal receiver might be placed across the ten fastest disk arms in the ASP. Journal entries are
written in a round robin technique with these arms.

© Copyright IBM Corp. 1995, 2017 12-79


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HVWRUHFRQVLGHUDWLRQV
‡ 5HFRPPHQGHGUHVWRUHVHTXHQFH DXWRPDWLFLIDOOLQWKHVDPHOLEUDU\ 
 -RXUQDOV
 3K\VLFDOILOHV
 /RJLFDOILOHV
 -RXUQDOUHFHLYHUV

• RSTLIB LIB(name)$OOREMHFWVZLWKLQOLEUDU\UHVWRUHGLQFRUUHFW
VHTXHQFH

• RSTLIB LIB(*NONSYS *ALLUSR)


ƒ /LEUDULHVUHVWRUHGLQDOSKDEHWLFVHTXHQFH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-59. Restore considerations

When you restore a journal, the system creates a new journal receiver and attaches it. A new
receiver chain is started.

© Copyright IBM Corp. 1995, 2017 12-80


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

2WKHUMRXUQDOFRQVLGHUDWLRQV
‡ %HIRUHLPDJHV
ƒ %DFNRXWUHFRYHU\LVSRVVLEOH
ƒ 'HOHWHGUHFRUGVFDQEHUHFRYHUHG
ƒ CMPJRNIMG LVPRUHPHDQLQJIXO
‡ -RXUQDOHGILOHVVKRXOGKDYHFRCRATIO(*NONE)
‡ JRNRCV VSUHDGDFURVVIDVWHVWGLVNDUPVLQ$63
‡ 6L]HRIMRXUQDOUHFHLYHUV
ƒ $FFHVVSDWKMRXUQDOHGDOVR"
STRJRNPF IMAGES(*AFTER *BOTH)
OMTJRNE(*NONE *OPNCLO)
CRTJRN RCVSIZOPT(*RMVINTENT*MINFIXLEN)

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-60. Other journal considerations

Journal entries to be omitted (OMTJRNE) specifies the journal entries that are omitted. The
possible values are:
• *NONE: No journal entries are omitted.
• *OPNCLO: Open and close entries are omitted. Open and close operations on the specified file
members do not create open and close journal entries.
• Receiver size options (RCVSIZOPT) specifies the options that affect the size of the receivers
attached to the journal. The possible values are:
• *NONE: No options affect the size of the journal entries attached to the receiver. All journal
entries placed on the receiver are permanent.
• *RMVINTENT: The size of the receivers attached to the journal are reduced by automatic
removal of the internal entries required only for initial program load (IPL) recovery when these
entries are no longer required.
• *MINFIXLEN: The size of the journal entries that are deposited into the attached journal
receivers is reduced by the automatic removal of the job, program, and user profile information

© Copyright IBM Corp. 1995, 2017 12-81


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

)LOHMRXUQDOLQJVXPPDU\
5HFRYHUVGDPDJHGGDWDILOHPHPEHU


 
 
 






'HFUHDVHVWLPHUHTXLUHGWRGREDFNXS

3URYLGHVDXGLWWUDLO



3URYLGHVDFWLYLW\UHSRUWLQJ

$LGVGHEXJJLQJ
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-61. File journaling summary

© Copyright IBM Corp. 1995, 2017 12-82


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

([HUFLVH-RXUQDOPDQDJHPHQW
‡ 8VHWKH&UHDWH-RXUQDO5HFHLYHUDQGWKH&UHDWH-RXUQDOFRPPDQGV
WRFUHDWHWZRREMHFWVZLWKZKLFKWRSHUIRUPMRXUQDOLQJ
‡ 8VHDQLQVWUXFWRUVXSSOLHGPDLQWHQDQFHSURJUDPWRSHUIRUP
DGGLWLRQVGHOHWLRQVDQGXSGDWHVWRILOHVEHLQJMRXUQDOHG
‡ 8VHWKH&KDQJH-RXUQDOFRPPDQGWRFKDQJHMRXUQDOUHFHLYHUV
‡ 8VHWKH'LVSOD\-RXUQDOFRPPDQGWRGLVSOD\MRXUQDOHQWULHVIURPD
FKDLQRIUHFHLYHUV
‡ 8VHWKH:RUNZLWK-RXUQDO$WWULEXWHVVFUHHQWRGLVSOD\
ƒ -RXUQDOUHFHLYHUDWWULEXWHV
ƒ -RXUQDOHGILHOGV
ƒ -RXUQDOUHFHLYHUGLUHFWRU\
‡ 8VHWKHFRQWHQWVRIMRXUQDOHQWULHVWRGHWHUPLQH
ƒ :KLFKILOHPHPEHUVZHUHRSHQHGDQGZKDWRSWLRQV LQSXWRXWSXWXSGDWH
GHOHWH ZHUHVSHFLILHG
ƒ 8VHUSURJUDPRSHUDWLRQVLVVXHGDJDLQVWWKHILOH
ƒ 7KHXVHRIWKH&2817551DQG)/$*ILHOGV
ƒ 7KHGDWHWLPHDQGPHGLDXVHGIRUSK\VLFDOILOHVDYHV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-62. Exercise: Journal management

© Copyright IBM Corp. 1995, 2017 12-83


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.7. Topic 7: Remote journaling

© Copyright IBM Corp. 1995, 2017 12-84


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF5HPRWHMRXUQDOLQJ

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-63. Topic 7: Remote journaling

© Copyright IBM Corp. 1995, 2017 12-85


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HPRWHMRXUQDO
‡ -RXUQDOHQWULHVWUDQVSRUWHGWRDGXSOLFDWHUHFHLYHURQDEDFNXSVHUYHU
UXQQLQJ,%0L

‡ 8VHGWRUHSOLFDWHGDWDUHPRWHO\RUSURYLGHDKRWEDFNXSVLWH

‡ ,%0LRSHUDWLQJV\VWHPEDVHVXSSRUW

‡ 7UDQVSRUWGRQHEHORZPDFKLQHLQWHUIDFHIRUEHWWHUSHUIRUPDQFH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-64. Remote journal

Remote journal management allows you to establish journals and journal receivers on a remote
system or to establish journal and receivers on independent disk pools that are associated with
specific journals and journal receivers on a local system.
The remote journaling function can replicate journal entries from the local system to the journals
and journal receivers that are located on the remote system or independent disk pools after they
have been established.

© Copyright IBM Corp. 1995, 2017 12-86


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HPRWHMRXUQDO+RWEDFNXS

3ULPDU\ ORFDO V\VWHP %DFNXS UHPRWH V\VWHP

&DOOWRRCVJRNE
5HFHLYH
$SSOLFDWLRQV H[LWSURJUDP

DQG 
DSSO\MREV 
3URFHVVLQJ

'%RSHUDWLRQ
&RPPXQLFDWLRQV
WUDQVSRUW

'% -51DQG -51DQG


'%ILOHV
ILOHV -515&9V -515&9V

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-65. Remote journal: Hot backup

• Objects cannot be journaled to remote journals


• Cannot use SNDJRNE or API QJIOSJRNE to send entries to remote journal
How does it work?
• DB images transported in real time
• All transport managed below the MI (that is, in microcode)
• Memory to memory transfer - does not wait to reach a target disk
• If the communications line goes down, source applications keep executing
Transport mechanism:
• TCP/IP
Two transport modes:
• Sync Transmission with confirmation
• Async Transmission (no confirmation)

© Copyright IBM Corp. 1995, 2017 12-87


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
The terms asynchronously maintained and synchronously maintained both describe a remote
journal function delivery mode for journal entry replication. If a journal is asynchronously
maintained, control is returned to the application generating the journal entry on the source system
without waiting for the journal entry to be replicated to the remote journal. An asynchronously
maintained remote journal might lag several journal entries behind the total number of journal
entries in the journal on the source system.
If a journal is synchronously maintained, control is not returned to the application generating the
journal entry on the local system until the journal entry is replicated to the remote journal.
• Can broadcast up to 255 secondaries/target systems
• Can cascade without limit to other systems
• CHGJRN initiated from source, performed in lock-step on target
What happens when I crash/recover?
Simply reconnect. The replication of journal entries to each of the associated remote journals ends
implicitly when the local system ends. To begin replicating journal entries to the remote journal, you
must deactivate the remote journal on the target system, then activate it again. After an IPL or vary
on operation, you are not required to reassociate the wanted remote journals with the journal on the
source system.
The journal state describes an attribute for a journal. The attribute value can be *ACTIVE,
*INACTIVE (remote journal only), or *STANDBY (local journal only). For a local journal, *ACTIVE
indicates that journal entries are currently allowed to be deposited into the journal. *STANDBY
indicates that most journal entries are not deposited.

© Copyright IBM Corp. 1995, 2017 12-88


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HPRWHMRXUQDOEHQHILWV
‡ /HVVGLVNZULWHVRQWKHVRXUFHV\VWHPWKDQSULRUVXSSRUW

‡ /HVV&38RYHUKHDGWKDQSULRUVXSSRUWRQWKHVRXUFHV\VWHP

‡ '%LPDJHVFDQEHVHQWWRWDUJHWPDFKLQHLQUHDOWLPH

‡ +LJKDYDLODELOLW\ [

‡ 6KLIWVDYLQJ-51UHFHLYHUVWRWKHWDUJHWPDFKLQH

‡ 1RORVWWUDQVDFWLRQV

‡ )DVWHUVZLWFKEDFN

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-66. Remote journal benefits

Remote journal allow you to build high availability HA solution but currently modern approach is
move to external storage and use external storage replication technology which is better than
internal based on remote journal.

© Copyright IBM Corp. 1995, 2017 12-89


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HPRWHMRXUQDOFRPPDQGVDQG$3,
• ADDRMTJRN$GG5HPRWH-RXUQDO 4MR$GG5HPRWH-RXUQDO$3, 
ƒ (VWDEOLVKHVDQGDVVRFLDWHVDUHPRWHMRXUQDORQDWDUJHWV\VWHPZLWKDMRXUQDORQ
DVRXUFHV\VWHP
• CHGRMTJRN&KDQJH-RXUQDO6WDWH 4MR&KDQJH-RXUQDO6WDWH$3,
ƒ &KDQJHVWKHMRXUQDOVWDWHIRUORFDODQGUHPRWHMRXUQDOV
• RMVRMTJRN5HPRYH5HPRWH-RXUQDO 4MR5HPRYH5HPRWH-RXUQDO
$3,
ƒ 'LVDVVRFLDWHVDUHPRWHMRXUQDORQDWDUJHWV\VWHPIURPDMRXUQDORQDVRXUFH
V\VWHP
‡ 5HWULHYH-RXUQDO,QIRUPDWLRQ 4MR5HWULHYH-RXUQDO,QIRUPDWLRQ$3, 
ƒ 5HWULHYHVWKHDWWULEXWHVRIDMRXUQDOLQFOXGLQJWKHUHFHLYHUGLUHFWRU\MRXUQDOHG
ILOHVDQGUHPRWHMRXUQDOV
‡ 5HWULHYH-RXUQDO5HFHLYHU,QIRUPDWLRQ 4MR5WY-UQ5HFHLYHU,QIRUPDWLRQ
$3, 
ƒ 5HWULHYHVWKHDWWULEXWHVRIDMRXUQDOUHFHLYHU

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-67. Remote journal commands and API

You can use the Add Remote Journal (ADDRMTJRN) Command or the Add Remote Journal
(QjoAddRemoteJournal) API to add a remote journal.
If you set up the remote journal CL-command or API, there are:
• No application changes required
• No special feature to install
• No tuning mandated
• No extra housekeeping steps
Even Swap of Receivers is automated on the target.
CL-Commands:
The Add Remote Journal (ADDRMTJRN) command associates a remote journal on the target
system, as identified by the relational database directory entry, with the specified journal on the
source system. The journal on the source system might be either a local journal or another remote
journal. A maximum of 255 remote journals might be associated with a single journal on a source
system.

© Copyright IBM Corp. 1995, 2017 12-90


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
The Change Remote Journal (CHGRMTJRN) command is used to change the journal state for
remote journals. This command is used on the source system for a remote journal that is
associated with a source-system journal to change the state of the remote journal from *ACTIVE to
*INACTIVE or from *INACTIVE to *ACTIVE. A journal state of *ACTIVE for a remote journal
indicates that journal entries can be received from the associated journal on the source system. A
journal state of *INACTIVE for a remote journal indicates that the journal is not ready to receive
journal entries from a source journal. This command also allows additional attributes that are
associated with the journal state to be set.
The Remove Remote Journal (RMVRMTJRN) command disassociates a remote journal on the
specified target system from the specified journal on the source system. The journal on the source
system can be either a local journal or another remote journal. The remote journal, and any
associated journal receivers, are not deleted from the target system by the command processing.
No processing is performed on the target system for the command. The remote journal that
remains on the target system can later be added back to the remote journal definition for the journal
on the source system by using the Add Remote Journal (ADDRMTJRN) command.
The Change Journal (CHGJRN) command can be used to modify the other journal attributes of
remote journals, such as the journal message queue, deleting receivers, and text. Special attention
needs to be given to the base main storage pool size for both source and target systems in order to
keep page faulting to a minimum. Refer to the Performance section for other performance issues
when working with remote journals.

© Copyright IBM Corp. 1995, 2017 12-91


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
12.8. Topic 8: Access path protection

© Copyright IBM Corp. 1995, 2017 12-92


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

7RSLF$FFHVVSDWK
SURWHFWLRQ

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-68. Topic 8: Access path protection

© Copyright IBM Corp. 1995, 2017 12-93


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

,QWURGXFWLRQWRDFFHVVSDWKMRXUQDOLQJ

+RZFDQ,VLJQLILFDQWO\UHGXFH
WKHWLPHQHHGHGWR,3/IROORZLQJ
DQDEQRUPDOV\VWHPHQG" 7KDWLVHDV\,PSOHPHQW
DFFHVVSDWKMRXUQDOLQJRUXVH
V\VWHPPDQDJHGDFFHVVSDWK
SURWHFWLRQ

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-69. Introduction to access path journaling

© Copyright IBM Corp. 1995, 2017 12-94


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

$FFHVVSDWKSURWHFWLRQ
‡ :KDWLVWKHEHQHILW"
ƒ 5HGXFHV,3/WLPHDIWHUDEQRUPDOHQG

‡ +RZ"
ƒ %\MRXUQDOLQJDFFHVVSDWKV

‡ :KDWGRHVWKHXVHUKDYHWRGR"
ƒ 9HU\OLWWOH

‡ :KDWGRHVLWFRVW"
ƒ 6RPH&38SHUIRUPDQFHDQGVRPH'$6'VSDFH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-70. Access path protection

Without access path protection, an IPL after an abnormal system end could take several hours.
An access path describes the order in which records in a database file are processed. A file can
have multiple access paths, if different programs need to see the records in different sequences. If
your system ends abnormally when access paths are in use, the system might have to rebuild the
access paths before you can use the files again. This is a time-consuming process. To perform an
IPL on a large, busy IBM i that has ended abnormally can take many hours.
The QSAVACCPTH system value indicates whether or not the access paths are saved during a save
operation. The access path is the order in which records in one or more database files are
organized for processing by a program.
Two methods of access-path protection are available:
1. System-managed access-path protection (SMAPP)
2. Explicit journaling of access paths

© Copyright IBM Corp. 1995, 2017 12-95


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

$FFHVVSDWK VFRQWULEXWLRQWR,3/WLPH
‡ $EQRUPDOHQGRIV\VWHPFDQOHDYHDQDFFHVVSDWKXQXVDEOH
‡ $FFHVVSDWKLVPDGHXVDEOHQRODWHUWKDQZKHQILOHLVRSHQHG
‡ 3URWHFWHGDFFHVVSDWKVDUH
ƒ 5HFRYHUHGTXLFNO\WKURXJKMRXUQDOGXULQJRUDIWHU,3/
‡ 8QSURWHFWHGDFFHVVSDWKV
ƒ '%ILOHVKDYHD5(&29(5DWWULEXWH
í RECOVER(*NO)5HEXLOGZKHQRSHQHG
í RECOVER(*AFTIPL),3/DQGWKHQUHEXLOG
í RECOVER(*IPL)
5HEXLOGGXULQJ,3/
9DOLGRQO\LIILOHKDVMAINT IMMED RU DLYQRW REBLD
ƒ 'XULQJ,3/5(&29(5DWWULEXWHFKDQJHDEOHRQ2YHUULGH$FFHVV3DWK
5HFRYHU\GLVSOD\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-71. Access path's contribution to IPL time

Access path maintenance (MAINT)


Specifies, for files with key fields, the type of access path maintenance used for all members of the
physical file.
The possible values are:
*IMMED: The access path is updated each time a record is changed, added, or deleted from a
member. *IMMED must be specified for files that require unique keys.
*REBLD: The access path is completely rebuilt each time a file member is opened. The access
path is maintained until the member is closed; then the access path is deleted. *REBLD cannot be
specified for files that require unique keys.
*DLY: The maintenance of the access path is delayed until the physical file member is opened for
use. Then, the access path is changed only for records that have been added, deleted, or changed
since the file was last opened. While the file is open, changes made to its members are
immediately reflected in the access paths of those members, no matter what is specified for MAINT.
To prevent a lengthy rebuild time when the file is opened, *DLY should be specified only when the
number of changes to the access path between successive opens are small; that is, when the file is
opened frequently or when the key fields in records for this access path change infrequently. *DLY
is not valid for Access paths that require unique key values.

© Copyright IBM Corp. 1995, 2017 12-96


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
If the number of changes between a close and the next open reaches approximately 10% of the
access path size, the system stops saving changes and the access path is completely rebuilt the
next time the file is opened.
Access path recovery (RECOVER)
Specifies for files with immediate or delayed access path maintenance, when recovery processing
of the file is performed if the access path is being changed when a system failure occurs. This
parameter is valid only for a file with a keyed access path.
If *IMMED is specified for the MAINT parameter, the access path can be rebuilt during initial
program load (IPL) (before any user can run a job), or after IPL has ended (during jobs running at
the same time), or when the file is next opened. While the access path is being rebuilt, the file
cannot be used by any job.
During the IPL, an Override Access Path Recovery display lists those access paths that must be
recovered and the RECOVER parameter value for each access path. The user can override the
RECOVER parameter value on this display. More information on access paths is in the IBM Power
Systems with IBM i Information Center.
If *REBLD is specified for the MAINT parameter, the access path is rebuilt the next time its file is
opened.
The possible values are:
*NO: The access path of the file is rebuilt when the file is opened. *NO is the default for all files that
do not require unique keys. The file's access path, if not valid, is rebuilt when the file is next
opened.

Note

*NO is the default for all files that do not require unique keys.

*AFTIPL: The access path of the file is rebuilt after the initial program load (IPL) operation is
completed. This option allows other jobs not using this file to start processing immediately after the
completion of the IPL. If a job tries to allocate the file while its access path is being rebuilt, a file
open exception occurs.

Note

*AFTIPL is the default for all files that require unique keys.

*IPL: The access path of the file is rebuilt during the IPL operation. This ensures that the file's
access path is rebuilt before the first user program tries to use it. However, no jobs can start running
until after all files that specify RECOVER(*IPL) have their access paths rebuilt.

© Copyright IBM Corp. 1995, 2017 12-97


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Force keyed access path (FRCACCPTH)
Specifies, for files with key fields, whether access path changes are forced to auxiliary storage
along with the associated records in the file. FRCACCPTH(*YES) minimizes (but does not remove)
the possibility that an abnormal job end can cause damage to the access path that requires it to be
rebuilt.
The possible values are:
*NO: The access path and associated records are not forced to be written to auxiliary storage when
the access path is changed.
*YES: The access path and associated records are forced to be written to auxiliary storage when
the access path is changed. *YES cannot be specified whether *REBLD is specified on the Access
path maintenance prompt (MAINT parameter).
FRCACCPTH(*YES) slows the response time of the IBM i if the access path is changed in an
interactive job. If the access path is changed frequently, the overall performance of the IBM i is
decreased.

© Copyright IBM Corp. 1995, 2017 12-98


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

(GLW5HEXLOGRI$FFHVV3DWKV('75%'$3FRPPDQG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-72. Edit Rebuild of Access Paths: EDTRBDAP command

This display appears during an attended IPL after an abnormal system end.
The Edit Rebuild of Access Paths display shows the names of the file members that have
immediate or delayed maintenance access paths that are not valid.
The display allows you to rebuild the access path for a given member of the file. The access path
for a file member is marked as not valid when the system ends abnormally and the file member is in
use.
Files with journaled access paths and files with rebuild maintenance of the access path are not
shown on the Edit Rebuild Access Path display.
When a sequence value is selected and the Enter key is pressed, the status field is updated to
show the current rebuild condition of the access path.
The following sequence values can be selected:
1-99=Rebuild sequence
Rebuild during IPL (number less than IPL Threshold)
If the sequence value is a number less than or equal to the IPL threshold value, the access path is
rebuilt during the IPL. This recovery option ensures that the file's access path is rebuilt before the
job uses the file. Note that rebuilding access paths during the IPL causes the IPL to run longer.

© Copyright IBM Corp. 1995, 2017 12-99


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Rebuild after IPL (number greater than IPL Threshold)
If the sequence value is a number greater than the IPL threshold value, the access path is rebuilt
after the IPL is completed. Jobs cannot use a file whose access path is rebuilt after the IPL until the
rebuilding of the access path for the file is complete. However, jobs not using a file whose access
path is rebuilt after the IPL can begin running immediately after the IPL is complete.
*OPN=Rebuild at open
The access path is rebuilt when the file is next opened. If the access path has unique keys,
rebuilding the access path at open time prevents some applications from adding and updating
records to the file until the rebuild of the access path is complete.
*HLD=Hold the rebuild
The access path is rebuilt when the sequence value is changed to 1-99 or *OPN.
Sequence
The sequence in which access paths are rebuilt is determined by the values assigned to them. The
possible values include: whole numbers ranging from 1 through 99, *OPN, and *HLD. One (1)
represents the highest priority path and is rebuilt first. Whether paths with values 1 through 99 are
rebuilt before or after the IPL is determined by the value specified on the THRESHOLD parameter.
*OPN designates a value of 100, which means the access path is rebuilt the next time the file is
opened, and *HLD designates a value of 200, which means the access path is not rebuilt until the
value has been changed to *OPN or to a number ranging from 1 through 99.
Status
The status values are:
• RUN: The access path is being rebuilt
• READY: The access path is waiting to be rebuilt according to its sequence number
• WAIT: The access path is rebuilt when the required locks are obtained
• HELD: The access path is rebuilt when the user changes the sequence to *OPN or to a value
ranging from 1 through 99.

© Copyright IBM Corp. 1995, 2017 12-100


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

([SOLFLWDFFHVVSDWKMRXUQDOLQJ SURWHFWLRQ
‡ <RXGHFLGHZKLFKDFFHVVSDWKVWRSURWHFW

‡ 8QGHUO\LQJSK\VLFDOILOHVPXVWEHMRXUQDOHG

• STRJRNAP IRUILOHZLWKWKHDFFHVVSDWK

‡ $FFHVVSDWKDQGILOHXVHVDPHMRXUQDO

‡ (QFRGHGYHFWRUDFFHVVSDWKVDUHQRWHOLJLEOH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-73. Explicit access path journaling (protection)

As mentioned earlier, if your system ends abnormally when access paths are in use, the system
might have to rebuild the access paths before the database can be used again.
To perform an IPL on a large, busy IBM i that has ended abnormally can take many hours.
Two methods of access-path protection are available:
• Explicit journaling of access paths
• System-managed access-path protection
Explicit journal management can be used to keep a record of changes to access paths. This greatly
reduces the amount of time it takes the system to perform an IPL after it ends abnormally. However,
this method requires the user to decide which access paths should be journaled and how the
journaling should be controlled.
The need to protect some access paths might have be obvious but for other access paths, the need
might not be so obvious. For example, the use of a file might vary from time-to-time during the day
or even over a cycle as long as a year. It is easy to omit an access path. Protecting every access
path might consume system resources unnecessarily and omission of the wrong path could affect
availability in the event of an abnormal termination.

© Copyright IBM Corp. 1995, 2017 12-101


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Most users make a decision based on their experience with their applications.
An alternative to a user controlled access path protection scheme is to use the System Managed
Access Path Protection (SMAPP) facility.

© Copyright IBM Corp. 1995, 2017 12-102


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

6\VWHPPDQDJHGDFFHVVSDWKSURWHFWLRQ
‡ 5HGXFHV,3/WLPHDIWHUDEQRUPDOHQG

‡ 8VHUVHWVWDUJHWUHFRYHU\WLPH

‡ $XWRPDWLF
ƒ 'HWHUPLQHVZKLFKDFFHVVSDWKVWRMRXUQDO
ƒ $GMXVWVIRUV\VWHPKDUGZDUHDQGILOHFKDQJHV
ƒ )LOHVQRWMRXUQDOHG8VHVLQWHUQDOMRXUQDODQGUHFHLYHU
ƒ )LOHVDOUHDG\MRXUQDOHG8VHVVDPHMRXUQDODQGUHFHLYHU

‡ :LOOQRWGXSOLFDWHSURWHFWLRQLIDFFHVVSDWKDOUHDG\MRXUQDOHG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-74. System-managed access-path protection

You can allow the system to determine which access paths to protect. You specify target recovery
times for access paths for the entire system or for auxiliary storage pools (ASPs). Your system has
a default recovery time for access paths for the entire system of 90 minutes when it is shipped. You
can use the Edit Recovery for Access Paths (EDTRCYAP) command to see and change the target
recovery times for access paths and to see how much space the IBM i is using for system-managed
access-path protection (SMAPP).
SMAPP provides a simple method to reduce your recovery time after an abnormal system end.
SMAPP manages the required environment for you. You do not need to use any type of journal
management to use SMAPP.
• Automated
• You need not take any action to benefit
• Adapts to new LFs and APs as they arrive
• No files get overlooked
• Uses an algorithm somewhat similar to journaling without as much disk space or CPU overhead
• Can be customized to your needs
• You get to dial the level of protection you require

© Copyright IBM Corp. 1995, 2017 12-103


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
• You tell the system how much recovery time you can afford and the system tries to match it
• Is expected to have minimal performance impact/overhead
• Perhaps as low as 3 - 4%
• Even less if you want to specify a slightly longer recovery time
• Completely compatible with any journaling you are already using
• No need to change any of your current practices
• Does not require set up of a private User ASP
Some access paths are not eligible for protection by SMAPP including the following:
• Those defined for file that specifies MAINT(*REBLD)
• Any access path that is already explicitly journaled
• Any access path in the QTEMP library
• Any access path whose underlying physical files are journaled to different journals
• Any access path for a physical file that was created specifying FRCACCPTH(*YES)
• Any encoded vector access path
• Any access path that uses an international component for Unicode (ICU) sort sequence table
• A file journaled to a journal in standby state

© Copyright IBM Corp. 1995, 2017 12-104


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

60$33SHUIRUPDQFHDQGDX[LOLDU\VWRUDJHXVH
‡ /RZWDUJHWUHFRYHU\WLPHKDVJUHDWHULPSDFWRQSHUIRUPDQFH

‡ $V\QFKURQRXVZULWHVZKLFKGRQRWGLUHFWO\DIIHFWUHVSRQVHWLPHIRUD
WUDQVDFWLRQ

‡ 6SHFLI\WDUJHWUHFRYHU\WLPHVHLWKHUIRUHQWLUHV\VWHPRU$63VEXWQRW
ERWK

‡ 6WRUDJHVSDFHIRUMRXUQDOUHFHLYHUV
ƒ 6\VWHPPDQDJHVLQWHUQDOUHFHLYHUVSDFH
ƒ ,QWHUQDOUHFHLYHUVDUHPRUHFRQGHQVHG OHVVVSDFH 
ƒ 8VHVH[LVWLQJUHFHLYHULIILOHLVDOUHDG\EHLQJMRXUQDOHG
RCVSIZOPT(*RMVINTENT) VDYHVVSDFHDWDVPDOOSHUIRUPDQFHFRVW
ƒ ,WFDQEHWXUQHGRII

‡ ,QFUHDVHGGLVNDFWLYLW\

‡ 8VXDOO\VPDOOLPSDFWRQ&38
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-75. SMAPP performance and auxiliary storage use

Disk space consumed


• AP JRN requires customer to change Journal receivers, can overflow an ASP, and consumes
hundreds of megabytes per day
• SMAPP logging area is circular and consumes less space
• JRNRCVR placement
• AP JRN requires Journal placement on user ASP to achieve best performance
• SMAPP spreads logging area among fastest arms, with affinity for arms with write cache,
bundles writes to 32 KB, and performs 10 writes in parallel
• Performance impacts
• AP JRN performs a synchronous write to the disk for each DB operation (Add, Delete, Update)
• SMAPP provides just as good protection with bundled async writes thereby reducing total
number of writes and performance overhead

© Copyright IBM Corp. 1995, 2017 12-105


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

(GLW5HFRYHU\IRU$FFHVV3DWKV ('75&<$3

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-76. Edit Recovery for Access Paths (EDTRCYAP)

The Edit Recovery for Access Paths display shows a list of access path recovery times for the
system and for auxiliary storage pools (ASP) that are currently active on the system. The
information shown reflects the current target and estimated access path recovery times. Access
path and access path recovery information is shown also for all auxiliary storage pools (ASPs) if
they are active and if system-managed access-path protection has not been turned off (the system
access path recovery time value is not *OFF). On this list, you can type changes for the target
access path recovery times for the system and for the ASPs. You can also view updated access
path recovery status information.

Note

The ASP information is not shown when the system ASP (ASP 1) is the only ASP that is active. The
system does not keep track of the access path rebuild exposure when SMAPP protection is set to
*OFF.

© Copyright IBM Corp. 1995, 2017 12-106


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
Estimate system access path recovery time
The estimated system access path recovery time is the estimated total amount of time (in minutes)
that the system takes to recover the access paths on the system during initial program load (IPL)
after an abnormal system end. This value assumes that all access paths eligible for protection are
recovered or built at IPL.
Total storage used
The total amount of auxiliary disk storage used by internal objects that are used exclusively for
system-managed access-path protection (SMAPP). This value is expressed in megabytes
(1,000,000 bytes) and is the sum of the auxiliary storage used for access-path protection for each
auxiliary storage pool (ASP).
% of storage used
The total amount of auxiliary disk storage used exclusively for system-managed access-path
protection as a percentage of the total amount of system auxiliary disk storage.
System access path recovery time
The system access path recovery time can be changed by typing a new value over the current
value. The target system-managed system access path recovery time is the time (in minutes)
targeted for access-path protection for the system. Allowed values are:
• *SYSDFT
• *NONE
• *MIN
• *OFF
• 1 to 1440
ASP (auxiliary storage pool)
Each ASP configured on the IBM Power System with IBM i is listed, whether or not access paths
can be created on the ASP.
Recovery time
The target time for access path recovery and the estimated time for access path recovery are
shown for each auxiliary storage pool (ASP). You can change the target access path recovery time
for an ASP by typing a new value over the current value.
• Target access path recovery time is the time (in minutes) targeted for access-path protection
for the ASP.
• Estimated access path recovery time is the estimated amount of time (in minutes) that the
system takes to recover the access paths for the ASP during an initial program load (IPL) after
an abnormal system end.
Disk storage used
The disk storage used for system-managed access-path protection (SMAPP) in megabytes and as
a percentage of total auxiliary storage is shown for each auxiliary storage pool (ASP).
• Megabytes storage used: The amount of auxiliary disk storage being used on each ASP
exclusively for SMAPP. This value is expressed in megabytes (1,000,000 bytes).

© Copyright IBM Corp. 1995, 2017 12-107


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty
• % of storage used on ASP: The amount of auxiliary disk storage used exclusively for SMAPP
as a percentage of the total amount of auxiliary storage used. If the user ASP has overflowed
into the system ASP, this value is ++++++.

© Copyright IBM Corp. 1995, 2017 12-108


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

60$33FRQWULEXWLRQWRV\VWHPSHUIRUPDQFH RI
‡ 60$33KDVVRPHHIIHFWRQWKHRYHUDOOV\VWHPSHUIRUPDQFH

‡ 7KHORZHUWKHWDUJHWUHFRYHU\WLPH\RXVSHFLI\IRUDFFHVVSDWKVWKH
JUHDWHUWKLVHIIHFWPLJKWEH

‡ 7\SLFDOO\WKHHIIHFWLVQRWYHU\QRWLFHDEOHXQOHVVWKHSURFHVVRULV
QHDULQJLWVFDSDFLW\

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-77. SMAPP contribution to system performance (1 of 2)

© Copyright IBM Corp. 1995, 2017 12-109


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

60$33FRQWULEXWLRQWRV\VWHPSHUIRUPDQFH RI
‡ $QRWKHUVLWXDWLRQWKDWPLJKWFDXVHDQLQFUHDVHLQSURFHVVRU
FRQVXPSWLRQLVZKHQORFDOMRXUQDOVDUHSODFHGLQVWDQGE\VWDWH
DQGODUJHDFFHVVSDWKVEXLOWRYHUILOHVMRXUQDOHGWRWKHORFDOMRXUQDODUH
PRGLILHG

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-78. SMAPP contribution to system performance (2 of 2)

When journaled files (that have large access paths built over them) are modified while the journal is
in a standby state, processor use is increased and system performance can be impacted.

© Copyright IBM Corp. 1995, 2017 12-110


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

60$33VXPPDU\
‡ $XWRPDWLF
‡ 1RWPXFK'$6'FRQVXPHG
‡ 1RWPXFKSHUIRUPDQFHRYHUKHDG
‡ 'RHVQRWPLVVDQ\ILOHV
‡ 1HHGVQRVSHFLDOVHWXSQR$63VUHTXLUHG
‡ 1RVSHFLDOKDUGZDUH
‡ &RYHUVEURDGVSHFWUXPRIRXWDJHFDXVHV
‡ 6XEVWDQWLDO,3/UHFRYHU\WLPHUHGXFWLRQV

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-79. SMAPP summary

There are several advantages to SMAPP that make its use worth investigating.

© Copyright IBM Corp. 1995, 2017 12-111


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 :KLFKRIWKHIROORZLQJLVQRWDYDOLGREMHFWWKDWFDQEH
MRXUQDOHG"
D 'DWDEDVHILOHV
E 'DWDDUHD
F 'DWDTXHXH
G 5RRWIROGHUV

 $ EODQN LVDSURJUDPWKDWLQWHUFHSWVDFWLYLW\WRDQREMHFWWKDWLV
EHLQJMRXUQDOHG
D -RXUQDO
E -RXUQDOUHFHLYHU
F 7ULJJHU
G 5HIHUHQWLDOFRQVWUDLQW

 :KDWLVWKHILUVWREMHFWWKDWQHHGVWREHFUHDWHGZKHQ\RXVWDUW
MRXUQDOLQJ"
D -RXUQDODXGLWWUDLO
E -RXUQDOUHFHLYHU
F -RXUQDO
G -RXUQDODFFHVVSDWK
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-80. Review questions (1 of 6)

© Copyright IBM Corp. 1995, 2017 12-112


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 :KLFKRIWKHIROORZLQJLVQRWDYDOLGREMHFWWKDWFDQEHMRXUQDOHG"
D'DWDEDVHILOHV
E'DWDDUHD
F'DWDTXHXH
G5RRWIROGHUV
7KHDQVZHULVURRWIROGHUV

 $MRXUQDO LVDSURJUDPWKDWLQWHUFHSWVDFWLYLW\WRDQREMHFWWKDWLV
EHLQJMRXUQDOHG
D-RXUQDO
E-RXUQDOUHFHLYHU
F7ULJJHU
G5HIHUHQWLDOFRQVWUDLQW
7KHDQVZHULVMRXUQDO

 :KDWLVWKHILUVWREMHFWWKDWQHHGVWREHFUHDWHGZKHQ\RXVWDUW
MRXUQDOLQJ"
D-RXUQDODXGLWWUDLO
E-RXUQDOUHFHLYHU
F-RXUQDO
G-RXUQDODFFHVVSDWK
7KHDQVZHULVMRXUQDOUHFHLYHU
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-81. Review answers (1 of 6)

© Copyright IBM Corp. 1995, 2017 12-113


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 :KLFKREMHFWFRQWDLQVWKHLPDJHVDQGGHWDLOVRIWKHREMHFWV
WKDWDUHEHLQJMRXUQDOHG"
D -RXUQDODXGLWWUDLO
E -RXUQDOUHFHLYHU
F -RXUQDO
G -RXUQDODFFHVVSDWK

 :KDWLVWKHFRPPDQGXVHGWRFUHDWHWKHMRXUQDO"
a. CRTJRN
b. CRTJRNRCV
c. STRJRNAP
d. STRJRNPF

 7UXHRUIDOVH7KHPDQDJHPHQWRIMRXUQDOUHFHLYHUVLV
VRPHWKLQJWKDWPXVWEHGRQHE\WKHGDWDEDVHDGPLQLVWUDWRU

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-82. Review questions (2 of 6)

© Copyright IBM Corp. 1995, 2017 12-114


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 :KLFKREMHFWFRQWDLQVWKHLPDJHVDQGGHWDLOVRIWKHREMHFWVWKDW
DUHEHLQJMRXUQDOHG"
D -RXUQDODXGLWWUDLO
E -RXUQDOUHFHLYHU
F -RXUQDO
G -RXUQDODFFHVVSDWK
7KHDQVZHULVMRXUQDOUHFHLYHU

 :KDWLVWKHFRPPDQGXVHGWRFUHDWHWKHMRXUQDO"
a. CRTJRN
b. CRTJRNRCV
c. STRJRNAP
d. STRJRNPF
7KHDQVZHULVCRTJRN

 7UXHRU)DOVH7KHPDQDJHPHQWRIMRXUQDOUHFHLYHUVLVVRPHWKLQJ
WKDWPXVWEHGRQHE\WKHGDWDEDVHDGPLQLVWUDWRU
7KHDQVZHULVIDOVH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-83. Review answers (2 of 6)

© Copyright IBM Corp. 1995, 2017 12-115


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 7KH EODQN FRPPDQGLVXVHGWRVHHWKHDWWULEXWHVDVVRFLDWHGZLWK
\RXUMRXUQDO
a. WRKJRN
b. CRTJRN
c. DSPJRNA
d. WRKJRNA

 :KDWFRPPDQGLVXVHGWRUHYLHZWKHGHWDLOVRIREMHFWVEHLQJ
MRXUQDOHG"
a. WRKJRN
b. DSPJRN
c. WRKJRNA
d. DSPJRNA

 7UXHRUIDOVH:KHQGLVSOD\LQJMRXUQDOLQIRUPDWLRQ\RXFDQVSHFLI\
WRRQO\VKRZWUDQVDFWLRQVSHUIRUPHGE\DVSHFLILFSURJUDP

 7UXHRUIDOVH8VHUJHQHUDWHGHQWULHVJHWSODFHGLQWRDMRXUQDO
UHFHLYHUZKHQWKHXVHUVHOHFWVDQRSWLRQWRJHQHUDWHDV\VWHP
PHVVDJH
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-84. Review questions (3 of 6)

© Copyright IBM Corp. 1995, 2017 12-116


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 7KHWRKJRNA FRPPDQGLVXVHGWRVHHWKHDWWULEXWHVDVVRFLDWHGZLWK\RXUMRXUQDO
a. WRKJRN
b. CRTJRN
c. DSPJRNA
d. WRKJRNA
7KHDQVZHULVWRKJRNA

 :KDWFRPPDQGLVXVHGWRUHYLHZWKHGHWDLOVRIREMHFWVEHLQJMRXUQDOHG"
a. WRKJRN
b. DSPJRN
c. WRKJRNA
d. DSPJRNA
7KHDQVZHULVDSPJRN

 7UXH RU)DOVH:KHQGLVSOD\LQJMRXUQDOLQIRUPDWLRQ\RXFDQVSHFLI\WRRQO\VKRZ
WUDQVDFWLRQVSHUIRUPHGE\DVSHFLILFSURJUDP
7KHDQVZHULVWUXH

 7UXHRUIDOVH8VHUJHQHUDWHGHQWULHVJHWSODFHGLQWRDMRXUQDOUHFHLYHUZKHQWKH
XVHUVHOHFWVDQRSWLRQWRJHQHUDWHDV\VWHPPHVVDJH
7KHDQVZHULVIDOVH
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-85. Review answers (3 of 6)

© Copyright IBM Corp. 1995, 2017 12-117


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH:KHQDEDGEDWFKRIWUDQVDFWLRQVLVSHUIRUPHG
DJDLQVWDQREMHFWEHLQJMRXUQDOHGWKHRQO\ZD\WREULQJWKDWREMHFW
EDFNWRDJRRGSRLQWLVWRUHVWRUHWKDWREMHFWRIIRI\RXUEDFNXS
PHGLDDQGUHNH\DJRRGEDWFKRIUHFRUGV

 7UXHRUIDOVH:KHQSHUIRUPLQJDIRUZDUGUHFRYHU\WKHV\VWHP
DVVLVWV\RXZLWKWKHUHFRYHU\RIMRXUQDOHGREMHFWVE\SURPSWLQJ\RX
ZLWKWKHPLVVLQJREMHFWQDPH

 7UXHRUIDOVH-RXUQDOLQJDQGVDYLQJFKDQJHGREMHFWVDUHWZR
UHFRYHU\PHWKRGVWKDWFDQQRWEHXVHGWRJHWKHURUDWWKHVDPHWLPH
ZLWKWKHVDPHREMHFWV

 :KLFKRIWKHIROORZLQJLVWKHFRPPDQGXVHGWRVDYHWKRVHREMHFWV
WKDWKDYHFKDQJHGVLQFHWKHODVWWLPHWKDWREMHFWZDVFKDQJHG
a. SAVLIBCHG
b. SAVOBJCHG
c. SAVCHGOBJ
d. SAVCHGLIB

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-86. Review questions (4 of 6)

© Copyright IBM Corp. 1995, 2017 12-118


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH:KHQDEDGEDWFKRIWUDQVDFWLRQVLVSHUIRUPHGDJDLQVWDQREMHFW
EHLQJMRXUQDOHGWKHRQO\ZD\WREULQJWKDWREMHFWEDFNWRDJRRGSRLQWLVWR
UHVWRUHWKDWREMHFWRIIRI\RXUEDFNXSPHGLDDQGUHNH\DJRRGEDWFKRIUHFRUGV
7KHDQVZHULVIDOVH

 7UXH RUIDOVH:KHQSHUIRUPLQJDIRUZDUGUHFRYHU\WKHV\VWHPDVVLVWV\RXZLWK


WKHUHFRYHU\RIMRXUQDOHGREMHFWVE\SURPSWLQJ\RXZLWKWKHPLVVLQJREMHFW
QDPH
7KHDQVZHULVWUXH

 7UXHRUIDOVH-RXUQDOLQJDQGVDYLQJFKDQJHGREMHFWVDUHWZRUHFRYHU\
PHWKRGVWKDWFDQQRWEHXVHGWRJHWKHURUDWWKHVDPHWLPHZLWKWKHVDPH
REMHFWV
7KHDQVZHULVIDOVH

 :KLFKRIWKHIROORZLQJLVWKHFRPPDQGXVHGWRVDYHWKRVHREMHFWVWKDWKDYH
FKDQJHGVLQFHWKHODVWWLPHWKDWREMHFWZDVFKDQJHG
a. SAVLIBCHG
b. SAVOBJCHG
c. SAVCHGOBJ
d. SAVCHGLIB
7KHDQVZHULVSAVCHGOBJ
-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-87. Review answers (4 of 6)

© Copyright IBM Corp. 1995, 2017 12-119


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH2EMHFWVWKDWKDYHDKLJKFKDQJHYROXPHDUH
SULPHFDQGLGDWHVWKDWVKRXOGEHMRXUQDOHG

 7UXHRUIDOVH)RUWKHEHVWSHUIRUPDQFHRQ\RXUV\VWHPLWLV
EHWWHUWRKDYHMXVWRQHMRXUQDOIRUDOORIWKHREMHFWVEHLQJ
MRXUQDOHGRQWKHV\VWHP

 7UXHRUIDOVH-RXUQDOHGILOHVPXVWEHLQWKHVDPHOLEUDU\
$63DVWKHMRXUQDOHGILOH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-88. Review questions (5 of 6)

© Copyright IBM Corp. 1995, 2017 12-120


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH2EMHFWVWKDWKDYHDKLJKFKDQJHYROXPHDUH
SULPHFDQGLGDWHVWKDWVKRXOGEHMRXUQDOHG
7KHDQVZHULVWUXH

 7UXH RUIDOVH)RUWKHEHVWSHUIRUPDQFHRQ\RXUV\VWHPLWLV


EHWWHUWRKDYHMXVWRQHMRXUQDOIRUDOORIWKHREMHFWVEHLQJ
MRXUQDOHGRQWKHV\VWHP
7KHDQVZHULVWUXH

 7UXHRUIDOVH-RXUQDOHGILOHVPXVWEHLQWKHVDPHOLEUDU\
$63DVWKHMRXUQDOHGILOH
7KHDQVZHULVIDOVH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-89. Review answers (5 of 6)

© Copyright IBM Corp. 1995, 2017 12-121


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH$FFHVVSDWKSURWHFWLRQZLOOFXWGRZQRQWKH
DPRXQWRIWLPHLWWDNHVDV\VWHPWR,3/DIWHUDQDEQRUPDO
V\VWHPHQG

 7UXHRUIDOVH-RXUQDOLQJFDQDOVREHXVHGWRSURWHFWDFFHVV
SDWKV

 7UXHRUIDOVH$W,3/WLPHWKHV\VWHPZLOOVKRZ\RXDVFUHHQ
WKDWOLVWVDOORIWKRVHREMHFWVZKRVHDFFHVVSDWKVDUHEHLQJ
SURWHFWHG MRXUQDOHG DQGKDYHDOUHDG\EHHQUHFRYHUHG
EDVLFDOO\DVFUHHQWRVKRZ\RXZKDWKDVDOUHDG\EH
UHFRYHUHG 

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-90. Review questions (6 of 6)

© Copyright IBM Corp. 1995, 2017 12-122


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH$FFHVVSDWKSURWHFWLRQZLOOFXWGRZQRQWKH
DPRXQWRIWLPHLWWDNHVDV\VWHPWR,3/DIWHUDQDEQRUPDO
V\VWHPHQG
7KHDQVZHULVWUXH

 7UXH RUIDOVH-RXUQDOLQJFDQDOVREHXVHGWRSURWHFWDFFHVV


SDWKV
7KHDQVZHULVWUXH

 7UXHRUIDOVH$W,3/WLPHWKHV\VWHPZLOOVKRZ\RXDVFUHHQ
WKDWOLVWVDOORIWKRVHREMHFWVZKRVHDFFHVVSDWKVDUHEHLQJ
SURWHFWHG MRXUQDOHG DQGKDYHDOUHDG\EHHQUHFRYHUHG
EDVLFDOO\DVFUHHQWRVKRZ\RXZKDWKDVDOUHDG\EH
UHFRYHUHG 
7KHDQVZHULVIDOVH

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-91. Review answers (6 of 6)

© Copyright IBM Corp. 1995, 2017 12-123


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 12. Journal management

Uempty

8QLWVXPPDU\
‡ 'HVFULEHKRZMRXUQDOPDQDJHPHQWFDQEHXVHGWRUHFRYHUGDWDORVW
GXULQJDIDLOXUH
‡ ,PSOHPHQWMRXUQDOPDQDJHPHQWRQ,%0LDVSDUWRIDFRPSUHKHQVLYH
UHFRYHU\SODQ
‡ /LVWWKHDGYDQWDJHVDQGFRQVLGHUDWLRQVRIMRXUQDOPDQDJHPHQW
‡ /LVWWKHDGYDQWDJHVDQGFRQVLGHUDWLRQVRIMRXUQDOLQJDFFHVVSDWKV
‡ 'HVFULEHUHPRWHMRXUQDOLQJDQGKRZLWFDQEHXVHGWRUHSOLFDWHGDWDRU
WRLPSOHPHQWDKRWEDFNXSHQYLURQPHQWRQDUHPRWHV\VWHP

-RXUQDOPDQDJHPHQW ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 12-92. Unit summary

© Copyright IBM Corp. 1995, 2017 12-124


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

Unit 13. Commitment control overview


Estimated time
01:00

Overview
Commitment Control is an extension of journaling and is designed to help you recover more
complex transactions. The information that is covered in this unit is an overview because you must
be a programmer to initiate and use Commitment Control. Specific details on the programming that
is required to implement commitment control is taught in course AS10 (System I RPG IV Advanced
Programming Workshop).

How you will check your progress


• Review questions
• Exercise

© Copyright IBM Corp. 1995, 2017 13-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHWKHIXQFWLRQVDQGFRQVLGHUDWLRQVRIFRPPLWPHQWFRQWURO
‡ 'HVFULEHKRZWRLPSOHPHQWFRPPLWPHQWFRQWURO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 13-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

:KDWLVFRPPLWPHQWFRQWURO"
‡ &RPPLWPHQWFRQWUROLVDIXQFWLRQWKDWHQVXUHVLQWHJULW\
ƒ ,WDOORZV\RXWRGHILQHDQGSURFHVVDJURXSRIFKDQJHVWRUHVRXUFHVVXFKDV
GDWDEDVHILOHVRUWDEOHVDVDWUDQVDFWLRQ
ƒ ,WHQVXUHVWKDWHLWKHUWKHHQWLUHJURXSRILQGLYLGXDOFKDQJHVRFFXURQDOO
V\VWHPVWKDWSDUWLFLSDWHRUWKDWQRQHRIWKHFKDQJHVRFFXU

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-2. What is commitment control?

You can use commitment control to design an application so the system can restart the application
if a job, an activation group within a job, or the system ends abnormally.
With commitment control, you can have assurance that when the application starts again, no partial
updates are in the database due to incomplete transactions from a prior failure.
A transaction is a group of individual changes to objects on the system that appears as a single
atomic change to the user.
You can find two terms the term transaction and Logical Unit of Work (LUW). The two terms are
interchangeable.

© Copyright IBM Corp. 1995, 2017 13-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

:K\FRPPLWPHQWFRQWURO"
‡ 6XSSRVHWKHIROORZLQJ
ƒ $QDSSOLFDWLRQ VGDWDEDVHILOHVDUHEHLQJMRXUQDOHG
ƒ 0XOWLSOHXVHUVDUHHQWHULQJWUDQVDFWLRQVLQYROYLQJPXOWLSOHILOHV
ƒ 7KHV\VWHPHQGVDEQRUPDOO\

‡ 3HUIRUPLQJDUHFRYHU\WKURXJKAPYJRNCHG RURMVJRNCHG PLJKW


SUHVHQWWKHVLWXDWLRQZKHUHWKHUHPLJKWQRWEHDUHFRYHU\SRLQWLQZKLFK
WKHDSSOLFDWLRQILOHVUHIOHFWRQO\ZKROHWUDQVDFWLRQV

‡ 7KHVROXWLRQLVFRPPLWPHQWFRQWURO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-3. Why commitment control?

In an environment where multiple users are keying in transactions using the same application and
the same data files, it is possible that journaling might not provide the best solution to recover from
an abnormal system or application end.
If you are only using journaling, there might not be a single recovery point that can be used to
recover all of the completed transactions. A single point recovery under these conditions might
require rekeying on the part of most of the users.
Commitment control provides a recovery method in which each user can have a unique recovery
point. It allows you to define and process a complex transaction (multiple changes to the database)
as a single unit of work.
Using commitment control, you can design an application that can be restarted for each job that
terminates abnormally. It ensures that all changes within a transaction are completed for the files
affected. It also provides facilities to remove changes when a user determines that a transaction is
not considered a complete transaction or is in error.

© Copyright IBM Corp. 1995, 2017 13-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

&RPSOH[WUDQVDFWLRQVZLWKPXOWLSOHXVHUV
'LVSOD\MRXUQDOHQWULHV

6HTXHQFH &RGH 7\SH 2EMHFW /LEUDU\ -RE 7LPH


 5 83 ,7(0 $'0&7/ : 
 5 83 ,7(0 $'0&7/ : 
 5 83 '(7$,/ $'0&7/ : 
 5 83 '(7$,/ $'0&7/ : 
 5 83 ,7(0 $'0&7/ : 
 5 83 ,7(0 $'0&7/ : 
 5 83 ,7(0 $'0&7/ : 
 5 83 '(7$,/ $'0&7/ : 
 5 83 '(7$,/ $'0&7/ : 
 ) &/ ,7(0 $'0&7/ : 
 ) &/ '(7$,/ $'0&7/ : 

" :KDWLVWKHUHFRYHU\SRLQW"
 /HDYHVXQILQLVKHG
 2PLWVFRPSOHWHWUDQVDFWLRQVIRU
:DQG:
&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-4. Complex transactions with multiple users

The example on the visual shows that the transactions that are considered complete are:
• Sequence #20 and sequence #23
• Sequence #21 and sequence #22
• Sequence #25 and sequence #27
• Sequence #26 and sequence #28
If you choose to start the recovery at sequence #20 through Sequence #28, the problem is that
sequence #24 is not a complete transaction and thus produces data that is damaged or corrupted.
On the other hand, you choose to start the recovery at sequence #20 through Sequence #23, now
the problem is that several transactions that are considered complete (sequence #25 - #28) is work
that will have to be redone, data that will have to be rekeyed.
This is a problem that will grow exponentially as more and more operators are keying in data in this
application environment.

© Copyright IBM Corp. 1995, 2017 13-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

)XQFWLRQVRIFRPPLWPHQWFRQWURO

‡ $OORZVDWUDQVDFWLRQWREHGHILQHG

‡ (QVXUHVWKDWLQFRPSOHWHWUDQVDFWLRQVDUHUROOHGEDFNLID
MRERUWKHV\VWHPHQGVDEQRUPDOO\

‡ 3HUPLWVUROOEDFNE\LQGLYLGXDOXVHU

‡ 3URYLGHVLQIRUPDWLRQIRUWKHUHVWDUWRIDQDSSOLFDWLRQLQWKH
HYHQWRIDMRERUV\VWHPIDLOXUH

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-5. Functions of commitment control

© Copyright IBM Corp. 1995, 2017 13-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

&RPPLWPHQWFRQWURO2YHUYLHZ
Sign On

Journal Entries

C BC . . . . . . . . . . . . . STRCMTCTL

CALL
&RPPLWPHQWGHILQLWLRQ

F OP . . . . . . . . . . . . . . . . .OPEN FILES
C SC . . . . . . . . . . . . . . . . .READ ITEM
&RPPLW
-2%

READ DETAIL
F\FOH

R UB Record Before . . . . . . . . . .UPDATE ITEM


R UP Record After
R UB Record Before . . . . . . . . . .UPDATE DETAIL
R UP Record After
C CM Commit Identification . . . . . .COMMIT Commit Identification

F CL . . . . . . . . . . . . . . . . .CLOSE FILES

C EC . . . . . . . . . . . . . ENDCMTCTL

SIGNOFF

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-6. Commitment control: Overview

A commitment definition includes:


• Parameters on the STRCMTCTL command
• Current status of the commitment definition
• Information about database files and other committable resources that contain changes that are
made during the current logical unit of work.
An application transaction should fall exactly within a commit cycle. A commit cycle is the time from
one commitment boundary to the next. The system assigns a commit cycle identifier to associate all
of the journal entries for a particular commit cycle together. Each journal that participates in a
transaction has its own commit cycle and its own commit cycle identifier.
Reprogramming of an application is required to implement commitment control. Specifically:
• To use commit in a program, the files have to be opened for commitment control.
• The commit identification is whatever information the programmer includes in the commit
operation. It is used to identify a restart point for the application.
• For rollbacks other than programmed rollback operations, the commit identification is written to
a notify object, if one is specified.

© Copyright IBM Corp. 1995, 2017 13-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

5ROOEDFNHYHQW
‡ 8QFRPPLWWHGFKDQJHVH[LVWDQG
ƒ 1RUPDORUDEQRUPDOHQGRIMRERUV\VWHP
ƒ ENDCMTCTL UXQ
í %DWFKMRE
í ,QWHUDFWLYHMREDQG5%LVWKHUHVSRQVHWRPHVVDJH
CPA8350
“ENDCMTCTL requested with changes pending (RB C CM)”
ƒ +//UROOEDFNRSHUDWLRQ

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-7. Rollback event

A rollback operation removes all changes made within a transaction since the previous commit
operation or rollback operation. During a rollback operation, the system also releases locks related
to the transaction. If the system contains thousands of transactions, the system can take hours to
complete a rollback operation. These long-running rollbacks can consume critical processor time,
lock resources or take up storage space.
Before you end a long-running rollback, you need to know which commitment definitions are being
rolled back and what state the commitment definitions are in. The State field for commitment
definitions that are rolling back is set to ROLLBACK IN PROGRESS.
Use the Work with Commitment Definitions (WRKCMTDFN) command to check the status of a
rollback by following these steps:
• Type WRKCMTDFN JOB(*ALL) from the character-based interface.
• Press F11 to display the State field.
Disable the ability to end a long-running rollback
Users with *ALLOBJ special authority can end rollbacks by default. If you want to restrict users who
have *ALLOBJ special authority from ending rollbacks, you can do this by creating data area
QGPL/QTNNOENDRB.

© Copyright IBM Corp. 1995, 2017 13-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

3UHYLRXVH[DPSOHZLWKFRPPLWPHQWFRQWURO
Sequence Code Type Object Library Job Time
20 C SC W1 10:21:15
21 R UB ITEM Before ADMCTL W1 10:21:15
22 R UP ITEM After ADMCTL W1 10:21:55
23 C SC W333 10:26:17
&RPSOHWH

24 R UB ITEM Before ADMCTL W333 10:26:17


25 R UP ITEM After ADMCTL W333 10:27:19
26 R UB DETAIL Before ADMCTL W333 10:27:23
27 R UP DETAIL After ADMCTL W333 10:27:40
28 C CM W333 10:28:35
29 C SC W22 10:28:45
30 R UB ITEM Before ADMCTL W22 10:29:12
31 R UP ITEM After ADMCTL W22 10:30:24

5ROOEDFNHYHQW
32 J IA 12:20:00
33 R UR ITEM After ADMCTL W22 12:21:15
34 R BR ITEM Before ADMCTL W22 12:21:18
35 C RB W22 12:21:30
36 R UR ITEM After ADMCTL W1 12:21:40
37 R BR ITEM Before ADMCTL W1 12:21:45
38 C RB W1 12:21:55
&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-8. Previous example with commitment control

1. Before the Rollback event, the transaction for job W333 is complete, but the transactions for W1
and W22 are incomplete.
2. Then a Rollback event occurs, it could be one of the following:
a. An implicit Rollback originating from the system.
b. A Rollback originating from a program Rollback instruction.
3. The completed transaction for job W333 is unaffected by the Rollback.
4. The incomplete transactions for jobs W1 and W22 are rolled back.
The system rolls back any uncommitted transactions.
• Record before image is entered in the journal as type UR.
• The image after the rollback is entered as type BR.
• DR identifies record deleted or rollback.
• IA identifies an IPL following an abnormal system termination.

© Copyright IBM Corp. 1995, 2017 13-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

&RPPLWPHQWFRQWUROUHTXLUHPHQWV
‡ ,QRUGHUWRLPSOHPHQWFRPPLWPHQWFRQWUROWKHIROORZLQJFRQGLWLRQVPXVW
EHPHW
ƒ $OOGDWDEDVHILOHVXQGHUFRPPLWPHQWFRQWUROPXVWEHMRXUQDOHG
ƒ %27+LPDJHV DXWRPDWLFIRUILOHVRSHQHGXQGHUFRPPLWPHQWFRQWURO 
ƒ -REPXVWLVVXHWKHSTRCMTCTL DQGWKHENDCMTCTL FRPPDQGV
ƒ 3URJUDPVPXVWRSHQILOHVIRUFRPPLWPHQWFRQWURO
ƒ 3URJUDPPXVWLVVXHCOMMIT RSHUDWLRQ

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-9. Commitment control requirements

If only after images are specified to be journaled, the system also journals the before images of the
files while those files are under commitment control.

© Copyright IBM Corp. 1995, 2017 13-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

6WDUW&RPPLWPHQW&RQWURO 675&07&7/

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-10. Start Commitment Control (STRCMTCTL)

The Start Commitment Control (STRCMTCTL) command is used to establish either a job level or
activation group level commitment definition.
This command also specifies the level of record locking that occurs for the commitment definition to
be started. Also, a notify object can be specified.
Before a commitment definition is established, the user must ensure that all database files that are
to be opened under commitment control for a single commitment transaction are journaled. If only
the after images are being journaled, the IBM Power System with IBM i implicitly begins journaling
both the before and the after images for the duration of the changes being made to files opened
under this commitment definition.
A default journal can be specified. Entries that describe all journals and systems involved in a
commitment control operation can be placed in this journal.
Commitment definition scope (CMTSCOPE)
The scope of a commitment definition determines which programs use that commitment definition,
and how locks acquired during transactions are scoped. The interface that starts the commitment
definition determines the scope of the commitment definition. Specifies the scope for the
commitment definition to be started. The possible values are:

© Copyright IBM Corp. 1995, 2017 13-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty
• *ACTGRP: An activation-group-level commitment definition is started for the activation group
associated with the program issuing the command.
• *JOB: The job-level commitment definition is started for the job. It specifies text that briefly
describes the commitment definition to be started. It specifies the default journal. The default
journal contains entries identifying each of the resources involved in a unit of work. Entries can
also be placed when each unit of work starts or ends due to a commit or rollback operation,
depending on the OMTJRNE parameter value.
Journal entries to be omitted (OMTJRNE)
Specifies the journal entries to omit from the default journal. If *NONE is specified on the DFTJRN
parameter, this is ignored. The possible values are:
• *NONE: No journal entries are omitted.
• *LUWID: The journal entry that contains the Logical Unit of Work Identifier (LUWID) and all the
resources involved in the logical unit of work, are omitted if the logical unit of work is committed
or rolled back successfully. If an error occurs while committing or rolling back the logical unit of
work, the entry will always be sent regardless of this value.
The default values for the parameters are underlined.
Commitment control does not need to be started by SQL applications. SQL implicitly starts
commitment control at connect time when the SQL isolation level is not *NONE.

© Copyright IBM Corp. 1995, 2017 13-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

5HFRUGORFNOHYHOSDUDPHWHU
• STRCMTCTL LCKLVL ( )
ƒ CHG 5HFRUGDGGVXSGDWHVDQGGHOHWHVDUHSURWHFWHGIURPFKDQJHVE\
RWKHUMREVXQWLOFRPPLWRUUROOEDFN

ƒ CS &KDQJHGDQGUHWULHYHGUHFRUGVDUHSURWHFWHGIURPFKDQJHVE\RWKHU
MREV5HWULHYHGUHFRUGVWKDWDUHQRWFKDQJHGDUHSURWHFWHGRQO\XQWLOWKH\DUH
UHOHDVHGRUDGLIIHUHQWUHFRUGIURPWKHVDPHILOHLVUHWULHYHG

ƒ ALL &KDQJHGDQGUHWULHYHGUHFRUGVDUHSURWHFWHGXQWLOFRPPLWRUUROOEDFN

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-11. Record lock-level parameter

Lock Level (LCVLVL)


Specifies the default level of record locking that occurs for the commitment definition to be started.
This is a required parameter.
The possible values are:
*CHG
Every record read for update (for a file opened under commitment control) is locked. If a record is
changed, added, or deleted, that record remains locked until the transaction is committed or rolled
back. Records that are accessed for update operations but are released without being changed are
unlocked.
*CS
Every record accessed for files opened under commitment control is locked. A record that is read,
but not changed or deleted, is unlocked when a different record is read. Records that are changed,
added, or deleted are locked until the transaction is committed or rolled back.
*ALL
Every record access for files opened under commitment control is locked until the transaction is
committed or rolled back.

© Copyright IBM Corp. 1995, 2017 13-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

1RWLI\REMHFWSDUDPHWHU
• STRCMTCTL NFYOBJ(object object-type)
ƒ 3URJUDPPHUFDQSURYLGHLQIRUPDWLRQIRUDUHVWDUWDIWHUDQDEQRUPDOHQG
ƒ 6SHFLI\HLWKHU FILE DTAARARU MSGQ WRLGHQWLI\WKHODVWVXFFHVVIXO
WUDQVDFWLRQ FRPPLW LIFRPPLWGHILQLWLRQHQGVDEQRUPDOO\
ƒ &RPPLWLGHQWLILFDWLRQFDQLGHQWLI\ODVWVXFFHVVIXOWUDQVDFWLRQ
í &KDUDFWHUGDWDVSHFLILHGRQ+// &/53*3/RU& FRPPLWRSHUDWLRQ
í (QWU\VSHFLILFGDWDRIFRPPLW &&0 MRXUQDOHQWU\
ƒ 7KLVLVDQRSWLRQDOSDUDPHWHU

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-12. Notify object parameter

The notify object parameter is specified on the STRCMTCTL command.


Notify Object (NFYOBJ)
It specifies the name and type of the object where notification is sent regarding the status of a
transaction for a commitment definition.
For a system failure, the commitment identifier is placed in the notify object after the next
successful initial program load (IPL). For a job that ends with uncommitted changes or with a
nonzero completion code, the commitment identifier is placed in the notify objects during end job
processing. For an activation group that ends with uncommitted changes or ends normally, the
notification text is placed in the notify object during activation group end processing.
*NONE
No notification is sent after an abnormal system or process end.
Object-name
Specify the name (library-name/object-name) of the object to receive notification of the last
transaction that is successfully committed. You must have correct authority for the object specified.
The possible object type values are:

© Copyright IBM Corp. 1995, 2017 13-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty
• *MSGQ: The text identifying the last commitment boundary is placed on the specified message
queue.
• *DTAARA: The text identifying the last commitment boundary is placed in the specified data
area. The data area specified must be of type character, and unique to this job. The text is
padded or truncated to fit the data area.
• *FILE: The text identifying the last commitment boundary is added to the specified physical file.

© Copyright IBM Corp. 1995, 2017 13-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

:KHQLVWKHQRWLI\REMHFWXSGDWHG"
‡ $WOHDVWRQHVXFFHVVIXOFRPPLWDQGDQ\RIWKHIROORZLQJFRQGLWLRQV
ƒ $EQRUPDOMREHQGRUDQDEQRUPDOV\VWHPHQG
í 5ROOEDFNRFFXUVLIWKHUHDUHXQFRPPLWWHGFKDQJHV
ƒ 1RUPDO(2-DQGXQFRPPLWWHGFKDQJHVH[LVW
í 5ROOEDFNDOVRRFFXUVLQWKLVFDVH
ƒ ENDCMTCTL ZLWKXQFRPPLWWHGFKDQJHV
í %DWFKMREWKHFKDQJHVDUHUROOHGEDFN
í ,QWHUDFWLYHMREJHWV&3$ENDCMTCTL UHTXHVWHGZLWKFKDQJHVSHQGLQJ 5%&
&0 DQGUHVSRQVH5%RU&0LVWDNHQ)RU&0UHVSRQVHWKHFRPPLWLGHQWLILHULV
HQWHUHGRQWKHSURPSWGLVSOD\

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-13. When is the notify object updated?

Notify object is used as part of programmer-written error handling procedure.


After an abnormal end, a program upon restart, could interrogate the notify object to get information
about restarting the application.
During normal processing of the application, the programmer would include on the commit
operation, after each transaction, a commit identification to identify that transaction.
Each application should have its own notify object if the object type is *FILE or *MSGQ and the
commit identification should include an identification of the job or user who made the transaction.
If the notify object is a *DTAARA, there should be a notify object for each combination of application
and user.

© Copyright IBM Corp. 1995, 2017 13-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

&RPPLWPHQWFRQWUROLPSOHPHQWDWLRQ
‡ ,GHQWLI\WKHDSSOLFDWLRQWKDWZLOOXVHFRPPLWPHQWFRQWURO

‡ -RXUQDODOORIWKHSK\VLFDOILOHVXVHGE\WKLVDSSOLFDWLRQ

‡ 0RGLI\WKHDSSOLFDWLRQSURJUDPV
ƒ )LOHVXVHGE\WKHDSSOLFDWLRQPXVWQRZEHRSHQHGIRUFRPPLW
ƒ 7KHDSSOLFDWLRQPXVWEHXSGDWHGWRGHILQHORJLFDOWUDQVDFWLRQERXQGDULHV
ƒ 8VHUROOEDFNLIGHVLUHG

‡ 0RGLI\&/SURJUDPVWRLQFOXGHSTRCMTCTL DQGENDCMTCTL

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-14. Commitment control implementation

© Copyright IBM Corp. 1995, 2017 13-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

&RPPLWPHQWFRQWURO&RQVLGHUDWLRQV
‡ $IWHUIDLOXUHDSSOLFDWLRQVDUHDWWUDQVDFWLRQERXQGDULHV

‡ 5HFRUGVDUHORFNHGORQJHU
ƒ ,ISRVVLEOHNHHSWUDQVDFWLRQVVPDOO

‡ &RQWUROODQJXDJHSURJUDPVPXVWEHPRGLILHGWRLQFOXGHSTRCMTCTL
DQGENDCMTCTL

‡ $SSOLFDWLRQSURJUDPVPXVWEHPRGLILHG
ƒ 2SHQILOHVIRUFRPPLWPHQWFRQWURO
ƒ $GGFRPPLWRSHUDWLRQDWHQGRIWUDQVDFWLRQV
ƒ <RXFDQXVHQRWLI\REMHFWWRDXWRPDWHUHVWDUW

‡ 0RUHMRXUQDOHQWULHVZLOOEHJHQHUDWHG

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-15. Commitment control: Considerations

If a rollback occurs, file cursor position is also rolled back.

© Copyright IBM Corp. 1995, 2017 13-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

(QKDQFHPHQWVWRGDWDEDVHVDYHSRLQWV
7UDQVDFWLRQ

%HJLQ &200,7
WUDQV 5ROOEDFNWR (QGWUDQV
$ % 6DYHSRLQW%

7LPHOLQH

)OLJKWUHVHUYDWLRQ +RWHOUHVHUYDWLRQ $XWRPRELOHUHVHUYDWLRQ

6DYHSRLQW$ 6DYHSRLQW%

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-16. Enhancements to database savepoints

The SAVEPOINT statement sets a savepoint within a unit of work to identify a point in time within
the unit of work to which relational database changes can be rolled back.
Faster transaction recovery with database savepoints. Instead of starting over from the beginning of
related transactions, start from a known interim step.
• ROLLBACK TO <savepoint>: This statement rolls back changes only to the specified
savepoint instead of all changes made by the transaction.
• RELEASE SAVEPOINT: This statement deletes a savepoint.
• COMMIT or ROLLBACK: Savepoints in a distributed transaction are scoped to the current
connection.

© Copyright IBM Corp. 1995, 2017 13-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

,$63FRQVLGHUDWLRQVIRUFRPPLWPHQWFRQWURO
‡ <RXVKRXOGEHDZDUHRIWKHIROORZLQJFRQVLGHUDWLRQVIRUFRPPLWPHQW
GHILQLWLRQVZKHQ\RXXVHLQGHSHQGHQWGLVNSRROV
ƒ QRECOVERY OLEUDU\
ƒ 6HW$63JURXS
ƒ 'HIDXOWMRXUQDO
ƒ ,3/DQGYDU\RII
ƒ 5HPRWHGDWDEDVH

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-17. IASP considerations for commitment control

Independent disk pools and independent disk pool groups, can each have a separate IBM i SQL
database. You can use commitment control with these databases.
QRECOVERY library considerations
When you start commitment control, the commitment definition is created in the QRECOVERY
library.
Each independent disk pool or independent disk pool group has its own version of a QRECOVERY
library. On an independent disk pool, the name of the QRECOVERY library is QRCYxxxxx, where
xxxxx is the number of the independent disk pool. Furthermore, if the independent disk pool is part
of a disk pool group, only the primary disk pool has a QRCYxxxxx library.
When you start commitment control, the commitment definition is created in the QRECOVERY
library of the independent disk pool that is associated with that job, making commitment control
active on the independent disk pool.
SET ASP Group considerations
Using the Set ASP Group (SETASPGRP) command while commitment control is active on an
independent disk pool has the following effects:

© Copyright IBM Corp. 1995, 2017 13-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty
• If you switch from an independent disk pool, and resources are registered with commitment
control on the disk pool, the SETASPGRP command fails.
• If you switch from an independent disk pool and no resources are registered with commitment
control, the commitment definitions are moved to the independent disk pool to which you are
switching.
• If you switch from the system disk pool, commitment control is not affected. The commitment
definitions stay on the system disk pool.
• If you move the commitment definition to another independent disk pool or independent disk
pool group, the notify object must also reside on that other independent disk pool or
independent disk pool group, otherwise if the object was not found, the update fails. The notify
object on the other independent disk pool or independent disk pool group is updated if the
commitment definitions end abnormally.
Default journal considerations
The following are default journal considerations:
• If you use the default journal, the journal must reside on the same independent disk pool or
independent disk pool group as the commitment definition.
• If the default journal is not found on the other independent disk pool or independent disk pool
group when commitment control starts, the commitment control start fails.
• If you move the commitment definition to another independent disk pool or independent disk
pool group, the default journal must also reside on that other independent disk pool or
independent disk pool group. If the journal is not found on the other independent disk pool or
independent disk pool group, the commitment definition is moved, but no default journal is used
from this point on.
IPL and vary off considerations
The following are IPL and vary off considerations:
• Recovery of commitment definitions residing on an independent disk pool is performed during
independent disk pool vary on processing and is similar to IPL recovery.
• Commitment definitions in an independent disk pool are not recovered during the IBM Power
Systems with IBM i iPL.
• The vary off of an independent disk pool has the following effects on commitment definitions:
• Jobs associated with the independent disk pool end.
• No new commitment definitions are allowed to be created on the independent disk pool.
• Commitment definitions residing on the independent disk pool become unusable.
• Commitment definitions residing on the independent disk pool, but not attached to a job,
release transaction scoped locks.
Remote database considerations
• When commitment control is active for a job or thread, access to data outside the independent
disk pool or disk pool group to which the commitment definition belongs is only possible
remotely, as if it were data that resides on another system. When you issue an SQL CONNECT

© Copyright IBM Corp. 1995, 2017 13-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty
statement to connect to the relational database (RDB) on the independent disk pool, the system
makes the connection a remote connection.
• The system disk pool and basic disk pools do not require a remote connection for read only
access to data that resides on an independent disk pool. Likewise, an independent disk pool
does not require a remote connection for read-only access to data that resides on the system
disk pool or a basic disk pool.

© Copyright IBM Corp. 1995, 2017 13-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

;$WUDQVDFWLRQVXSSRUWIRUFRPPLWPHQWFRQWURO
‡ '%8'%IRU,%0LFDQSDUWLFLSDWHLQ;2SHQJOREDOWUDQVDFWLRQV

‡ 7KHUHDUHILYHFRPSRQHQWVWRWKH'73PRGHO
ƒ $SSOLFDWLRQSURJUDP $3
ƒ 7UDQVDFWLRQPDQDJHU 70 
ƒ 5HVRXUFHPDQDJHU 50
ƒ &RPPXQLFDWLRQVUHVRXUFHPDQDJHU &50
ƒ &RPPXQLFDWLRQSURWRFRO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-18. XA transaction support for commitment control

DB2 UDB for IBM i can participate in X/Open global transactions


The Open Group has defined an industry standard model for transactional work that allows
changes made against unrelated resources to be part of single global transaction. An example of
this is changes to databases that are provided by two separate vendors. This model is called the
X/Open Distributed Transaction Processing model (DTP model).
In the XA environment, each database is considered a separate resource manager. When a
transaction manager wants to access two databases under the same transaction, it must use the
XA protocols to perform two-phase commit with the two resource managers.
Since each independent disk pool is a separate SQL database, in the XA environment each
independent disk pool is also considered a separate resource manager. For an application server to
perform a transaction, which targets two different independent disk pools, the transaction manager
must also use a two-phase commit protocol.
Application Program (AP): Implements the wanted function of the end user by specifying a
sequence of operations that involves resources such as databases. It defines the start and end of
global transactions, accesses resources within transaction boundaries, and normally makes the
decision whether to commit or roll back each transaction.

© Copyright IBM Corp. 1995, 2017 13-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty
Transaction Manager: Manages global transactions and coordinates the decision to start them,
and commit them, or roll them back in order to ensure atomic transaction completion. The TM also
coordinates recovery activities with the RMs after a component fails.
Resource Manager (RM): Manages a defined part of the computer's shared resources, such as a
database management system. The AP uses interfaces defined by each RM to perform
transactional work. The TM uses interfaces provided by the RM to carry out transaction completion.
Communications Resource Manager (CRM): Allows an instance of the model to access another
instance either inside or outside the current TM domain. CRMs are outside the scope of DB2 UDB
for IBM i and are not discussed here.
Communication Protocol: This refers to the protocols used by CRMs to communicate with each
other. This is outside the scope of DB2 UDB for IBM i and is not discussed here.
The XA Specification is the part of the DTP model that describes a set of interfaces that is used by
the TM and RM components of the DTP model. DB2 UDB for IBM i implements these interfaces as
a set of UNIX style APIs and exit programs. See XA APIs for detailed documentation of these APIs
and for more information on how to use DB2 UDB for IBM i as an RM.
IBM i Navigator and XA transactions
IBM i Navigator supports the management of XA transactions as Global transactions. A Global
transaction might contain changes both outside and within DB2 UDB for IBM i. A global transaction
is coordinated by an external Transaction Manager using the Open Group XA architecture, or
another similar architecture.
An application commits or rolls back a global transaction using interfaces provided by the
Transaction Manager. The Transaction Manager uses commit protocols defined by the XA
architecture, or another architecture, to complete the transaction. DB2 UDB for IBM i acts as an XA
Resource Manager when participating in a global transaction. There are two types of global
transactions:
• Transaction-scoped locks: Locks acquired on behalf of the transaction are scoped to the
transaction. The transaction can move from one job or thread to another.
• Job-scoped locks: Locks acquired on behalf of the transaction are scoped to the job. The
transaction cannot move from the job that started it.
You can find more information on the IBM Knowledge Center website at
[Link]

© Copyright IBM Corp. 1995, 2017 13-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

,%01DYLJDWRUIRUL&RPPLWPHQWFRQWURO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-19. IBM Navigator for i: Commitment control

You can use IBM Navigator for i to display information about all transactions (logical units of work)
on the system. You can also look at information about the job, if any, associated with a transaction
To work with commitment control wit IBM Navigator for i do following:
1. Log on using web browser to the IBM i system using [Link] address or system
name>:2001.
2. On the left pane, expand Database then Databases and your database.
3. Click Transaction and on the main pane you will have Database Transactions and Global
Transactions link to with.

© Copyright IBM Corp. 1995, 2017 13-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

,%0L1DYLJDWRU6XSSRUWIRUFRPPLWPHQWFRQWURO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-20. IBM i Navigator: Support for commitment control

This display shows the following:


• Unit of Work ID
• Unit of Work State
• Job
• User
• Number
• Resynchronization in Progress
• Commitment Definition
If you choose a Transaction and right-click it, you can get more information about the transaction,
such as:
• Jobs
• Resource Status
• Properties

© Copyright IBM Corp. 1995, 2017 13-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

([HUFLVH&RPPLWPHQWFRQWURO
‡ $QDO\]HWKHMRXUQDOHQWULHVPDGHDVDUHVXOWRILPSOHPHQWLQJ
FRPPLWRSHUDWLRQV
‡ $QDO\]HHQWULHVPDGHDVDUHVXOWRISHUIRUPLQJDUROOEDFN
RSHUDWLRQ
‡ 'HWHUPLQHWKHQDPHRIWKHSURJUDPWKDWUROOVEDFNLQFRPSOHWH
RSHUDWLRQVZKHQWKHRSHUDWRUVHOHFWVWKHRSWLRQWRµFDQFHOVD
MRELPPHGLDWHO\¶LQWKHPLGGOHRIDFRPPLWF\FOH
‡ $QDO\]HXVHUMRXUQDOHQWULHV
‡ 'LVSOD\DQGLQWHUSUHWWKHFRPPLWPHQWFRQWUROVWDWXVIRUDMRE
WKDWLVLQWKHPLGGOHRIDQLQFRPSOHWHFRPPLWF\FOH
‡ 8VHWKH$SSO\-RXUQDOHG&KDQJHVFRPPDQGAPYJRNCHGWR
UHFRYHUIURPDGDPDJHGRUXQXVDEOHILOH
‡ 8VHWKH5HPRYH-RXUQDOHG&KDQJHVFRPPDQGRMVJRNCHG
WRVHOHFWLYHO\EDFNRXWHUURQHRXVFKDQJHV XSGDWHVDGGVRU
GHOHWHV WRDILOH

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-21. Exercise: Commitment control

© Copyright IBM Corp. 1995, 2017 13-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH3URJUDPPLQJFKDQJHVPXVWEHPDGHWRDQ
DSSOLFDWLRQLQRUGHUWRLPSOHPHQWFRPPLWPHQWFRQWURO

 7UXHRUIDOVH&RPPLWPHQWFRQWUROUHTXLUHVWKDWMRXUQDOLQJ
EHLPSOHPHQWHGIRUWKHREMHFWVWKDWDUHXVHGE\WKLV
DSSOLFDWLRQ

 7UXHRUIDOVH&RPPLWPHQWFRQWURODOORZV\RXWRUHFRYHU
RQO\WKRVHWUDQVDFWLRQVWKDWDUHFRQVLGHUHGDZKROHRU
FRPSOHWHWUDQVDFWLRQ

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-22. Review questions

© Copyright IBM Corp. 1995, 2017 13-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH3URJUDPPLQJFKDQJHVPXVWEHPDGHWRDQ
DSSOLFDWLRQLQRUGHUWRLPSOHPHQWFRPPLWPHQWFRQWURO
7KHDQVZHULVWUXH

 7UXH RUIDOVH&RPPLWPHQWFRQWUROUHTXLUHVWKDWMRXUQDOLQJ
EHLPSOHPHQWHGIRUWKHREMHFWVWKDWDUHXVHGE\WKLV
DSSOLFDWLRQ
7KHDQVZHULVWUXH

 7UXH RUIDOVH&RPPLWPHQWFRQWURODOORZV\RXWRUHFRYHU
RQO\WKRVHWUDQVDFWLRQVWKDWDUHFRQVLGHUHGDZKROHRU
FRPSOHWHWUDQVDFWLRQ
7KHDQVZHULVIDOVH

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-23. Review answers

© Copyright IBM Corp. 1995, 2017 13-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 13. Commitment control overview

Uempty

8QLWVXPPDU\
‡ 'HVFULEHWKHIXQFWLRQVDQGFRQVLGHUDWLRQVRIFRPPLWPHQWFRQWURO
‡ 'HVFULEHKRZWRLPSOHPHQWFRPPLWPHQWFRQWURO

&RPPLWPHQWFRQWURORYHUYLHZ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 13-24. Unit summary

© Copyright IBM Corp. 1995, 2017 13-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

Unit 14. Backup and recovery planning


Estimated time
01:00

Overview
Save and restore commands, journal management, commitment control, user auxiliary storage
pools, access path journaling, mirrored, and device parity and dual systems are all powerful tools
that perform valuable functions. To ensure that the system is adequately protected from disk failure,
site loss, human error, and power or system failure, all of these tools must be integrated properly
into a comprehensive backup and recovery plan.

How you will check your progress


• Review questions

References
IBM System i Information Center
[Link]
p?topic=/rzahg/[Link]
SC41-5304 Systems Management Recovering Your System; Appendix B:
Example Disaster Recovery Plan

© Copyright IBM Corp. 1995, 2017 14-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

8QLWREMHFWLYHV
‡ &RPSDUHWKHDYDLODELOLW\RSWLRQVWKDWDUHDYDLODEOHDQGWKHLULPSDFWRQ
WKHUHFRYHU\SURFHVV
‡ 'HVFULEHVLPSOHPHGLXPDQGFRPSOH[VDYHVWUDWHJLHV
‡ 'HVFULEHDGLVDVWHUUHFRYHU\SODQ

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 14-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
14.1. Topic 1: The environment

© Copyright IBM Corp. 1995, 2017 14-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

7RSLF7KHHQYLURQPHQW

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-2. Topic 1: The environment

© Copyright IBM Corp. 1995, 2017 14-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

%DODQFHFRVWVRIEDFNXSDQGUHFRYHU\

&RVWRILPSOHPHQWLQJ &RVWRIIDLOXUH
DYDLODELOLW\IHDWXUHV PXOWLSOLHGE\
DQGEDFNLQJXS SUREDELOLW\RIIDLOXUH

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-3. Balance costs of backup and recovery

The cost of implementing availability features must be offset by the cost of failure multiplied by
probability of failure.

© Copyright IBM Corp. 1995, 2017 14-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

&DQ\RXUEXVLQHVVVWLOOIXQFWLRQ"

,%0L

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-4. Can your business still function?

If you were to lose a key application, for example order entry, could you recover it and how long
would it take to recover?

© Copyright IBM Corp. 1995, 2017 14-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

%DFNXSDQGUHFRYHU\SODQHYDOXDWLRQ
3RLQW 5HFRYHU\WLPHOLQH
.QRZQSRLQW ODVWVDYH
$FWLYLW\RFFXUVRQV\VWHP
3RLQW
)DLOXUHRFFXUV
+DUGZDUHUHSDLURU,3/
3RLQW
+DUGZDUHDYDLODEOH
,QIRUPDWLRQLVUHVWRUHGIURP
EDFNXS
3RLQW
6\VWHPUHFRYHUHGWR
NQRZQSRLQW 7UDQVDFWLRQVIURPSRLQWWR
SRLQWDUHUHFRYHUHG
3RLQW
6\VWHPUHFRYHUHGWR
IDLOXUHSRLQW %XVLQHVVDFWLYLW\IURPIDLOXUH
SRLQWWRUHFRYHU\SRLQW
LVUHFRYHUHG
3RLQW
6\VWHPLVFXUUHQW
&DQ\RXUSODQFRPSOHWHHDFKVWHS"
+RZORQJZLOOLWWDNHWRFRPSOHWHHDFKVWHS"
%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-5. Backup and recovery plan evaluation

The timeline for backup and recovery begins when you save the information and ends when your
system is fully recovered after a failure.
Refer to this timeline as you read this information and make the decisions. Your strategies for
saving and availability determine these things:
• Whether you can successfully complete each step in the chart.
• How long does it take you to complete each step.
Use the timeline to develop specific examples.
• What if the known point (1) is Sunday evening and the failure point (2) is Thursday afternoon?
• How long does it take to get back to the known point?
• How long does it take you to get to the current point (6)?
• Is it even possible with the save strategy that you have planned.

© Copyright IBM Corp. 1995, 2017 14-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

:KDWWRVDYHDQGKRZRIWHQ" RI
‡ )UHTXHQWFKDQJHV VDYHIUHTXHQWO\ GDLO\ 
ƒ 6HFXULW\LQIRUPDWLRQ
ƒ &RQILJXUDWLRQREMHFWVLQQSYS
ƒ QGPLQUSRSYS ,%0VXSSOLHGOLEUDULHVZLWKXVHUGDWD
ƒ 8VHUOLEUDULHV
ƒ )ROGHUVDQGGRFXPHQWV
ƒ 'LVWULEXWLRQV
ƒ 'LUHFWRULHV
‡ ,QIUHTXHQWFKDQJHV 6DYHLQIUHTXHQWO\ ZHHNO\ 
ƒ 6\VWHPLICQSYSQHLPSYSQUSRTOOL
ƒ /LFHQVHGSURJUDPOLEUDULHV 53*&2%2/DQGVRRQ IROGHUVGLUHFWRULHV

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-6. What to save and how often? (1 of 3)

The answer to the question of what you need to save is simple: everything. To be prepared for a
site loss or certain types of disk failures, you need to be able to recover everything on your system.
Saving the right things determines whether you can recover to point 4 (the last save) shown in the
backup and recovery timeline, in the previous visual.
In an ideal world, how often you need to save is also an easy question.
• Every day, save the parts of your system that change often.
• Every week, save the parts of your system that do not change often.
Saving the right things at the right time determines how much information you need to recover to
get from point 4 to point 5 in the backup and recovery timeline in the previous visual.
This table shows the parts of the system that change often, and should be saved daily.

© Copyright IBM Corp. 1995, 2017 14-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

:KDWWRVDYHDQGKRZRIWHQ" RI

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-7. What to save and how often? (2 of 3)

Item description IBM-supplied? When changes occur


Security information (user profiles,
Regularly as new users and objects are
private authorities, authorization Some
added or authorities are changed1
lists) Configuration objects in QSYS
Regularly, when device descriptions are
added or changed or when you use the
Configuration objects in QSYS No Hardware Service Manager function to
update configuration information1

IBM-supplied libraries that contain


Yes Regularly
user data (QGPL, QUSRSYS)
User libraries that contain user data
No Regularly
and programs
Folders and documents Some Regularly, if you use these objects
Regularly, if you use the distribution
Distributions No
function
Directories Some Regularly, if you use these objects

1These objects might also change when you update licensed programs.

© Copyright IBM Corp. 1995, 2017 14-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

:KDWWRVDYHDQGKRZRIWHQ" RI

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-8. What to save and how often? (3 of 3)

Item description IBM-supplied? When changes occur


PTFs or new release of the
Licensed Internal Code Yes
operating system
Operating system objects in QSYS PTFs or new release of the
Yes
library operating system
Operating System/400 optional PTFs or new release of the
Yes
libraries (QHLPSYS, QUSRTOOL) operating system
Licensed program libraries (QRPG,
Yes Updates to licensed programs
QCBL, Qxxxx)

Licensed program folders (Qxxxxxxx) Yes Updates to licensed programs


Licensed program libraries directories
Yes Updates to licensed programs
(/QIBM/QOpenSys/QIBM)

© Copyright IBM Corp. 1995, 2017 14-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

6DYHZLQGRZVDYHVWUDWHJ\
‡ 6DYHZLQGRZ
ƒ 6\VWHPDQGGDWDDWNQRZQSRLQW
ƒ 1RWFKDQJLQJIRUSHULRGRIWLPH

6DYHZLQGRZ 6DYHVWUDWHJ\

 KRXUVZLWKQR
6LPSOH
V\VWHPDFWLYLW\
 KRXUVZLWKQR
0HGLXP
V\VWHPDFWLYLW\

 PLQLPDOGRZQWLPH &RPSOH[

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-9. Save window/save strategy

Realistically, when you run the save procedures, how you run your save procedures and what you
save, all of these things depend on the size of your save window. Your save window is the amount
of time that your system can be unavailable to users while you perform your save operations. To
simplify your recovery, you need to save when your system is at a known point and your data is not
changing.
To determine which save strategy is the best strategy for your business, you will have to balance
what your users think is an acceptable save window versus the value of the data you might lose
and the amount of time it might take to recover that data in case it is lost or damaged.
If your system is so critical to your business that you do not have a manageable save window, you
probably cannot afford an unscheduled outage either. In this case, you should seriously evaluate all
of the availability options of IBM i, including implementing a dual systems environment.
Based on the size of your save window, you will choose one of the following save strategies. Then,
reevaluate your decision based on how your save strategy positions you for a recovery.
• Simple save strategy: If you have a long save window, 8 to 12 hours available daily with no
system activity including batch work, then implementing a simple save strategy is the best
option.

© Copyright IBM Corp. 1995, 2017 14-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
• Medium save strategy: If you have a shorter block of time, 4 to 6 hours available with no
system activity during this time, then implementing a medium save strategy is the best option.
• Complex save strategy: You have a short save window, which means that there is little or no
time when your system is not being used for interactive or batch work, then implementing a
complex save strategy is the best option.

© Copyright IBM Corp. 1995, 2017 14-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

6LPSOHVDYHVWUDWHJ\
‡ 6DYHHYHU\WKLQJQLJKWO\
ƒ ,VVXHGO SAVEWKHQVHOHFWRSWLRQ (QWLUHV\VWHP 

Or

‡ 6DYHHYHU\WKLQJRQFHSHUZHHNDQGVDYHDOOXVHUGDWDQLJKWO\
ƒ ,VVXHGO SAVEWKHQVHOHFWRSWLRQ $OOXVHUGDWD 

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-10. Simple save strategy

The simplest save strategy is to save everything every night or during the off-shift hours. The
simplest way to save the entire system is to use option 21 - Save Entire system from the Save
menu. You can schedule option 21 to run without an operator (unattended) at a specified time.
You can also use this method to save your entire system after you upgrade to a new release or
apply program temporary fixes (PTFs).
You might find that you do not have enough time or enough tape unit capability to run option 21
without an operator. You can still employ a simple strategy:
• Daily: Save everything that changes often.
• Weekly: Save the things that do not change often.
Choosing Option 23 - Save all user data on the Save menu saves those things that change
regularly. Option 23 can be scheduled to run attended or unattended. To run unattended, you must
have enough online backup media capacity.
If your system has a long period of inactivity on the weekend, your save strategy might look like
this:
• Friday night: Save menu option 21
• Monday night: Save menu option 23

© Copyright IBM Corp. 1995, 2017 14-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
• Tuesday night: Save menu option 23
• Wednesday night: Save menu option 23
• Thursday night: Save menu option 23
• Friday night: Save menu option 21

© Copyright IBM Corp. 1995, 2017 14-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

0HGLXPVDYHVWUDWHJ\

:HHNO\ 6DYHHYHU\WKLQJZHHNO\
'DLO\ 6DYHDOOXVHUGDWDPLGZHHN

Or
'DLO\ 6DYHMRXUQDOUHFHLYHUV

Or
6DYHFKDQJHGREMHFWV
'DLO\
SAVCHGOBJSAVDLOSAV 

Or
6DYHJURXSVRIOLEUDULHVIROGHUVDQG
'DLO\
GLUHFWRULHV VLPSOLILHGZLWK%$&.83PHQX 

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-11. Medium save strategy

You might find that you do not have a long enough save window to use the simple save strategy.
Perhaps you run large batch jobs on your system at night. Or, you have very large files that take a
long time to save. If this is the case, you might need to develop a medium save strategy, which
means that the complexity for saving and for recovery is medium.
When developing a medium save strategy apply this principle: the more often the data changes, the
more often you should save that data. When using the medium save strategy you need to be more
detailed in evaluating how often your data changes.
Several techniques are available to help you implement a medium save strategy. You can use one
or several or a combination of these strategies.
• Saving changed objects
• Journaling
• Database files and saving the journal receivers
• Saving groups of libraries, folders, or directories

© Copyright IBM Corp. 1995, 2017 14-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

&RPSOH[VDYHVWUDWHJ\
‡ &RPSOH[VDYHVWUDWHJ\
ƒ 7KLVLVVLPLODUWRDPHGLXPVDYHVWUDWHJ\
ƒ 'DLO\VDYHVPLJKWEHDWVSHFLILFWLPHV
ƒ 6DYHZKLOHDFWLYHPLJKWEHQHFHVVDU\
í $YDLODEOHRQSAVLIB, SAVOBJ, SAVCHGOBJ, SAVDLO, SAV
ƒ 8VHH[WHUQDOVWRUDJH)XOO6\VWHP&RS\6HUYLFHV0DQDJHU%506

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-12. Complex save strategy

A very short save window requires implementing a complex save strategy for both saving your data
and for performing a recovery of this data in case of a system failure or a loss of user data. You will
use the same tools and techniques that are described for a medium save strategy but you will be
implementing these strategies at a greater level of detail. For example, you might need to save
specific critical files at specific times of the day or week. If you will be implementing a complex save
strategy then you might also want to consider using IBM i Backup Recovery and Media Services
(BRMS).
Saving your system while it is active is often necessary when implementing a complex save
strategy. The save-while-active (SAVACT) parameter is supported on the following commands:
• Save Library (SAVLIB)
• Save Object (SAVOBJ)
• Save Changed Objects (SAVCHGOBJ)
• Save Document Library Object (SAVDLO)
• Save (SAV)

© Copyright IBM Corp. 1995, 2017 14-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
If you use save-while-active support, you can significantly reduce the amount of time that files are
made unavailable. When the system has established a checkpoint for all objects being saved, the
objects can be made available for use. Save-while-active support can be used in combination with
journaling and commitment control to simplify the recovery procedure. If you choose to use
save-while-active support, make sure that you understand that process and monitor how well
checkpoints are being established on your system.
You can also reduce the amount time that files are unavailable by performing save operations on
more than one save device at a time, or performing concurrent save operations. For example, you
can save libraries to save device number one, folders to save device number two, and save
directories and other IFS objects to a third save device. Another way to set up a concurrent save
operations is to save different sets of libraries or objects to different save devices.
Another time saving strategy to your data is to use multiple save devices simultaneously by
performing a parallel save operation. This is useful if most of your data is contained in a single
library. To perform a parallel save operation, you need Backup Recovery and Media Services or an
application that allows you to create media definition objects.
For more information on save-while-active support, concurrent save operations, and parallel save
operations, refer to the Systems Management Recovering Your System Guide SC41-5304-12.
If your situation requires a medium save strategy or a complex save strategy, it also requires
regular review, of the following:
• Are saving everything occasionally?
• What do you need to do to recover to the known point (4) on the backup and recovery timeline?
• Are you using options like journaling or saving changed objects to help you recover to the
failure point (5)? Do you know how to recover using those options?
• Have you added new applications? Are the new libraries, folders, and directories being saved?
• Are you saving the IBM-supplied libraries that contain user data (QGPL and QUSRSYS)?
• Have you tested your recovery?
The best way to test if your save strategy is a sound strategy is to perform a full recovery. Although
you can test a recovery on your own system, doing so can be risky. If you have not saved
everything successfully, you might lose information when you attempt to restore the data. A number
of organizations offer recovery testing as a service. IBM Business Recovery Services is one
organization that can assist you with recovery testing.
It could be good solution to use external storage to make backup (even opt21) without production
interruption to do this you need external storage with FlashCopy functionality and additional
storage. To make FlashCopy from IBM i the best is use FSCSM Full System Copy Services
Manager and BRSM to integration backup solution. More latter in this course.

© Copyright IBM Corp. 1995, 2017 14-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

$YDLODELOLW\RSWLRQV

$WWULEXWH 3K\VLFDOILOHMRXUQDOLQJ 0LUURUHGSURWHFWLRQ 'HYLFHSDULW\SURWHFWLRQ

'DWDORVVDIWHUVLQJOH 0LQLPDOORVVWRILOHGDWDLIJRRG
1RQHRIWKHGDWDLVORVW 1RQHRIWKHGDWDLVORVW
GLVNIDLOXUH EDFNXSVDUHDYDLODEOH

5HFRYHU\WLPHDIWHU
3RWHQWLDOO\PDQ\KRXUV 1RQHWRDIHZKRXUV 1RQHWRDIHZKRXUV
VLQJOHGLVNIDLOXUH

3HUIRUPDQFHLPSDFW 0LQLPDOWRVLJQLILFDQW 0LQLPDO 0LQLPDO

3ODQQLQJFRPSOH[LW\
 +DUGZDUH 0LQLPDO &DUHIXOSODQQLQJ &DUHIXOSODQQLQJ
 6RIWZDUH 6LJQLILFDQW 0LQLPDO 0LQLPDO

6HWXSFRPSOH[LW\DQG
0LQLPDO 0LQLPDO 0LQLPDO
WLPH

2SHUDWLRQDODQG
PDQDJHPHQW $YHUDJH 0LQLPDO 0LQLPDO
FRPSOH[LW\

3RVVLEO\PRUHGLVNDQG 'RXEOHWKHGLVNSRVVLEO\ 2QHRUWZRGLVNXQLWVSHU


$GGLWLRQDOKDUGZDUH
VHSDUDWH$63V PRUHFRQWUROOHUV SDULW\VHW

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-13. Availability options

On the visual, you can compare availability options and impact for a system.

© Copyright IBM Corp. 1995, 2017 14-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

$YDLODELOLW\RSWLRQVE\IDLOXUHW\SH5HFRYHU\WLPH
+DVWKLVUHODWLYHLPSDFWRQWKHUHFRYHU\WLPHIRUWKHVHIDLOXUHW\SHV
3URJUDP
7KLVVDYHRUDYDLODELOLW\RSWLRQ '$6' 6\VWHP 3RZHUORVV3URJUDPIDLOXUH6LWHORVV

6DYHRSHUDWLRQV     

)LOHMRXUQDOLQJ    

$FFHVVSDWKSURWHFWLRQ   

8QLQWHUUXSWLEOHSRZHUVXSSO\ 

8VHU$63V 

'HYLFHSDULW\SURWHFWLRQ 

0LUURUHGSURWHFWLRQ 

5HGXQGDQF\   

+$'5VROXWLRQV 
%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-14. Availability options by failure type: Recovery time

The availability options (save operations, journaling, access path protection, mirroring, and so forth)
are rated in terms of relative impact on recovery time for various failure types (DASD, power failure,
site loss, system loss, and so forth).
The number of plus signs (+) in a column indicates that option's impact compared to the other
options. An option with more pluses has greater relative impact.

© Copyright IBM Corp. 1995, 2017 14-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
14.2. Topic 2: Creating a disaster recovery plan

© Copyright IBM Corp. 1995, 2017 14-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

7RSLF&UHDWLQJDGLVDVWHU
UHFRYHU\SODQ

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-15. Topic 2: Creating a disaster recovery plan

© Copyright IBM Corp. 1995, 2017 14-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

'LVDVWHUUHFRYHU\SODQ0DMRUJRDOV
‡ 0LQLPL]HLQWHUUXSWLRQVWRQRUPDORSHUDWLRQV
‡ /LPLWH[WHQWRIGLVUXSWLRQDQGGDPDJH
‡ 0LQLPL]HHFRQRPLFLPSDFWRIWKHLQWHUUXSWLRQ
‡ (VWDEOLVKDOWHUQDWLYHPHDQVRIRSHUDWLRQLQDGYDQFH
‡ 7UDLQVWDIIZLWKHPHUJHQF\SURFHGXUHV
‡ 3URYLGHVPRRWKDQGUDSLGUHVWRUDWLRQRIVHUYLFH

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-16. Disaster recovery plan: Major goals

The objective of a disaster recovery plan is to ensure that you can respond to a disaster or other
emergency that affects information systems and minimize the effect on the operation of the
business.
When you have prepared the information described in this topic collection, store your document in a
safe. This safe should be in a location that is off-site that is easily and readily accessible and ideally,
this would be a fireproof safe.

© Copyright IBM Corp. 1995, 2017 14-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

'LVDVWHUUHFRYHU\SODQ
‡ 3HUVRQQHO
ƒ 'DWDSURFHVVLQJ
ƒ 2UJDQL]DWLRQDOFKDUW
ƒ 3RVLWLRQVDGGUHVVWHOHSKRQHQXPEHUHPDLODGGUHVV
‡ $SSOLFDWLRQSURILOH+RZFULWLFDOZKHQLWUXQVPDQXIDFWXUHU
‡ ,QYHQWRU\SURILOH0DQXIDFWXUHUGHVFULSWLRQPRGHOVHULDOQXPEHURZQHUFRVW
‡ ,QIRUPDWLRQVHUYLFHVEDFNXSSURFHGXUHV
ƒ ,%0L
ƒ 3HUVRQDOFRPSXWHUV
‡ 'LVDVWHUUHFRYHU\SURFHGXUHV
ƒ (PHUJHQF\UHVSRQVHSURFHGXUHVWRSURWHFWOLYHVDQGOLPLWGDPDJH
ƒ %DFNXSRSHUDWLRQDOSURFHGXUHVWRFRQGXFWHVVHQWLDOWDVNV
ƒ 5HFRYHU\DQGUHVWRUDWLRQRIGDWDSURFHVVLQJV\VWHP
ƒ 'LVDVWHUDFWLRQFKHFNOLVW EHIRUHEHJLQQLQJUHFRYHU\
ƒ 5HFRYHU\VWDUWXSSURFHGXUHV QRWLI\SHRSOHDQGRXWVLGHFRPSDQLHVLQYROYHG
‡ 5HFRYHU\SODQDWPRELOHVLWH
‡ 5HFRYHU\SODQDWKRWVLWH
‡ 5HVWRULQJHQWLUHV\VWHP
‡ 3ODQDQGVWDUWWRUHEXLOGGDWDSURFHVVLQJVLWH
‡ 7HVWWKHGLVDVWHUUHFRYHU\SODQ
%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-17. Disaster recovery plan

IBM i Knowledge Center: IBM i 7.3 > Systems management > Backup and recovery > Planning
a backup and recovery strategy
[Link]
At the site [Link] you
can find describe a method how to create and maintain a detailed Disaster recovery plan.
Section 1. Major goals of this plan (as shown by the previous slide).
Section 2. Personnel, including a table describing all required information of involved personnel.
Section 3. Application profile: Use the Display Software Resources (DSPSFWRSC) command to
complete this table.
Section 4. Inventory profile: Use the Work with Hardware Products (WRKHDWPRD) command to
complete this table. A second table with miscellaneous inventory should be filled in.
Section 5. Information services backup procedures.
Section 6. Disaster recovery procedures: For any disaster recovery plans, the following elements
should be addressed:
• Emergency response procedures
• Backup operations procedures

© Copyright IBM Corp. 1995, 2017 14-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty
• Recovery actions procedures
• Disaster action checklist:
• Recovery start-up procedures for use after a disaster
Section 7. Recovery plan: Mobile site including a checklist:
• Mobile site setup plan
• Communication disaster plan
• Electrical service
Section 8. Recovery plan - hot site: The disaster recovery service provides an alternate hot site.
The site has a backup system for temporary use while the home site is being reestablished.
Section 9. Restoring the entire system: To get your system back to the way it was before the
disaster, use the procedures on recovering after a complete system loss in Systems management:
Backup and recovery.
Section 10. Rebuilding process
Section 11. Testing the disaster recovery plan
Section 12. Disaster site rebuilding
Section 13. Record of plan changes: Keep your current plan. Keep records of changes to your
configuration, your applications, and your backup schedules and procedures.
Sample disaster recovery plan
The objective of a disaster recovery plan is to ensure that you can respond to a disaster or other
emergency that affects information systems and minimize effect on the operation of the business.
When you have prepared the information described in this topic, store your document in safe.
This safe should be in a location that is off-site that is easily and readily accessible, and ideally, this
would be a fireproof safe.
Section 1. Major goals of a disaster recovery plan
Here are the major goals of a disaster recovery plane.
• To minimize interruptions to the normal operations
• To limit the extent of disruption and damage
• To minimize the economic impact of the interruption
• To establish alternative means of operation in advance
• To train personnel with emergency procedures
• To provide for smooth and rapid restoration of service

© Copyright IBM Corp. 1995, 2017 14-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH,QIRUPDWLRQWKDWFKDQJHVIUHTXHQWO\LV
VRPHWKLQJWKDWVKRXOGEHVDYHGRQDZHHNO\EDVLV

 7UXHRUIDOVH7KH/,&DQGDOORIWKH4OLEUDULHVVKRXOGEH
VDYHGRQDGDLO\EDVLV

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHVDYHVWUDWHJLHVWKDW
ZDVFRYHUHGLQWKHOHFWXUH"
D 6LPSOH
E 0HGLXP
F )XOO
G &RPSOH[

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-18. Review questions

© Copyright IBM Corp. 1995, 2017 14-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

5HYLHZDQVZHUV
 7UXHRUIDOVH,QIRUPDWLRQWKDWFKDQJHVIUHTXHQWO\LV
VRPHWKLQJWKDWVKRXOGEHVDYHGRQDZHHNO\EDVLV
7KHDQVZHULVIDOVH

 7UXHRUIDOVH7KH/,&DQGDOORIWKH4OLEUDULHVVKRXOGEH
VDYHGRQDGDLO\EDVLV
7KHDQVZHULVIDOVH

 :KLFKRIWKHIROORZLQJLVQRWRQHRIWKHVDYHVWUDWHJLHVWKDW
ZDVFRYHUHGLQWKHOHFWXUH"
D 6LPSOH
E 0HGLXP
F )XOO
G &RPSOH[
7KHDQVZHULVIXOO

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-19. Review answers

© Copyright IBM Corp. 1995, 2017 14-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 14. Backup and recovery planning

Uempty

8QLWVXPPDU\
‡ &RPSDUHWKHDYDLODELOLW\RSWLRQVWKDWDUHDYDLODEOHDQGWKHLULPSDFWRQ
WKHUHFRYHU\SURFHVV
‡ 'HVFULEHVLPSOHPHGLXPDQGFRPSOH[VDYHVWUDWHJLHV
‡ 'HVFULEHDGLVDVWHUUHFRYHU\SODQ

%DFNXSDQGUHFRYHU\SODQQLQJ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 14-20. Unit summary

© Copyright IBM Corp. 1995, 2017 14-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

Unit 15. Problem determination


Estimated time
01:20

Overview
This unit is provided to take a look at system displays that can help you with problem management
using the knowledge gained in previous units.

How you will check your progress


• Review questions
• Exercise

© Copyright IBM Corp. 1995, 2017 15-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

8QLWREMHFWLYHV
‡ 'LVSOD\V\VWHPLQIRUPDWLRQDQGLGHQWLI\SUREOHPMREV
‡ &KDQJHYDOXHVWKDWDIIHFWV\VWHPSHUIRUPDQFHDQGSUREOHPKDQGOLQJ
‡ 6FKHGXOHIXQFWLRQVWKDWDYRLGV\VWHPSUREOHPV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 15-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
15.1. Topic 1: Problem determination concepts

© Copyright IBM Corp. 1995, 2017 15-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7RSLF3UREOHP
GHWHUPLQDWLRQFRQFHSWV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-2. Topic 1: Problem determination concepts

© Copyright IBM Corp. 1995, 2017 15-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

3UREOHPGHWHUPLQDWLRQ
‡ :KHUHFDQ,ORRN"
‡ :KDWFDQ,GR"

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-3. Problem determination

© Copyright IBM Corp. 1995, 2017 15-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

3UREOHPGHWHUPLQDWLRQSURFHVV
‡ 3UREOHPGHWHUPLQDWLRQKDVWZRFRPSRQHQWV
ƒ 3UREOHPGHWHUPLQDWLRQ 3'
ƒ 3UREOHPVRXUFHLGHQWLILFDWLRQ 36,

‡ 3UREOHPGHWHUPLQDWLRQ
ƒ ,GHQWLI\LQJWKHSUREOHP
ƒ ,GHQWLI\LQJWKHHIIHFWVRIWKLVSUREOHP

‡ 3UREOHPVRXUFHLGHQWLILFDWLRQ
ƒ ,GHQWLI\LQJZKDWKDVFDXVHGWKHSUREOHP

‡ 2IWHQFDOOHG3'36,

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-4. Problem determination process

The terms problem determination and problem source identification are often joined together into
yet another acronym, PD/PSI. While this might seem to be an unnecessary duplication of terms, it
conveys that there is an important distinction between the following components of problem
analysis:
• Problem determination (PD): The process of finding out exactly what the problem is and what
its effects are
• Problem source identification (PSI): The process of finding out what has caused the problem
In some cases, it is not possible to give a complete explanation of the cause of a problem. Your
service provider, with the assistance of appropriate diagnostic information, can recommend a
course of action to recover from a problem.

© Copyright IBM Corp. 1995, 2017 15-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

&ODVVLILFDWLRQRIV\PSWRPV
‡ 7KHUHDUHWZRFODVVLILFDWLRQVRIV\PSWRPV
ƒ ([WHUQDOV\PSWRPV
í ,QFRUUHFWRXWSXW
í 0HVVDJHV
í :DLW
í /RRS
ƒ ,QWHUQDOV\PSWRPV
í 5HFRUGPHVVDJHV
í 'HWHUPLQHLIRQHMRELVLQDORRSRULVWKHHQWLUHV\VWHP
í 'HWHUPLQHLIWKHZDLWLVDWDMREOHYHORUWKHV\VWHPOHYHO
í 'HWHUPLQHLIWKHSUREOHPLVLVRODWHGZLWKLQDMREHQYLURQPHQWRUEHWZHHQMREV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-5. Classification of symptoms

External symptoms
The first objective of problem isolation is to define the external symptoms accurately. The external
symptoms are the attributes of the incident that first drew attention to the existence of a problem.
One or more of the following symptoms can be present:
• Incorrect output: The displayed or printed output from a job is not as expected.
• Messages: There are error messages in the job log, system operator message queue, or the
system history log.
• Wait: A job, many jobs, or the entire system can stop processing with little CPU activity.
• Loop: A job, or many jobs, can consume large amounts of CPU, precluding normal processing
Internal symptoms
The second objective of problem isolation is to find one or more internal symptoms. Any number of
internal symptoms can contribute to an external symptom. Each internal symptom has a special
diagnostic plan that requires the collection of specific information.
• Where messages are concerned, it is necessary to record any return codes, sense codes,
dump identifiers, and qualifiers.

© Copyright IBM Corp. 1995, 2017 15-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
• When a loop is encountered, it is necessary to determine whether there is a single job involved
in the loop or if the entire IBM i is affected.
• When a wait condition is encountered, it is necessary to determine whether the wait is at a job
or a system level.
• Messages are the key indicators in determining whether a lock condition is held within a job
environment or between jobs.

© Copyright IBM Corp. 1995, 2017 15-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

3UREOHPVROYLQJWRROV

,%03RZHU6\VWHPVZLWK
,%0LWRROER[
3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-6. Problem solving tools

The system cannot solve all problems for you, so to help you, IBM i provides you with the
description of a problem and tools to help solve it. These tools (CL commands, menus, displays,
message queues, and logs) are provided as part of IBM i.
How your server manages problems:
The problem analysis functions that are provided by your server allow you to manage both
system-detected and user-defined problems. Your server provides functions for problem analysis,
problem logging and tracking, problem reporting, and problem correction. The structured problem
management server helps you and your service provider quickly and accurately manage problems
as they occur on the server.
Here is an example of the flow when managing a problem:
1. The server detects a hardware error.
2. An error notification is sent to the server.
3. A problem record is created with configuration information, a system reference code, the name
of the reporting device, and other information.
4. The system error log records the error.
5. A message is sent to the system operator's message queue.

© Copyright IBM Corp. 1995, 2017 15-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
6. Problem analysis starts with the message.
The results of problem analysis are automatically stored, along with the collected problem
information. At this point, you can report the problem to your service provider.
Various tools are available to help you manage the problems on your server.
• Messages
• Error messages
• System reference codes
• Logs
• Alerts
• Solving problems using problem handling menus
• Electronic customer support
• Error codes

© Copyright IBM Corp. 1995, 2017 15-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

6*'LDJQRVWLFWRROV5HGERRNV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-7. SG24-8253: Diagnostic tools Redbooks

You can download it from [Link]

© Copyright IBM Corp. 1995, 2017 15-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
15.2. Topic 2: Problem determination using 5250
emulation

© Copyright IBM Corp. 1995, 2017 15-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7RSLF3UREOHP
GHWHUPLQDWLRQXVLQJ
HPXODWLRQ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-8. Topic 2: Problem determination using 5250 emulation

© Copyright IBM Corp. 1995, 2017 15-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

:RUNZLWK$FWLYH-REVFRPPDQG

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-9. Work with Active Jobs command

The Work with Active Jobs (WRKACTJOB) command allows you to work with performance and
status information for the active jobs in the system. The sequence of jobs can be changed with the
Sequence (SEQ) parameter or through operations on the display. Other parameters allow the
selection of jobs to be shown on the display.

© Copyright IBM Corp. 1995, 2017 15-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

:RUNZLWK$FWLYH-REVVFUHHQ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-10. Work with Active Jobs screen

The Work with Active Jobs display shows the performance and status information for jobs that are
currently active on the system. All information is gathered on a job basis. The jobs are ordered on
the basis of the subsystems in which they are running. Jobs that run in a subsystem (autostart jobs,
interactive jobs, batch jobs, readers, and writers) are alphabetized by job name and indented under
the subsystem monitor job field they are associated with. Subsystem monitors (with the jobs in the
subsystem grouped under each monitor job) are alphabetized and presented before system (SYS)
jobs. The system jobs (SCPF, QSYSARB, QLUS) are alphabetized by job name and presented
following the subsystem monitors and jobs within the subsystems.

© Copyright IBM Corp. 1995, 2017 15-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

:RUNZLWK-RE

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-11. Work with Job

The Work with Job and the Display Job menus allow you to select options to work with or to change
information related to a user job.
Information about the following options can be shown regardless of where the job is located in the
system (on a job queue, on an output queue, or active):
• Job status attributes
• Job definition attributes
• Spooled file information

© Copyright IBM Corp. 1995, 2017 15-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

2SWLRQ'LVSOD\-RE5XQ$WWULEXWHV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-12. Option 3: Display Job Run Attributes

The Work with Job Run Attributes display, and the Display Job Run Attributes display, show run
attributes that are defined in the class object associated with the job. Note that F9 from this display,
allows you to change job attributes.

© Copyright IBM Corp. 1995, 2017 15-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

2SWLRQ-REORJRU'63-2%/2*

)3*83

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-13. Option 10: Job log or DSPJOBLOG

The Display All Messages display shows you the commands processed by the job and the
messages returned from running those commands. All available messages are shown, including
those not normally seen on the original display.
If you are displaying a batch job, you can see commands that are still to be processed (identified by
"..").
If you want to see more details press F10 function key and then PGUP (page up).
For specific information about messages, put the cursor on the message you want information
about and press the Help key. An additional message information display will then be shown.

© Copyright IBM Corp. 1995, 2017 15-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

(QGLQJDMRE

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-14. Ending a job

Option 4=End
Use this option to run the End Job (ENDJOB) command; the job's spooled files are not deleted
unless the default for the Delete spooled file (SPLFILE) parameter is overridden by using the
Parameter's input field. Unless the OPTION parameter is overridden by using the Parameter's input
field, a controlled end is performed as if the End Job (ENDJOB) command were typed with all the
default parameter values assumed. The End Reader (ENDRDR) or End Writer (ENDWTR) command
(with OPTION(*CNTRLD)) is issued if this option is selected for a spooling reader or spooling writer
job. This option is not valid for system or subsystem monitor jobs. END replaces the status field if
the command runs successfully.
The End Job (ENDJOB) command ends the specified job and any associated inline data files. The
job can be on a job queue, it can be active, or it can have already completed running.

© Copyright IBM Corp. 1995, 2017 15-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

(QG-RE$EQRUPDO

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-15. End Job Abnormal

The End Job Abnormal (ENDJOBABN) command ends a job that cannot be ended successfully by
running the End Job (ENDJOB) command with *IMMED specified for the How to end (OPTION)
parameter. The ENDJOBABN command cannot be issued against a job until 10 minutes have
passed following the request for immediate ending. This allows sufficient time for normal job ending
functions to be attempted.
When the ENDJOBABN command is issued, most of the end-of-job processing is bypassed
(including spooling of the job log, the end of job display for interactive jobs, and the end-of-job
processing for the specific functions that are being performed). The part of the end-of-job
processing that is attempted is allowed only five minutes to complete. If it does not do so in five
minutes, the job is forced to end at that point. Because some of the job cleanup is not performed,
the ENDJOBABN command should only be used when a job that is in the process of immediate
ending does not finish ending and resources in use by the job are needed by another job or by the
system. When the ENDJOBABN command is used, some resources in use by the ended job might
be left unavailable until the next IPL.

© Copyright IBM Corp. 1995, 2017 15-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

'LVSOD\V\VWHPRSHUDWRUPHVVDJHV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-16. Display system operator messages

The Display Messages (DSPMSG) command is used by the display station user to show the
messages received at the specified message queue. If the message queue is not allocated to the
job in which this command is entered or to any other job, it is implicitly allocated by this command
for the duration of the command. When the messages are shown, options are also shown that allow
the user to either remove one or more messages from the queue or to enter a reply to each inquiry
message.
To display the system operator message queue, enter the DSPMSG QSYSOPR command.

© Copyright IBM Corp. 1995, 2017 15-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

+LVWRU\ORJ
‡ 6\VWHPKLVWRU\
ƒ $XWRPDWLFDOO\ORJVV\VWHPDFWLYLW\
í -RELQIRUPDWLRQ VWDUWVWRSWLPHV
í &RPSRQHQWIDLOXUHV
í &ULWLFDO,%03RZHU6\VWHPVZLWK,%0LQIRUPDWLRQ
6WRUDJHWKUHVKROGV

‡ ,QIRUPDWLRQZULWWHQWRDV\VWHPORJ
ƒ QHST
í 0XOWLSOHSK\VLFDOILOHVQHST\\GGGD!

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-17. History log

© Copyright IBM Corp. 1995, 2017 15-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

3UREOHPDQDO\VLV+LVWRU\ORJ

QHST *MSGQ DSPLOG

‡ &ROOHFWLRQRIPHVVDJHV
VXPPDUL]LQJV\VWHPDFWLYLW\
ƒ ,%0LLQIRUPDWLRQ
ƒ -RELQIRUPDWLRQ
ƒ 'HYLFHVWDWXVFKDQJHV QHSTyydddn
ƒ 6\VWHPRSHUDWRUPHVVDJHV
ƒ 37)DFWLYLW\ QHSTLOGSIZ

'A LOG VERSION'

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-18. Problem analysis: History log

© Copyright IBM Corp. 1995, 2017 15-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

'63/2*

QHST/RJRIDOOV\VWHPPHVVDJHV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-19. DSPLOG

The Display Log (DSPLOG) command shows the system history log (QHST). The history log
contains information about the operation of the system and system status.
The display contains the messages sent to the log, the date and time the message was sent, and
the name of the job that sent it.

© Copyright IBM Corp. 1995, 2017 15-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

'63/2*4+67

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-20. DSPLOG QHST

This view of the log shows all system activity.

© Copyright IBM Corp. 1995, 2017 15-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

6DYLQJDQGGHOHWLQJKLVWRU\ORJV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-21. Saving and deleting history logs

However, system do it themselves the Work with Files (WRKF) commands allows you to see and
perform housekeeping on the system history log (QHST*) files.

© Copyright IBM Corp. 1995, 2017 15-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

&RS\VFUHHQ
,QHHGVRPH
DVVLVWDQFH

STRCPYSCN
/HWPHVHH
ZKDWLVKDSSHQLQJ
5HPRWHDVVLVWDQFH RQ\RXU
ZRUNVWDWLRQ
RUSUREOHPGHWHUPLQDWLRQ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-22. Copy screen

The Start Copy Screen (STRCPYSCN) command allows you to copy the screens of another display
station on your display station to observe what is happening and diagnose problems.
If the STRCPYSCN command is used to copy displays from a source device that has the
wide-display feature to an output device with a regular-width display, the command is accepted, but
wide-display images are not shown and an informational message is sent to the target work station
indicating that the display was not shown.
If the STRCPYSCN command is used to copy displays from a source device that supports graphic
DBCS characters, the command is accepted and character information is shown, but graphic
DBCS characters appear as single byte. No message is sent.

© Copyright IBM Corp. 1995, 2017 15-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
15.3. Topic 3: Problem determination using IBM
Navigator for i

© Copyright IBM Corp. 1995, 2017 15-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7RSLF3UREOHP
GHWHUPLQDWLRQXVLQJ,%0
1DYLJDWRUIRUL

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-23. Topic 3: Problem determination using IBM Navigator for i

© Copyright IBM Corp. 1995, 2017 15-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$FWLYH-REV'HWDLOV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-24. Active Jobs: Details

To work with active job details using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane find your job and right-click it and from pop-up menu select Details now you
can find the following information: about the job:
▪ Call stack
▪ Library list
▪ Locked objects
▪ Open files
▪ Threads
▪ Transactions
▪ Elapsed performance statistics
▪ SQL

© Copyright IBM Corp. 1995, 2017 15-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$FWLYH-REV-RE/RJ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-25. Active Jobs: Job Log

To work with job log using IBM Navigator for i do following:


1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane, find your job and right-click it and from pop-up menu select Job Log.

© Copyright IBM Corp. 1995, 2017 15-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$FWLYH-REV(ODSVHG3HUIRUPDQFH6WDWLVWLFV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-26. Active Jobs: Elapsed Performance Statistics

To work with active job details using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane, find your job and right-click it and from pop-up menu select Details and then
Performance and Elapsed Performance Statistics.
This is a way to get a job's performance statistics.

© Copyright IBM Corp. 1995, 2017 15-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV*HQHUDO

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-27. Job properties: General

To work with active job details using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane, find your job and right-click it and from pop-up menu select Details and then
Properties.
Job properties show you all of the information related to your job. Consider how knowing or being
aware of the information displayed through these panels could be helpful when solving problems
related to your jobs.

© Copyright IBM Corp. 1995, 2017 15-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV3HUIRUPDQFHDQG3ULQWHU2XWSXW

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-28. Job properties: Performance and Printer Output

Another two tabs Performance and Printer Output allow a user to monitor and alter the job's
performance metrics and control printed output.

© Copyright IBM Corp. 1995, 2017 15-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV0HVVDJHVDQG-RE/RJ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-29. Job properties: Messages and Job Log

On the Message tab, you can manage message handling. Job Log tabs allows you to manage job
log attributes for you job.

© Copyright IBM Corp. 1995, 2017 15-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV6HUYHUDQG6HFXULW\

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-30. Job properties: Server and Security

The Server tab allows you to view information about server jobs. For each server job, you can see
the type of server, job user identity, and if available, the client IP address.
Security allows you to view properties related to security for jobs that are currently active.

© Copyright IBM Corp. 1995, 2017 15-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV'DWH7LPHDQG,QWHUQDWLRQDO

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-31. Job properties: Date/Time and International

Date/Time and International allows you to monitor and alter the job's date, time and international
attributes.

© Copyright IBM Corp. 1995, 2017 15-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

-RESURSHUWLHV7KUHDGV5HVRXUFHVDQG2WKHU

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-32. Job properties: Threads, Resources, and Other

The Treads, Resources, Others tabs allows you to monitor and alter the job's thread and resource
attributes.

© Copyright IBM Corp. 1995, 2017 15-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

(QGDMRE

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-33. End a job

To delete active job using IBM Navigator for i do following:


1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand Work Management then click Active Jobs.
3. On the main pane, find your job and right-click it and from pop-up menu select Delete /End.
Use the Confirm Delete/End dialog to delete selected jobs. To delete a job means the job's
processing is ended. The jobs are ended when you click Delete.

© Copyright IBM Corp. 1995, 2017 15-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$FWLYH3RROV3HUIRUPDQFHVWDWLVWLFV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-34. Active Pools: Performance statistics

To work with Active Pools performance statistics using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand System then click system Status and choose Memory.
3. On the Memory tab, click Active Memory Pools to work with performance statistics (this sis
equivalent for WRKSYSSTS command).
4. On the Memory tab click Memory Pools Health Indicators to display the performance data.
The data is rendered as charts or tables depending on which perspective is displayed.
To perform an action, select the wanted action from the Select Action field.
You can use the menu at the top of the perspective or the buttons at the bottom to perform actions
against the entire perspective. These include:
• Perspective
▪ Save As...: This action will allow you to save your current perspective to a specific location.
▪ Done: This action will close the current perspective and return you to the previous panel.
• Edit
▪ Edit Perspective: This action will allow you to manipulate the current perspective.

© Copyright IBM Corp. 1995, 2017 15-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
▪ Options: This action will allow you to change your user options for this task.
• View
▪ Show Context: This action will show or hide relevant collection information.
▪ Show System Information: This action will show or hide detailed system configuration
information for the physical system where the collection was created.
▪ History: This menu allows you to view all prior perspectives that have been loaded, and
return to them using a single click. This acts similarly to a web browser history.
▪ Home: This action will take you back to the initial panel and allow you to start over.

© Copyright IBM Corp. 1995, 2017 15-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

6\VWHPRSHUDWRUPHVVDJHV RI 

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-35. System operator messages (1 of 2)

To work with System Operator messages using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane, expand System then click System Operator Messages.
3. On the main pane messages will be displayed.

© Copyright IBM Corp. 1995, 2017 15-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

6\VWHPRSHUDWRUPHVVDJHV RI

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-36. System operator messages (2 of 2)

To see more detail right-click the selected message and choose from pop-up menu Properties.
A variety of system messages can indicate conditions that range from simple typing errors to
problems with system devices or programs. Error messages can be sent to a message queue or to
a program and shown on a display. Messages might be one of the following:
• An error message on your current display
• A message regarding a system problem that is sent to the system operator message queue,
QSYSOPR
• A message regarding a device problem that is sent to the message queue specified in a device
description
• A message regarding a potential server system condition that is sent to the QSYSMSG
message queue, the system operator message queue, and other message queues specified by
the users
• An unexpected error message that is not handled by a program (shown on the Display Program
Messages display)

© Copyright IBM Corp. 1995, 2017 15-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
15.4. Topic 4: Using the power off switch

© Copyright IBM Corp. 1995, 2017 15-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7RSLF8VLQJWKHSRZHURII
VZLWFK

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-37. Topic 4: Using the power off switch

© Copyright IBM Corp. 1995, 2017 15-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

:K\XVHWKHSRZHUVZLWFK"

,I,KDYHWRVKXWGRZQWKH
V\VWHPDEQRUPDOO\ZKDW
6KXWGRZQXVLQJ
FDQ,GRWRUHGXFHWKHWLPH
WKHSRZHUVZLWFK
IRUWKHQH[W,3/"
RUSRZHUSXVK
EXWWRQ

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-38. Why use the power switch?

It is vital for the system to shut down normally so that internal directories can be written to auxiliary
storage. Damage to internal directories results in a very long IPL. It is also important from your
application point of view that any changes made to data are also written to auxiliary storage.

© Copyright IBM Corp. 1995, 2017 15-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

3RZHUGRZQLQLWLDWLRQXVLQJSRZHUSXVKEXWWRQRUSRZHU
VZLWFK
‡ 7KLVRSHUDWLRQHQGV
ƒ $OOLQWHUUXSWHG0,LQVWUXFWLRQVFRPSOHWHG
ƒ 3RZHURIIIROORZV
ƒ 1H[W,3/ORQJHUWKDQQRUPDO
‡ ,IQRWFRPSOHWHGLQPLQXWHV\RXVKRXOGXVHV\VWHPSUREOHP
KDQGOLQJSURFHGXUHV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-39. Power down initiation using power push button or power switch

Powering off your system by using the Power Switch.


What function does this action perform?
It allows the system to complete machine interface (MI) instructions that would be interrupted
during abnormal system end.
What happens on the system?
Objects referred to by MI instruction are marked as usable.
This will avoid a lengthy IPL.
When to perform this type of power down?
Perform this action when you cannot execute the PWRDWNSYS command. You should only use the
Power Switch if normal shutdown is not possible.
Note in biggest environment in one server can be installed and running many partitions and after
switch off the server all partitions will cause an abnormal power down.

© Copyright IBM Corp. 1995, 2017 15-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

:KDWFDQ,GRWRKHOSPLQLPL]HSUREOHPV"
‡ <RXFDQ
ƒ 5HFRJQL]HQRUPDOYHUVXVDEQRUPDO
í 6\VWHPSHUIRUPDQFH
í -REPL[
ƒ *HWULGRIXQQHHGHGREMHFWV
í &OHDQXS\RXUV\VWHP

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-40. What can I do to help minimize problems?

It is very important that you start observing your system using the commands shown previously in
this unit so that you are aware of the values presented under normal circumstances. Then, when
something abnormal does occur, it is easier for you to identify it.
You also should do housekeeping on your system on a regular basis so that the IBM i is not tracking
unnecessary jobs or objects.

© Copyright IBM Corp. 1995, 2017 15-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty
15.5. Topic 5: System cleanup

© Copyright IBM Corp. 1995, 2017 15-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7RSLF6\VWHPFOHDQXS

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-41. Topic 5: System cleanup

© Copyright IBM Corp. 1995, 2017 15-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

&OHDQLQJXS\RXUV\VWHP
‡ 7HPSRUDU\OLEUDULHVGHOHWHG
‡ :RUNFRQWUROEORFNVFRPSUHVVHG QTOTJOB
‡ 8QXVHGDGGUHVVHVPDGHDYDLODEOH
‡ 6XEV\VWHPMREORJVFORVHG
‡ 1HZMREORJVFUHDWHG

7KHWDVNVSHUIRUPHGGXULQJDQ,3/
UHVXOWLQDPRUHHIILFLHQWV\VWHP

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-42. Cleaning up your system

When you IPL, the system does some housekeeping of system jobs and workspace, resulting in a
more efficient IBM i.

© Copyright IBM Corp. 1995, 2017 15-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$XWRPDWLFFOHDQXS 2SHUDWLRQDO$VVLVWDQW

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-43. Automatic cleanup (Operational Assistant)

GO CLEANUP, option 1 (or GO ASSIST, option 11, 2, then 1), allows you to change the automatic
cleanup options for messages, job logs and other system output, system journals, and system logs.
You have the option of keeping any of these items and still doing automatic cleanup for the others.
The number of days shown on this visual is the default.

© Copyright IBM Corp. 1995, 2017 15-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7DLORULQJDXWRPDWLFFOHDQXS RI
$XWRPDWLFFOHDQXS 0DQXDOFOHDQXS
0HVVDJHV 0HVVDJHV
‡ 8VHUPHVVDJHTXHXHV ‡ $OORWKHUTXHXHV
‡ :RUNVWDWLRQPHVVDJHTXHXHV
‡ 6\VWHPRSHUDWRUPHVVDJHTXHXH

3ULQWHURXWSXW 3ULQWHURXWSXW
‡ 2XWSXWTXHXHQEZJOBLOG MREORJV ‡ $OORWKHURXWSXWTXHXHV
‡ 2XWSXWTXHXHQEZDEBUG VHUYLFHDQGSURJUDP
GXPSV

-RXUQDOV -RXUQDOV
‡ ',$ILOHVMRXUQDO ‡ 6HFXULW\MRXUQDO
‡ '61;MRXUQDO ‡ $OOXVHUMRXUQDOV
‡ 3UREOHPGDWDEDVHVMRXUQDO
‡ 3HUIRUPDQFHDGMXVWPHQWMRXUQDO
‡ -REDFFRXQWLQJMRXUQDO
‡ 26,0HVVDJH6HUYLFHVMRXUQDO
‡ 0DQDJHG6\VWHP6HUYLFHMRXUQDO
‡ $SSOLFDWLRQ(QDEOHU2)&ILOHVMRXUQDO
‡ $SSOLFDWLRQSURJUDPGULYHUILOHVMRXUQDO
‡ 6103MRXUQDO

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-44. Tailoring automatic cleanup (1 of 3)

This chart shows exactly what is handled by the automatic cleanup and what objects you still need
to clean up manually.

© Copyright IBM Corp. 1995, 2017 15-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7DLORULQJDXWRPDWLFFOHDQXS RI
$XWRPDWLFFOHDQXS 0DQXDOFOHDQXS
‡ $SSOLFDWLRQ'HYHORSPHQW0DQDJHU
7UDQVDFWLRQVMRXUQDO
‡ 3URMHFWORJVMRXUQDO
‡ :RUNRUGHUUHTXHVWMRXUQDO
‡ 406'MREMRXUQDO

2WKHUV\VWHPREMHFWV 2EMHFWVFUHDWHGE\DSSOLFDWLRQVRUXVHUV
‡ +LVWRU\ORJ ‡ 'DWDEDVHILOHV GHOHWHLIQRORQJHUQHHGHG
‡ 3UREOHPORJDQGILOHV ‡ 'DWDEDVHILOHV UHRUJDQL]H
‡ $OHUWVGDWDEDVH ‡ 3URJUDPV IRUH[DPSOH4XHU\
‡ 37)VDYHILOHV
‡ 5HFODLPWHPSRUDU\VWRUDJHXVHGE\
WHPSRUDULO\GHFRPSUHVVHGREMHFWV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-45. Tailoring automatic cleanup (2 of 3)

This visual continues the list of system objects that automatic cleanup affects.

© Copyright IBM Corp. 1995, 2017 15-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

7DLORULQJDXWRPDWLFFOHDQXS RI
• RTVCLSRC
ƒ PGM(QSYS/QEZUSRCLNP) SRCFILE(SOURCE-LIB/SOURCE-FILE)

• STRPDM
ƒ 8VH6(8WRFRGHDGGLWLRQDOIXQFWLRQV

‡ &RPSLOHQEZUSRCLNP DQGVWRUHLWLQDOLEUDU\
ƒ 7KHOLEUDU\\RXVWRUHLWLQVKRXOGSUHFHGH46<6LQWKHOLEUDU\OLVW

1RZ<RXUYHUVLRQRIQEZUSRCLNP ZLOOEHDXWRPDWLFDOO\UXQE\WKH
V\VWHP

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-46. Tailoring automatic cleanup (3 of 3)

The IBM-supplied automatic cleanup program is called QEZUSRCLNP. You can add additional
function to this program if you choose

© Copyright IBM Corp. 1995, 2017 15-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HRUJDQL]HILOH
‡ 7KLVIUHHVVWRUDJHXVHGE\GHOHWHGUHFRUGVLWFDQDOVRVHTXHQFHDILOH
PRUHHIILFLHQWO\
‡ ,IDILOHLVMRXUQDOHGEDFNLWXSLPPHGLDWHO\DIWHULWLVUHRUJDQL]HG

DSPFD FILE(Name) TYPE(*MBRLIST)

DELETED
MEMBER SIZE_ _ _ _ _ _ _ _RECORDS RECORDS

BROCHPF 12493824 45712 5981

RGZPFM FILE(Name) MBR(Name) KEYFILE(File Member)

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-47. Reorganize file

The Reorganize Physical File Member (RGZPFM) command removes deleted records from
(compresses) one member of a physical file in the database, and it optionally reorganizes that
member.
A file description shows how many deleted rows (records) it has.
Also check large files for deleted records.
Reorganizing a file frees the space occupied by deleted records and can re sequence the records
so that it lends itself to faster processing.

© Copyright IBM Corp. 1995, 2017 15-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HRUJDQL]HILOHRUWDEOH

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-48. Reorganize file or table

Check the number of rows and the number of deleted rows of your large files. The space occupied
by deleted records/rows can be regained by reorganizing the file.
To reorganize table using IBM Navigator for i do following:
1. Log on to the system using web browser [Link] address or system name>:2001.
2. On the left pane expand Database then Databases and expand your database.
3. Click selected schema.
4. On the main pane right-click the Table and choose Open.
5. Right-click the selected table and from pop-up menu select Data and Reorganize.
This can be compare to CL RGZPFM command.

© Copyright IBM Corp. 1995, 2017 15-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

&OHDU6DYH)LOH &5/6$9)
‡ 6DYLQJXVLQJDVDYHILOH

*FILE *SAVF

SAVSAVFDTA
SAVOBJ CUSTMAST
CUSTMAST CUSTMAST

:DVWHG
VSDFHRQ
V\VWHP

CLRSAVF FILE(SAVE-FILE-NAME)

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-49. Clear Save File (CRLSAVF)

Once a save file has been copied to tape (SAVSAVFDTA), the information in the save file no longer
needs to be kept on disk. Running CLRSAVF frees up disk space, but leaves the save file itself
there for the next time it is needed.

© Copyright IBM Corp. 1995, 2017 15-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HFODLP6WRUDJH 5&/67*
‡ 8QH[SHFWHGIDLOXUHFDQFDXVHXQXVXDOFRQGLWLRQV
ƒ 2EMHFWVQRWFRUUHFWO\XSGDWHG GDPDJHG
ƒ 8VHUSURILOHVPLJKWFRQWDLQLQFRUUHFWLQIRUPDWLRQDERXWREMHFWRZQHUVKLS

‡ &RQVLGHUUXQQLQJRCLSTS ZKHQ
ƒ WRKSYSSTS-+LJKSHUFHQWDJHRIDX[LOLDU\VWRUDJHXVHG
ƒ 8QXVXDOWKLQJVH[LVWZKHQ\RX
í :RUNZLWKREMHFWGHVFULSWLRQ
í :RUNZLWKXVHUSURILOHV
ƒ 6WDUWLQJV\VWHP
í 0HVVDJHUHFHLYHGQRWHQRXJKVWRUDJH
ƒ +DYHQRWUXQRCLSTG LQTXLWHDZKLOH

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-50. Reclaim Storage (RCLSTG)

To run RCLSTG, the system must be in a restricted state. Depending on the amount of DASD on
your system and the number of objects, RCLSTG might take a number of hours to run. However, it
can clear up problems with objects that cannot be addressed any other way. It is recommended to
perform backup before reclaim storage if it is possible.

© Copyright IBM Corp. 1995, 2017 15-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5&/67*FRPPDQG

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-51. RCLSTG command

The RCLSTG command attempts to correct objects that were incompletely updated such as
database files, libraries, device descriptions, user profiles with incorrect object ownership
information, directories and stream files. Any unusable objects or fragments are deleted. The
command has four parameters: Estimate, Select, Omit and ASPDEV.
ESTIMATE: Specifies whether to calculate an estimate of the amount of time that the RCLSTG
command will take to run. The estimate is calculated by using statistics collected during previous
RCLSTG operations and the values specified for the other RCLSTG parameters. The options are
*YES or *NO, with *NO as the default.
SELECT: Specifies whether to run all reclaim functions or only one specific reclaim function. The
choices for this parameter are *ALL, *DBXREF and *DIR. *ALL is the default. This parameter tells
the system to reclaim the database cross-reference table and all file objects or the directory and its
IFS objects, or both.
OMIT: Specifies the reclaim functions that you would like omitted during the reclaim process. The
choices are *NONE, *DBXREF or *DIR. *NONE is the default.
ASPDEV: Specifies the auxiliary storage pool (ASP) that is to be reclaimed. The options are
*SYSBAS (pools 1 through 32), an auxiliary-storage-pool-device-name (pools higher than 32) or an
auxiliary-storage-pool-group-name (wherein the primary and secondary ASPs within the ASP group
named) will be reclaimed. The default is *SYSBAS.

© Copyright IBM Corp. 1995, 2017 15-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

$IWHUUXQQLQJ5&/67*
‡ 'LUHFWRU\45HFODLP URRWILOHV\VWHPREMHFWVRQO\

‡ /LEUDU\45&/
ƒ ([DPLQHDIWHUUXQQLQJRCLSTG
ƒ DSPLIB 45&/

‡ 7DNHDSSURSULDWHDFWLRQ
ƒ 'HOHWHXQXVDEOHREMHFWV
ƒ 0RYHREMHFWV
ƒ *UDQWDXWKRULW\
ƒ 7UDQVIHURZQHUVKLS
ƒ &RS\GDWDWRUHEXLOGILOHV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-52. After running RCLSTG

After running RCLSTG, examine the contents of QRCL and QReclaim directory. The QReclaim
directory is for lost objects from the Root File system, while the QRCL is for lost objects that normally
reside in libraries.

© Copyright IBM Corp. 1995, 2017 15-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

([HUFLVH3UREOHPGHWHUPLQDWLRQ
‡ 8VHWKH&RS\6FUHHQ,PDJHIDFLOLW\
‡ 'LVSOD\DQGFKDQJHDWWULEXWHVRIDQDFWLYHMRE
‡ &UHDWHDQGYLHZDVSRROILOH
‡ 'LVSOD\WKHMREORJIRUDEDWFKMRE
‡ :RUNZLWKVWDWXVGLVSOD\V
‡ 'LVSOD\WKHKLVWRU\ORJ
‡ $QDO\]HDQGFRUUHFWDSUREOHPZLWKDMRE

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-53. Exercise: Problem determination

© Copyright IBM Corp. 1995, 2017 15-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH7KHSURFHVVRIILQGLQJRXWH[DFWO\ZKDWLVWKHSUREOHPLV
SUREOHPVRXUFHLGHQWLILFDWLRQ

 7KHWZRFODVVLILFDWLRQVRISUREOHPV\PSWRPVDUH
D 0HVVDJHV
E ([WHUQDOV\PSWRPV
F 65&
G ,QWHUQDOV\PSWRPV

 7KHFRPPDQGWRZRUNZLWKDOORIWKHDFWLYHMREVRQWKH,%03RZHU
6\VWHPZLWK,%0LLV
a. WRKJOB
b. WRKACTJOB
c. WRKSBMJOB
d. WRKSPLJOB

 7UXHRUIDOVH:KHQGLVSOD\LQJ\RXUMRE¶VUXQDWWULEXWHV\RXFDQVHOHFW
WKH)NH\WRFKDQJH\RXUMRE

 7UXHRUIDOVH,I\RXUMREKDVQRWHQGHGDIWHUILYHPLQXWHV\RXFDQ
VXEPLWWKHENDJOBABN FRPPDQG

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-54. Review questions (1 of 2)

© Copyright IBM Corp. 1995, 2017 15-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HYLHZDQVZHUV RI
 7UXHRUIDOVH7KHSURFHVVRIILQGLQJRXWH[DFWO\ZKDWLVWKHSUREOHPLVSUREOHPVRXUFH
LGHQWLILFDWLRQ
7KHDQVZHULVIDOVH

 7KHWZRFODVVLILFDWLRQVRISUREOHPV\PSWRPVDUH
D 0HVVDJHV
E ([WHUQDOV\PSWRPV
F 65&
G ,QWHUQDOV\PSWRPV
7KHDQVZHUVDUHH[WHUQDOV\PSWRPVDQGLQWHUQDOV\PSWRPV

 7KHFRPPDQGWRZRUNZLWKDOORIWKHDFWLYHMREVRQWKH,%0L LV
a. WRKJOB
b. WRKACTJOB
c. WRKSBMJOB
d. WRKSPLJOB
7KHDQVZHULVWRKACTJOB

 7UXH RUIDOVH:KHQGLVSOD\LQJ\RXUMRE¶VUXQDWWULEXWHV\RXFDQVHOHFWWKH)NH\WR
FKDQJH\RXUMRE
7KHDQVZHULVWUXH

 7UXHRUIDOVH,I\RXUMREKDVQRWHQGHGDIWHUILYHPLQXWHV\RXFDQVXEPLWWKH
ENDJOBABN FRPPDQG
7KHDQVZHULVIDOVH
3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-55. Review answers (1 of 2)

© Copyright IBM Corp. 1995, 2017 15-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HYLHZTXHVWLRQV RI
 7UXHRUIDOVH&KRRVLQJWKH$FWLYH-REVEUDQFKLQ,%0L
1DYLJDWRULVHTXLYDOHQWWRXVLQJWKHWRKACTJOB FRPPDQG
RQWKHJUHHQVFUHHQ

 7UXHRUIDOVH2QO\WKHV\VWHPRSHUDWRUFDQPDNHFKDQJHV
WRDXVHU¶VMRE

 7UXHRUIDOVH7KHSUHIHUUHGPHWKRGWRVKXWGRZQDQ,%0
3RZHU6\VWHPZLWK,%0LLVWRXVHWKHSRZHUVZLWFK

 7UXHRUIDOVH7KH&/($183SURJUDPZLOODOZD\VUXQ
DXWRPDWLFDOO\RQ\RXUV\VWHPDWPLGQLJKW

 7UXHRUIDOVH$SURJUDPPHUFDQXSGDWHWKH&/($183
SURJUDPWRSHUIRUPZKDWHYHUXVHUDFWLYLWLHVWKHSURJUDPPHU
GHFLGHVWRDGG
3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-56. Review questions (2 of 2)

© Copyright IBM Corp. 1995, 2017 15-65


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

5HYLHZDQVZHUV RI
 7UXH RUIDOVH&KRRVLQJWKH$FWLYH-REVEUDQFKLQ,%01DYLJDWRUIRULLV
HTXLYDOHQWWRXVLQJWKHWRKACTJOB FRPPDQGRQWKHJUHHQVFUHHQ
7KHDQVZHULVWUXH

 7UXHRUIDOVH2QO\WKHV\VWHPRSHUDWRUFDQPDNHFKDQJHVWRDXVHU¶VMRE
7KHDQVZHULVIDOVH

 7UXHRUIDOVH7KHSUHIHUUHGPHWKRGWRVKXWGRZQDQ,%0LLVWRXVHWKHSRZHU
VZLWFK
7KHDQVZHULVIDOVH

 7UXHRUIDOVH7KH&/($183SURJUDPZLOODOZD\VUXQDXWRPDWLFDOO\RQ\RXU
V\VWHPDWPLGQLJKW
7KHDQVZHULVIDOVH

 7UXH RUIDOVH$SURJUDPPHUFDQXSGDWHWKH&/($183SURJUDPWRSHUIRUP


ZKDWHYHUXVHUDFWLYLWLHVWKHSURJUDPPHUGHFLGHVWRDGG
7KHDQVZHULVWUXH

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-57. Review answers (2 of 2)

© Copyright IBM Corp. 1995, 2017 15-66


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 15. Problem determination

Uempty

8QLWVXPPDU\
‡ 'LVSOD\V\VWHPLQIRUPDWLRQDQGLGHQWLI\SUREOHPMREV
‡ &KDQJHYDOXHVWKDWDIIHFWV\VWHPSHUIRUPDQFHDQGSUREOHPKDQGOLQJ
‡ 6FKHGXOHIXQFWLRQVWKDWDYRLGV\VWHPSUREOHPV

3UREOHPGHWHUPLQDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 15-58. Unit summary

© Copyright IBM Corp. 1995, 2017 15-67


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

Unit 16. Introduction to Backup Recovery


and Media Services
Estimated time
00:45

Overview
This unit provides an overview of the features and functions of Backup, Recovery, and Media
Services included Cloud Solutions.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 16-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHWKHIHDWXUHVDQGIXQFWLRQVSURYLGHGE\%506
‡ /LVWWKHGLIIHUHQWVRIWZDUHWKDWPDNHVXSWKH%506SURGXFW
‡ 'LVFXVVWKHEHQHILWVRIXVLQJ%506IXQFWLRQV
‡ 'LVFXVVWKHEHQHILWVRIXVLQJWKH%506&ORXG6ROXWLRQV
‡ 'LVFXVVWKHEHQHILWVRIXVLQJ%5061HWZRUNDQG(QWHUSULVHVHUYLFHV
‡ 'HVFULEHWKHIXQFWLRQVVXSSRUWHGIRU%506E\,%01DYLJDWRUIRUL

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 16-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
16.1. Topic 1: Overview of BRMS functions and
features

© Copyright IBM Corp. 1995, 2017 16-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

7RSLF2YHUYLHZRI%506
IXQFWLRQVDQGIHDWXUHV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-2. Topic 1: Overview of BRMS functions and features

Backup Recovery and Media Services (BRMS) provides a robust, easy-to-use graphical user
interface to perform save and recovery operations and to manage media.

© Copyright IBM Corp. 1995, 2017 16-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506VRIWZDUH RI
‡ ,QVWDOO26RSWLRQVDQG%506
ƒ 66 2SWLRQ0HGLDDQG6WRUDJH([WHQVLRQV
í 3UHUHTXLVLWH
ƒ 66 2SWLRQ(QFU\SWHG%DFNXS(QDEOHPHQW
ƒ %5 %$6(
ƒ %5 2SWLRQ1HWZRUNIHDWXUH
ƒ %5 2SWLRQ$GYDQFHG)XQFWLRQVIHDWXUH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-3. BRMS software (1 of 2)

The OS feature is a prerequisite feature to BRMS. It also required when developing HSM dynamic
retrieval functions.
Media and Storage Extensions provides an API to enable application monitoring and control of
media usage, including volumes to be selected and volume expiration dates. This can be useful for
software developers who want to customize their own storage management applications.
An API is provided to handle the interruption that occurs when an application tries to open a
database file that was migrated to offline media. The API enables an on-demand recall of a
database file from offline media to direct access storage device (DASD) and resumption of the
application. Application changes are not required.
These APIs provide support to use or build applications to manage tape usage and the recall of
data from offline media to DASD.

© Copyright IBM Corp. 1995, 2017 16-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV RI
‡ 3ULPDU\IXQFWLRQV
ƒ %DFNXSDQGUHFRYHU\ OLFHQVH %$6(RSWLRQ

ƒ 1HWZRUNLQJ OLFHQVHRSWLRQ

ƒ $UFKLYHDQGUHWULHYH OLFHQVHRSWLRQ

ƒ +LHUDUFKLFDOVWRUDJHPDQDJHPHQW OLFHQVHRSWLRQ

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-4. Backup Recovery and Media Services (2 of 2)

Base Product
BRMS provides the following functions in the base product:
1. Backup
▪ Backup planning interfaces
▪ Online backup of Lotus server and journaled objects
▪ Automated backup capabilities
▪ Media library support for both IBM and third-party media libraries
▪ TSM client
▪ Parallel save capabilities
▪ Unattended restricted state backup
▪ Maintain complete backup history
2. Recovery
▪ System disaster recovery report
▪ Automated point-in-time recovery for Lotus server and journaled objects

© Copyright IBM Corp. 1995, 2017 16-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
▪ Individual object recovery
▪ Automated recovery capabilities
3. Media Management
▪ Media reporting, tracking, and selection
▪ Manage media movement
▪ Protect and secure media
▪ Duplicate media
▪ Reclaim fragmented media
Optional Features
In addition, there are two optional features, which you can add to the base product to provide
greater functional capability.
BRMS Network Feature
With the BRMS Network Feature, a BRMS system is connected to other BRMS systems in the
network using native TCP/IP and/or APPN. A BRMS network system provides:
• Centralized media management
• The ability to restore data from another system
BRMS Advanced Feature
The BRMS Advanced feature enables Hierarchical Storage Manager (HSM) archive with HSM
dynamic retrieval and automated auxiliary storage pool (ASP) data migration. Some of the
functions provided by HSM are:
• Automatic, transparent management of data across a storage hierarchy
• Migration of user libraries, folders, and spooled files between ASPs
• Archive (with storage free option)
• Dynamic retrieval
• Automatic movement of data, based on system policies
In addition, the BRMS Advanced feature is required to use the following functions in BRMS:
• Media library management
▪ BRMS System defined name
▪ Tape media library status tool
▪ Software encryption
▪ High availability for I-ASPs in a BRMS network

© Copyright IBM Corp. 1995, 2017 16-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%5065HVWULFWLRQV
‡ 5HVWULFWLRQV
ƒ 7DSHYROXPHV SK\VLFDODQGYLUWXDO PXVWKDYHDXQLTXHYROXPH,'
ƒ 7KHUHLVQRVXSSRUWIRU
í 'LVNHWWH
í 8QODEHOHGRUQRQVWDQGDUGODEHOHGWDSHV
ƒ ,WGRHVQRWVXSSRUWSAVSTGCPYTOTAPRUCPYFRMTAP QDWLYHO\
ƒ ,WFDQQRWUXQRQWKHVDPHV\VWHPDVRWKHUWDSHPDQDJHPHQWVRIWZDUH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-5. BRMS: Restrictions

Incompatible with other tape management solutions.


If you have another tape management solution installed on your system when BRMS is installed,
the existing tape management solution may no longer work correctly. This is due to a low-level tape
routine provided by IBM to many non-IBM tape management system vendors. This routing
intercepts any tape activity and calls a nominated program. If BRMS is installed after one of these
other products (even if for a trial), this routine will call the BRMS program for checking tape activity,
rather than the routine for the original product.
You can use the CPYTOTAP or CPYFRMTAP commands controlled by BRMS. Before running one of
these commands you have to set input and output controls issuing the SETMEDBRM command.

© Copyright IBM Corp. 1995, 2017 16-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

6XSSRUWHGWDSHV\VWHPV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-6. Supported tape systems

The website captured in the visual is the best place to get the most up-to-date details about what
specific tape hardware is supported for attachment to your IBM i system.
[Link]
Note that we are not talking about tape drive or physical tape library because many installations are
more complicated basing on VTL appliance (virtual tape library) which use VTL and storage.

© Copyright IBM Corp. 1995, 2017 16-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

)ODVK&RS\VXSSRUW2YHUYLHZ

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-7. FlashCopy support: Overview

FlashCopy creates a copy of the source system onto a second set of disk drives, which are then
attached and used by another system or logical partition (LPAR). The BRMS implementation of
FlashCopy provides a way to perform a backup on a system that has been copied by FlashCopy
and a BRMS history appears, as the backup is performed, on the production system.
For this functionality you need external storage.

Important

If you plan to use online Domino backup, you must do the backup on the production system. You
must save all journal receivers on the production system to avoid journal receiver conflict and to
enable point-in-time recovery.

BRMS stores backup history and media information in a library called QUSRBRM. The files in this
library define both the setup of the BRMS environment and the dynamic information gathered as a
result of doing BRMS operations such as saves and restore tasks. This information is critical to the
recovery of the system. When using FlashCopy to create a full system image, QUSRBRM is also
copied from the production system to the backup system.

© Copyright IBM Corp. 1995, 2017 16-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
The slide shows two partitions:
1. A production partition for normal day-to-day processing.
2. A backup partition for taking offline backups.
The BRMS FlashCopy function requires the BRMS Network Feature product 5770-BR1. In order to
use BRMS to perform a backup of the copy system, FlashCopy function must be enabled on the
production system. After you enable the BRMS FlashCopy function, all backups that are performed
on the backup system look like they were performed on the production system.
This solution can be upgraded to more flexibility by using FSCSM (Full System Copy Services
Manager) product IBM Lab Services.

© Copyright IBM Corp. 1995, 2017 16-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

2YHUYLHZRI%506VWDQGDUGSURGXFWIXQFWLRQDOLW\

%DFNXS

+RZ :KDW :KHUHWRVWRUH

3ROLFLHV &RQWUROJURXSV 'HYLFHV 0HGLD0DQDJHPHQW

+RZ :KDW :KHUHWRUHWULHYH

5HFRYHU\

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-8. Overview of BRMS standard product functionality

The visual illustrates how BRMS processes backups and recoveries through the media
management system. Policies, control groups, and devices link the backup and recovery
processes.
Through user-defined controls, BRMS works in conjunction with your IBM i platform to manage your
most critical and complex backups while simplifying day-to-day operational tasks. The standard
BRMS product provides three basic functions.
Backup: BRMS backup assists you in establishing a disciplined approach to designing and
managing your backup operations. It helps you to define, process, monitor, and report your backup
activities. Use BRMS to back up all of the data on your IBM i platform including objects in libraries,
folders, directories, spooled files, security information, system configurations, and the operating
system itself. To do this, you can use the default backup control groups, already set up in BRMS, or
you can design your own backup operation to suit more specific needs.
Recovery: BRMS recovery provides for the orderly retrieval of lost or damaged data. Its most
important feature is a series of recovery reports that take you, step-by-step, through the recovery of
your system. These reports not only contain restore instructions, but also indicate which volumes
the system requires for the recovery. With BRMS, you can restore your entire system, or selected
items such as control groups, libraries, objects, folders, auxiliary storage pools (ASPs), spooled
files, or integrated file system links.

© Copyright IBM Corp. 1995, 2017 16-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
Media Management: BRMS media management tracks all of your tapes and save files. Media is
tracked through all cycles from media creation to expiration. The tracking process includes active
use, storage location, and return to scratch pool availability. BRMS tracks your media until you
remove it from the media inventory or until it is otherwise disabled due to usage threshold or poor
quality rating. BRMS also records and updates changes to the media inventory.

© Copyright IBM Corp. 1995, 2017 16-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506PDLQPHQX *2%506

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-9. BRMS main menu (GO BRMS)

To work with main BRMS menu run GO BRMS.

© Copyright IBM Corp. 1995, 2017 16-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506SROLFLHV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-10. BRMS policies

BRMS offering few types policies depending on management task that you want to perform.
Policies define how BRMS operations are generally to be done, similar to the ways in which system
values control how your IBM i product operates.
Policies establish actions and assumptions that are used during processing. They also provide a
single point of control for administering broad changes in operating principles. Each policy provides
a template for managing backup and media management strategies at high levels.
Types of policies
The standard BRMS package provides the following policies:
• The System Policy is very similar to a set of system values. Unless other policies or controls
are in place, system policy parameters determine the policy defaults for many of your BRMS
operations.
• The Backup Policy specifies how to perform backups. You can define weekly backup activities,
types of incremental backup, and the level at which you want to save media information. One
backup policy governs all backup operations. You can define or change these operations at the
control group level.

© Copyright IBM Corp. 1995, 2017 16-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
• The Recovery Policy defines how recovery operations are generally to be performed. One
recovery policy governs all recovery operations. You can redefine or change recovery
command values to allow for single or phased recoveries.
• The Media Policies govern the handling of media by media type. Media policies determine
retention periods and instruct BRMS where to find the appropriate tapes to perform your
backup. They also determine whether backup operations will create and use save files. Unlike
system, backup, and recovery policies, multiple media policies can exist.
• The Move Policy determines the movement of media from creation through expiration, and
through various on and off-site storage locations. Multiple move policies can also exist.

© Copyright IBM Corp. 1995, 2017 16-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%DFNXSFRQWUROJURXSV RI
‡ 'HVFULEHVWKHEDFNXS
ƒ :KDWWREDFNXSOLEUDULHVREMHFWVIROGHUVVSRROILOHVREMHFWVLQGLUHFWRULHV
VSHFLDOYDOXHV
ƒ )XOORUFXPXODWLYH
ƒ 6DYHZKLOHDFWLYH
‡ &RQWUROVEDFNXSV
ƒ 6XEV\VWHPVWRHQGMRETXHXHVWRKROGXVHUVWRVLJQRII
ƒ :KLFKPHGLDWRVHOHFW
ƒ 8VHVDYHILOHV
ƒ 8VHYLUWXDOWDSH
‡ 7UDFNVVXFFHVVRIEDFNXS
ƒ %506ORJVKRZVDOOEDFNXSDFWLYLW\
ƒ %DFNXSDFWLYLW\UHSRUWVKRZVDOOLWHPVVDYHGDQGPLVVHG
ƒ 6DYHVWUDWHJ\H[FHSWLRQVVKRZVOLEVQHYHUEDFNHGXS
‡ )DFLOLWDWHVSDUDOOHOVDYHV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-11. Backup control groups (1 of 2)

The backup function is the cornerstone of the BRMS product. It is the option that controls the save
process, which ultimately determines how effectively a system can be restored.
Careful planning is required in determining a backup strategy before using BRMS.
Once the backup control group has been defined, performing a backup is simply a matter of issuing
a command STRBKUBRM (Start Backup using BRM), naming a single backup control group, and
specifying immediate or delayed start, and interactive or batch options. The delayed option submits
the backup job to run at a scheduled time. This is a 24-hour clock submission time.
Conceptually, a backup control group is very much like a control language program (CLP). A CLP
consists of a list of commands that will run as part of calling up the CL program. A backup control
group is very similar in that it is used to identify a list of objects that are to be saved as part of
running this control group.

© Copyright IBM Corp. 1995, 2017 16-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%DFNXSFRQWUROJURXSV RI

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-12. Backup control groups (2 of 2)

A control group defines a group of libraries, lists, and special values (starting with *) to be backed
up.
The WRKCTLGBRM display is used to create, change, copy, or delete control groups. You can
add, edit, or delete entries for subsystems to end or restart and hold or release job queues.
You can perform an IPL after the backup.

© Copyright IBM Corp. 1995, 2017 16-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

'HYLFHV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-13. Devices

The Work with Devices display shows all devices, their category and associated type and model
that have been defined to BRMS. The Work with Devices display allows you to add, change or
remove a device from a list of devices that you want to use in BRMS processing. You can also work
with the configuration status of a device that you select. Devices that are added to the device list
must have been defined to the system through the device description function.

© Copyright IBM Corp. 1995, 2017 16-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0HGLDPDQDJHPHQW :5.0('%50  RI


‡ 7KHWRKMEDBRM FRPPDQG
ƒ 7UDFNVFRQWHQWVRIHDFKWDSH
ƒ 3URWHFWVWDSHVDJDLQVWRYHUZULWLQJ
ƒ 0DQDJHVWDSHPRYHVWRDQGIURPRIIVLWHORFDWLRQV
ƒ /RJVWDSHXVDJHDQGHUURUUDWHV
ƒ 'XSOLFDWHVWDSHVDQGPDQDJHVSDLUV
ƒ 0DQDJHVWDSHVHWV
ƒ 0DQDJHVSDUDOOHOVHWV

‡ 8VHRSWLRQWRLQYRNHWKHWRKMEDIBRM FRPPDQG

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-14. Media management (WRKMEDBRM) (1 of 2)

The Work with Media Information using BRMS (WRKMEDIBRM) command displays media
information based on libraries, date ranges, and sequences. This command can be started from the
command line, or through option 13 at the WRKMEDBRM display. The display shows the date and
time each library was saved, the type of save, the volume serial, and its associated expiration date,
the number of objects that were saved, and the number that were not saved.
Using the default on the command will display all of the BRMS save history, with the most recent
save information displayed first.

© Copyright IBM Corp. 1995, 2017 16-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0HGLDPDQDJHPHQW :5.0('%50  RI

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-15. Media management (WRKMEDBRM) (2 of 2)

The Work with Media display is used to add, change, and remove media volumes in the media
inventory.
Perform media-related processes on single or groups of volumes in the media inventory.
Creation and expiration dates as well as current storage location, current container, and last move
dates are displayed for each volume.
Use F11 to view more information, such as cartridge type, virtual catalog, volume statistics, and so
on.
From this display, most media management functions can be accessed and performed.

© Copyright IBM Corp. 1995, 2017 16-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0HGLDLQIRUPDWLRQ :5.0(',%50  RI


‡ 7KHWRKMEDIBRM FRPPDQG
ƒ 7UDFNVGDWDWKDWKDVEHHQVDYHG
ƒ ,VVRUWDEOH
ƒ $OORZVTXLFNDQGHDV\UHVWRUHV
ƒ &DQYLHZGRZQWRREMHFWPHPEHUGHWDLOLISURSHUOHYHORIGHWDLOKDVEHHQ
VDYHG

‡ 7\SHRIVDYHLVVKRZQ

‡ )VKRZVLIDQ\REMHFWVZHUHPLVVHGGXULQJWKHVDYH
ƒ 'LVSOD\VDQ\HUURUVWKDWPLJKWKDYHEHHQORJJHG

‡ 8VHRSWLRQWRLQYRNHWKHWRKMEDBRM FRPPDQG

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-16. Media information (WRKMEDIBRM) (1 of 2)

The Work with Media Information using BRMS (WRKMEDIBRM) command displays media
information based on libraries, date ranges, and sequences. This command can be started from the
command line, or through option 13 at the WRKMEDBRM display. The display shows the date and
time each library was saved, the type of save, the volume serial, and its associated expiration date,
the number of objects that were saved, and the number that were not saved.
Using the default on the command will display all of the BRMS save history, with the most recent
save information displayed first.

© Copyright IBM Corp. 1995, 2017 16-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0HGLDLQIRUPDWLRQ :5.0(',%50  RI

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-17. Media information (WRKMEDIBRM) (2 of 2)

This column will display how many device resources were used during parallel processing.
This display lists all saved items (libraries, special values, integrated file system information, and so
on) saved by BRMS with their accompanying save information.
This screen allows you to remove saved items from the save history, display saved items or restore
saved items.
You can select object detail to review or restore objects from selected saves, provided information
was saved at that level. (option 9)

© Copyright IBM Corp. 1995, 2017 16-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

5HFRYHU\
‡ 5HFRYHULQJDIHZREMHFWV
ƒ 7KHXVHUVHOHFWVREMHFWVIURPDOLVWRIVDYHGLWHPV
ƒ %506SURYLGHVPRXQWPHVVDJHVDVUHTXLUHG
ƒ 7KHUHLVDQRQOLQHSURJUHVVUHSRUW

‡ 5HFRYHULQJDODUJHQXPEHURIREMHFWVRUZKROHV\VWHP
ƒ 7KHYROXPHVXPPDU\UHSRUWOLVWVYROXPHVQHHGHG
ƒ 7KHUHFRYHU\DQDO\VLVUHSRUWOLVWVVWHSVUHTXLUHG
ƒ %506PDQDJHVWKHUHFRYHU\

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-18. Recovery

BRMS provides facilities to allow you to document a recovery plan using contact lists and activity
lists.
Three recovery reports are printed during the maintenance command. The 'Recovery Analysis
Report' gives you step-by-step instructions to guide you through recovering your system.
When using the *RESTORE option on a full system recovery, the information is displayed on the
screen and is used to guide you through the recovery. You need only use options on a work-with
screen that is refreshed automatically as libraries are restored.
Using BRMS networking allows you to restore information to a system different from the system
that performed the save.

© Copyright IBM Corp. 1995, 2017 16-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

5HFRYHU\ZLWK:5.0(',%50

• WRKMEDIBRM ZLWK 5HVWRUHREMHFW


ƒ :KHQ\RXVHOHFWRSWLRQWKHVXEVHTXHQWVFUHHQVVKRXOGJXLGH\RXWKURXJK
WKHUHVWRIWKHUHVWRUH
,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-19. Recovery with WRKMEDIBRM

The WRKMEDIBRM command will list data that has been backed up using BRMS.
From this screen, I can choose option 7 to restore a specific object that is being tracked by BRMS.
Using this method, makes the recovery or restore of this object very simple because the system is
keeping track of where this data is stored. BRMS will call for the specific tape required and will
know what sequence number on that tape to get the data from. All of this information is
automatically filled into the recovery command.

© Copyright IBM Corp. 1995, 2017 16-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

$UFKLYHDQG5HWULHYDO
‡ $UFKLYH
ƒ /RFDWHDQGOLVWREMHFWVWKDWKDYHQRWEHHQXVHGUHFHQWO\
ƒ 0RYHWKHVHREMHFWVWRWDSHDQGHUDVHIURPGLVN
ƒ 7KLVIUHHVXSGLVNVSDFH

‡ 5HWULHYDO
ƒ 5HVWRUHREMHFWVEDFNWRGLVNZKHQQHHGHG
ƒ )RU FILE,)6DQG'/2REMHFWV%506RSWLRQDOO\VKRXOGDXWRUHFDOOZKHQ
WRXFKHGE\DXVHUSURYLGHGWKDWWKH\DUHDUFKLYHGZLWKSTG(*FREE)

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-20. Archive and Retrieval

Archiving is an effective technique for saving valuable disk space. The archive facility in BRMS
enables you to manage the storage on tape and removal from disk of seldom-used or inactive
objects, including documents and folders.
BRMS also simplifies the retrieval of such archived objects. It is this type of function and control that
makes data archival a more viable option. Users are reticent about allowing objects to be deleted
from the system unless there is a reliable facility that manages the archival and retrieval process.

© Copyright IBM Corp. 1995, 2017 16-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

$UFKLYH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-21. Archive

The WRKCTLGBRM TYPE(*ARC) command allows you select which objects the archive job has to
judge to determine whether they become an archive candidate. Each BRMS control group (Backup
as well as Archive) is provided with lots of attributes. With Archive the specific attributes define the
archive candidates.
The Start Archive using BRM (STRARCBRM) command selects a control group and begins the
archive process. You can start the archive immediately or you can schedule it using the system job
scheduler.
Processing can be batch or interactive.

Note

The default value for the Option (OPTION) parameter is *REPORT, which produces a report of
archive candidates. To perform an archive, you must change the OPTION parameter to *ARCHIVE.

© Copyright IBM Corp. 1995, 2017 16-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

5HWULHYDO
‡ 2EMHFWVDUFKLYHGZLWKWKHSTG(*FREE)SDUDPHWHU
ƒ /HDYHREMHFWGHVFULSWLRQLQSODFH
ƒ 'RZQWRPHPEHUOHYHO
‡ 7KHVHREMHFWVFDQEHG\QDPLFDOO\UHWULHYHGXSRQDFFHVVVXFKDVILOH
RSHQ
‡ 6HDPOHVVRSHUDWLRQLIXVLQJWDSHOLEUDU\
ƒ 6WDQGDORQHGULYHZRXOGEHUHVWRUHRSHUDWLRQ
‡ 5HWULHYHRSHUDWLRQVFDQEHSHUIRUPHGLQ
ƒ %DWFK
ƒ ,QWHUDFWLYH
ƒ 6HWIRUODWHUUHWULHYDO
í %DVHGRQWKHUHWULHYHSROLF\

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-22. Retrieval

© Copyright IBM Corp. 1995, 2017 16-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

6HW5HWULHYH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-23. Set Retrieve

The Set Retrieve Controls for BRM (SETRTVBRM) command can be used to change the way that
retrieve operations work when performed by your job.
The controls you specify with SETRTVBRM remain in effect for the duration of your job or until they
are reset or otherwise changed by another SETRTVBRM command. The controls you specify with
this command are not kept when the job ends. To see control values that are currently in effect, type
the SETRTVBRM command on a command line and press F4.

© Copyright IBM Corp. 1995, 2017 16-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0LJUDWLRQ
,)6QRZ
VXSSRUWHG
/LEUDU\6XSSRUW

6 + 6 + 6 +
6 ' 6 ' 6 '
' ' ' ' ' '

$63 8VHU$63 ,$63

1(:,$636833257
&DQPRYH3)/)ILOHVZLWKLQ
DQ$63
%HWZHHQ66' )DVW DQG
+'' 6ORZ 

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-24. Migration

Now the objects (PF/LF, IFS, Library) can be migrate between disks HDD/SSD and between ASP’s
and IASP.
Similar to the IBM Storage Easy Tier function, the BRMS storage tiering function within an ASP
responds to the presence of Flash or SSD drives in a storage pool that also contains hard disk
drives (HDDs). Those drives can be either internal or external disk drives. However, unlike IBM
Storage implementations of Easy Tier, which move small pieces of data to and from faster storage
based on patterns of usage, the BRMS migration function operates at a file or library level to
automatically migrate frequently accessed database files in their entirety from HDDs to Flash or
SSDs, thus placing such files in a faster tier of storage, and vice versa. A system administrator can
also choose to move a file or a library to SSD, based on knowledge that the whole file or library will
be needed in the future. This aspect can be useful for month-end or quarter-end processing by
moving the necessary files, which only periodically have frequent access, into faster storage.

© Copyright IBM Corp. 1995, 2017 16-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0LJUDWLRQFRQWUROJURXS

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-25. Migration control group

The Work with Migration Control Groups display is shown when the Work with Control Groups
(WRKCTLGBRM) command TYPE(*MGR) OPTION(*) is processed. The Work with Migration Control
Groups display is used to create, edit, copy, delete or display migration control groups. Additionally,
you can add, change or delete entries for subsystems to end and job queues to hold, attributes
associated with each migration control group, as well as schedule when control groups are to run.
Migration control groups are lists of libraries or first-level folders that share common migration
characteristics. You can create multiple migration control groups to complete your migration
strategy.

© Copyright IBM Corp. 1995, 2017 16-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

0LJUDWLRQSURFHVV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-26. Migration process

The Start Migration using BRM (STRMGRBRM) command allows you to specify a migration control
group to process. You can start the migration immediately or you can schedule it using the system
job scheduler. Processing can be batch or interactive.
The default for the OPTION parameter is *REPORT, which produces the Migration Item Candidate
report. This allows you to process a report and review what will be migrated prior to performing the
migration operation. To perform a migration for the items in the Migration Item Candidate report
created by the *REPORT option or to restart a migration that was interrupted for some reason, you
can specify the special value *RESUME.

© Copyright IBM Corp. 1995, 2017 16-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506QHWZRUN RI

7&3 7&3
61$ % 61$
5'% 5'%

$ 6KDUHGPHGLD &

‡ $GYDQWDJHV 7&3
61$
ƒ 6KDUHGVFUDWFKSRRO 5'%
ƒ &URVVV\VWHPUHVWRUHVHVSHFLDOO\VSRROILOHV
ƒ $EOHWRVHHDOOPHGLDIURPRQHV\VWHP
ƒ $ELOLW\WRFUHDWHUHFRYHU\UHSRUWIRUV\VWHP%IURPV\VWHP$

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-27. BRMS network (1 of 2)

By placing multiple IBM i systems in a BRMS network, the systems can share BRMS policies,
media information and storage locations with other systems in the BRMS network. This allows
backups across all IBM i systems in the BRMS network to be managed in a consistent manner. It
also optimizes the media.
In the scenario in the visual, you could have either:
1. One system that is three logical partitions for system A, B, and C
Or
2. Three separate, standalone systems that are connected through a local area network (LAN)
Or
3. A combination of both #1 and #2
In order for networking to be active on these systems:
• Each of these systems must have BRMS installed, with the networking option installed.
• In this example, a tape library is shared by the systems in the visual.
• BRMS networking allows for the sharing of the same tape library and tape or media pool.

© Copyright IBM Corp. 1995, 2017 16-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
BRMS does not communicate with any tape drive or tape library. Communication is handled by the
OS. BRMS tells the OS what it needs, and then the OS communicates the request.
There are two parts to setting up this BRMS network: software and hardware.
1. Software is the BRMS networking that must be set up between these systems.
2. Hardware is the tape library setup.
• Each system needs an input/output adapter (virtual o physical) connected to a drive in the tape
library
• It is suggested that the TAPMLBxx has the same name on each system.
• Only one system is able to use the drive at a time. If there are more drives in the library, you can
do more operations at the same time.

Note

From a BRMS standpoint, it makes no difference if the systems are LPARs or separate (physical
standalone) systems. Think of each BRMS system as a separate system.

© Copyright IBM Corp. 1995, 2017 16-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506QHWZRUN RI
‡ &RQVLGHUDWLRQV
ƒ 1HWZRUNLQJDGGVFRPSOH[LW\WR\RXU%506VHWXS
ƒ <RXQHHGWRHQVXUHFRPPXQLFDWLRQVVWD\DFWLYH
ƒ <RXQHHGWRFRRUGLQDWHVFKHGXOHVIRU%506IXQFWLRQV
í %506GDLO\PDLQWHQDQFH
í 0HGLDPRYHPHQW
í 3RVVLEOHORFNFRQGLWLRQVLIPXOWLSOHV\VWHPVLQD%506QHWZRUNDUHSHUIRUPLQJ
WKHVHIXQFWLRQVVLPXOWDQHRXVO\
ƒ <RXQHHGWRLPSOHPHQWD37)VWUDWHJ\PDNHVXUHWRVWD\FXUUHQWXSWRGDWH
ƒ 7LPH]RQH 7KH%506DOORZXSWRKRXUVGLIIHUHQFHEHWZHHQV\VWHP
LQWKHQHWZRUN

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-28. BRMS network (2 of 2)

Some considerations to keep in mind if you are going to network your systems for BRMS purposes
are:
• Connecting your systems in a network environment adds complexity to the setup of BRMS.
More details are covered later in this unit.
• For networking to stay active, you need to ensure that communications remain active. More
details are covered later in this unit.
• In a network environment, you need to coordinate or schedule BRMS functions, such as daily
maintenance; otherwise, there is a possibility of a lock condition occurring.
• Another consideration is the need to implement a PTF strategy. It is highly recommended that
you maintain all of the systems in the network at the most recent and up-to-date PTF level as
possible. At a minimum, systems that are at the same version and release level should also be
maintained at the same PTF level. It is possible to have systems at different version and release
levels to be networked. There are PTFs that must be installed to support level of communication
between systems at different versions / release level.

© Copyright IBM Corp. 1995, 2017 16-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVH
‡ ,IP\EDFNXSLVGRQH"
ƒ +RZGR,FKHFNDODUJHQXPEHURIVHUYHUV/3$5V"
ƒ &DQ,VRPHKRZUHFHLYHLQIRUPDWLRQZKDWLVJRLQJRQ"
‡ &DQ,UXQEDFNXSRQPDQ\VHUYHUVIURPRQHSODFH"
‡ &DQ,FKHFNORJVZLWKRXWQHHGLQJWRORJRQWRHDFKSDUWLWLRQ"

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-29. BRMS Enterprise

There is some question when you work with big or complex BRMS environment.

© Copyright IBM Corp. 1995, 2017 16-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVHRYHUYLHZ
7KH%506(QWHUSULVHVROXWLRQSURYLGHVFDSDELOLW\WR

‡ 0RQLWRUWKHEDFNXSRQ%506V\VWHPVIURPRQHSODFH

‡ 0RQLWRUVWDQGDORQHDQGQHWZRUNLQVWDOODWLRQV

‡ 0RQLWRUQRGHDFWLYLW\LQVHYHUDOZD\V

‡ 1RLPSDFWIRUWUDGLWLRQDO%506QHWZRUNV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-30. BRMS Enterprise overview

BRMS Enterprise allows administrators to monitor backup operations for their BRMS systems from
a central site that is called an Enterprise Hub. The systems that are monitored by the Hub are
called Enterprise Nodes. The Enterprise Network is composed of Nodes that can be standalone
BRMS systems, part of a BRMS Network or any combination of standalone and BRMS Networked
systems. Configuration and management of the Nodes are handled through the Hub and do not
impact the existing operations of traditional BRMS Networks.
The Hub can monitor Node backup activity in several ways with either the Start recovery BRMS
command (STRRCYBRM) or the Start maintenance BRMS command (STRMNTBRM) or by using the
Display log BRMS (DSPLOGBRM) reports.
These can be:
• Run manually or scheduled
• Stored on the Hub
• Optionally stored on the Node
• Email notifications for report errors
• Email reports
• Status for backup control group runs
• Display and filter the BRMS log
• Connectivity status

© Copyright IBM Corp. 1995, 2017 16-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVHWZRPRGHOV
0XOWLSOH%506QHWZRUNV 2QH%,*%506QHWZRUN
25
&HQWUDO &HQWUDO
³(QWHUSULVH6\VWHP´ ³(QWHUSULVH6\VWHP´

%5061HWZRUN &ROOHFWV &ROOHFWV


%506
0HGLD
'DWDEDV
H ,%0L
$

%,*%5061HWZRUN
%506 %506
0HGLD 0HGLD
'DWDED 'DWDEDV
,%0L VH H ,%0L

%5061HWZRUN
% &
&ROOHFWV
%506
0HGLD
'DWDEDV
,%0L
H
$
%506 %506
0HGLD 0HGLD
'DWDEDV 'DWDEDV
,%0L H H ,%0L
%
%5061HWZRUN &

&ROOHFWV
%506
0HGLD
'DWDEDV
,%0L
H
$
%506 %506
0HGLD 0HGLD
'DWDEDV 'DWDEDV
,%0L H H ,%0L
% &

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-31. BRMS Enterprise two models

There are two available networks models.


1. Multiple BRMS Networks: Which consist of a few BRMS Networks. In this example it shows
three BRMS networks.
2. One Big Network: Which consists all systems in one big network.

© Copyright IBM Corp. 1995, 2017 16-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVHIXQFWLRQ
‡ 1RJUHHQVFUHHQ,%01DYLJDWRUIRU,

&HQWUDO
³(QWHUSULVH6\VWHP´

ƒ (DVLHUWRXVH
ƒ (DVLHUIRU%506WRLPSOHPHQW

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-32. BRMS Enterprise function

© Copyright IBM Corp. 1995, 2017 16-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVHWHUPLQRORJ\ RI 
‡ +8% DOVRNQRZQDV«&HQWUDOL]HG(QWHUSULVH6\VWHP
ƒ $FHQWUDOVLWHWKDWPRQLWRUV%506EDFNXSVIRU(QWHUSULVH1RGHV
ƒ 7KH1RGHVEHLQJPRQLWRUHGE\WKH+XEDUHFDOOHGDQ(QWHUSULVH1HWZRUN
í (QWHUSULVH1HWZRUNPD\LQFOXGH%506VWDQGDORQHDQG%5061HWZRUNHG
V\VWHPV
í &RPPXQLFDWLRQLVFRQILJXUHGWKURXJKHDFKRIWKH1RGHVLQWKH(QWHUSULVH1HWZRUN
DQGLVFRPSOHWHO\LQGHSHQGHQWRIWUDGLWLRQDO%5061HWZRUNFRQILJXUDWLRQ
‡ 1RGHV
ƒ (QWHUSULVH1RGHVDUH%506V\VWHPVWKDWDUHEHLQJPRQLWRUHGE\DQ
(QWHUSULVH+XE
ƒ (QWHUSULVH1RGHSURSHUWLHVDUHGHILQHGE\DQGPDLQWDLQHGRQWKH+XE
ƒ 1R(QWHUSULVHFRQILJXUDWLRQLVFXUUHQWO\UHTXLUHGRQWKH1RGHV
í 1RGH3ROLF\
(DFK1RGHKDVDQDVVRFLDWHG1RGH3ROLF\
1RGH3ROLF\GHILQHVSURSHUWLHVWKDWFDQEHVKDUHGEHWZHHQPXOWLSOH1RGHV
(DFK1RGHFDQUHIHUHQFHWKH1RGH3ROLF\IRUDQ\RILWVSURSHUWLHV
í 1RGH*URXS
1RGH*URXSVDOORZDQDGPLQLVWUDWRUWRDVVLJQDQDPHWRDJURXSRI1RGHV
7KH1RGH*URXSVFDQEHEDVHGRQDWWULEXWHVWKH1RGHVKDYHLQFRPPRQIRU
H[DPSOH RZQHUORFDWLRQWLPH]RQHDQGVRIRUWK

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-33. BRMS Enterprise terminology (1 of 2)

HUB (also known as - Centralized Enterprise System)


• The Enterprise Hub is a central site that monitors BRMS backups for other BRMS systems
called Enterprise Nodes. The Nodes that are monitored by the Hub are called an Enterprise
Network.
• The Enterprise Network can include BRMS standalone and BRMS Networked systems.
Communication is configured through each of the Nodes in the Enterprise Network and is
completely independent of traditional BRMS Network configuration.
Nodes
• Enterprise Nodes are BRMS systems that are monitored by an Enterprise Hub. Enterprise
Node properties are defined by and maintained on the Hub.
• No Enterprise configuration is currently required on the Nodes!
▪ Node Policy
Each Node has an associated Node Policy. The Node Policy defines properties that can be
shared between multiple Nodes. Each Node can reference the Node Policy for any of its
properties.

© Copyright IBM Corp. 1995, 2017 16-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
▪ Node Group
Node Groups allow an administrator to assign a name to a group of Nodes. The Node
Groups can be based on attributes the Nodes have in common, for example - owner,
location, time zone.

© Copyright IBM Corp. 1995, 2017 16-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506(QWHUSULVHWHUPLQRORJ\ RI 
‡ &RQWDFWV
ƒ $UHXVHUVDVVRFLDWHGZLWKWKH+XEDQG1RGHV
ƒ $UHXVHGIRUDYDULHW\RIQRWLILFDWLRQV
‡ 5HSRUW'HILQLWLRQ
ƒ 'HILQHKRZDQGZKHQDUHSRUWLVJHQHUDWHGIRUD1RGH
ƒ &DQEHUXQPDQXDOO\RULWFDQEHVFKHGXOHGWRUXQDWGHILQHGLQWHUYDOV
ƒ 2XWSXWLVVWRUHGLQDXVHUGHVLJQDWHGRXWSXWTXHXHRQWKH+XEDQGHPDLOHG
WRWKH&RQWDFWVIRUWKH1RGH
í 5HSRUW3ROLF\
(DFK5HSRUW'HILQLWLRQKDVDQDVVRFLDWHG5HSRUW3ROLF\
5HSRUW3ROLF\GHILQHVSURSHUWLHVWKDWFDQEHVKDUHGEHWZHHQPXOWLSOH5HSRUW
'HILQLWLRQV
(DFK5HSRUW'HILQLWLRQFDQUHIHUHQFHWKH5HSRUW3ROLF\IRUDQ\RILWVSURSHUWLHV
í 5HSRUW
:KHQD5HSRUW'HILQLWLRQLVUXQIRUD1RGHD5HSRUWLVJHQHUDWHG
(DFKUHSRUWLGHQWLILHVZKHQWKH5HSRUW'HILQLWLRQZDVUXQZKDW5HSRUW2XWSXWZDV
SURGXFHGDQGZKHUHWKH5HSRUW2XWSXWZDVVWRUHG
í 5HSRUW2XWSXW
,VSURGXFHGZKHQD5HSRUWLVUXQIRUD5HSRUW'HILQLWLRQ
&DQEHIRXQGWKURXJKWKH5HSRUWWKDWLGHQWLILHVZKHQWKH5HSRUW'HILQLWLRQZDVUXQ
0D\LQFOXGHPXOWLSOHILOHV
,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-34. BRMS Enterprise terminology (2 of 2)

Contact
Contacts are users that are associated with the Hub and Nodes. The Contacts are used for
various notifications, including reports or errors that are encountered while generating reports.
Report Definition
Report Definitions define how and when a report is generated for a Node.
The Report Definition can be run manually or it can be scheduled to run at defined intervals.
The output that is created by running a Report Definition is stored in a user designated output
queue on the Hub. The output can also be stored in a user designated output queue on the
Node and / or emailed to the Contacts for the Node.
Report Policy
Each Report Definition has an associated Report Policy. The Report Policy defines
properties that can be shared between multiple Report Definitions. Each Report
Definition can reference the Report Policy for any of its properties.

© Copyright IBM Corp. 1995, 2017 16-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
Report
When a Report Definition is run for a Node, a Report is generated. Each Report
identifies when the Report Definition was run, what Report Output was produced and
where the Report Output was stored.
Report Output
Report Output is produced when a Report is run for a Report Definition. The Report
Output can be found through the Report that identifies when the Report Definition was
run. Report Output can include multiple files.

© Copyright IBM Corp. 1995, 2017 16-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

+RZGR,DFFHVVWKH%506(QWHUSULVHIXQFWLRQ"

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-35. How do I access the BRMS Enterprise function?

To start working with the Enterprise function when using IBM Navigator for i:
1. On left pane click Backup Recovery and Media Services.
2. Click Advanced button.
3. Click the double arrow next to Enterprise Services and from pop-up menu select Open.

© Copyright IBM Corp. 1995, 2017 16-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

&ORXG6WRUDJH6ROXWLRQVXVDJHFRQFHSWV

2EMHFWVKDULQJDPRQJPXOWLSOH
V\VWHPV
 37)V
 ,62V /RFDO+DUGZDUHRU&ORXG3URYLGHU
 )LOHV (QDEOHVPRYLQJWRSK\VLFDOWDSHLQWKHFORXG
 RWKHUV (QDEOHVUHFRYHU\WHVWLQJRIIVLWH

%DFNXS$UFKLYH
 %506PDQDJHVGDWDEDFNXSRSHUDWLRQVDXWRPDWLFDOO\

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-36. Cloud Storage Solutions usage concepts

Cloud solution allows share data between multiple systems. Backup/Archive data to the cloud.

© Copyright IBM Corp. 1995, 2017 16-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%0&ORXG6WRUDJH6ROXWLRQV
‡ 5HTXLUHPHQWV
ƒ ,&& %$6(,%0&ORXG6WRUDJH6ROXWLRQVIRUL
ƒ ,&&&ORXG6WRUDJH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-37. IBM Cloud Storage Solutions

BRMS can be used to transfer virtual save media, from tape or optical image catalogs, to/from the
cloud using product IBM Cloud Storage Solutions for i (5733ICC). Cloud Storage Solutions for i
allow cloud connector resources to be defined for cloud storage providers such as
IBM SoftLayer and for private interfaces such as file transfer protocol (FTP). BRMS will create
BRMS storage locations for each cloud resource defined on a system. When virtual media is
moved to a cloud storage location, the media will be transferred to the cloud using the cloud
resource. Likewise, when that media is moved from a cloud location the media will be transferred
back to the i system. Media will also be automatically transferred back to the system during a
restore when no local save media is available to the restore.

© Copyright IBM Corp. 1995, 2017 16-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%0&ORXG6WRUDJH6ROXWLRQVIRUL RI

7&3,3 &ORXG6WRUDJH
Virtual
Tape

%DFNXS\RXUV\VWHPWR&ORXGVWRUDJH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-38. IBM Cloud Storage Solutions for i (1 of 3)

You can store your data to the cloud.

© Copyright IBM Corp. 1995, 2017 16-47


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%0&ORXG6WRUDJH6ROXWLRQVIRUL RI

)736HUYHU
Virtual
Tape

%DFNXS\RXUV\VWHPWR)736WRUDJH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-39. IBM Cloud Storage Solutions for i (2 of 3)

Another place when you can store data is FTP server.

© Copyright IBM Corp. 1995, 2017 16-48


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

&ORXG6WRUDJH6ROXWLRQVIRUL RI

7&3,3 6RIW/D\HU$PD]RQ$]XUH
Virtual
Tape

‡ &ORXG6WRUDJH6ROXWLRQVIRULLVDQ$3,WKDWHQDEOHVGHSOR\PHQWRI,%0L
GDWDWRDSXEOLFFORXG
ƒ ,QLWLDOO\WDUJHWHGIRUFXVWRPHUVZLWKXQGHU7E\WHRIGDWD
ƒ ,QLWLDOSXEOLFFORXGSURYLGHU6RIW/D\HU
‡ ,QLWLDOSURGXFWRIIHULQJZLOOIHDWXUH
ƒ 7XUQNH\%506VHWXSDQGUXQZLWKYLUWXDOWDSHPDQDJHPHQW
ƒ 6HFXULW\XVLQJ931
‡ $XWRVDYHDQGV\QFKURQL]HILOHVLQWKH,%0L,)6GLUHFWRU\
ƒ 5ROO\RXURZQEDFNXSUHFRYHU\ EDQGZLGWKFRQVLGHUDWLRQV 

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-40. Cloud Storage Solutions for i (3 of 3)

Cloud Storage Solutions for i is an API that enables deployment of IBM i data to a public cloud:
• Initially targeted for customers with under 1 Tbyte of data
• Initial public cloud provider: SoftLayer
Initial product offering will feature:
• Turn-key BRMS setup and run with virtual tape management
• Security using VPN
Auto save and synchronize files in the IBM i IFS directory:
• Roll your own backup/recovery (bandwidth considerations)

© Copyright IBM Corp. 1995, 2017 16-49


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

&ORXGVWRUDJH&DFKHGEDFNXS,%0LHQYLURQPHQW

SXEOLFRUSULYDWHFORXG
7&3,3
Virtual
Tape

‡ )RXQGDWLRQDOWRSRORJ\LVHQDEOHGXVLQJ9LUWXDO7DSH
ƒ 3K\VLFDOVWRUDJHFDFKHYLDDGLVNSRRO
ƒ 'DWDLVVDYHGIURPLDVWDSHREMHFWVLQWRWKHVWRUDJHFDFKH
‡ 7DSHREMHFWVLQWKHVWRUDJHFDFKHFRQYHUWHGWRFORXGREMHFWV
FRQWDLQHUVUHFRJQL]HGE\FORXGSURYLGHU
ƒ &ORXGSURYLGHUKDVDQREMHFWIRUPDW 6:,)7 LQLWLDOO\WKDWHQDEOHVVDYHVWR
JHQHULFGLVNRIDQ\NLQG
ƒ 7RGHSOR\WRWKHFORXG&ORXG6WRUDJH6ROXWLRQVJURXSVWKHWDSHREMHFWVLQWR
FORXGREMHFWV
‡ &ORXGREMHFWVZLOOEHWUDQVPLWWHGDV\QFKURQRXVO\WRDFORXGSURYLGHU
ƒ ,%0LZLOOOHYHUDJH%506WRPDQDJHVDYHSURFHVVIURPYLUWXDOWDSHWRSXEOLF
FORXG
,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-41. Cloud storage: Cached backup IBM i environment

Foundational topology is enabled using Virtual Tape.


• Physical storage cache using a disk pool
• Data is saved from i as tape objects into the storage cache
Tape objects in the storage cache, converted to cloud objects (containers recognized by cloud
provider).
• Cloud provider has an object format (SWIFT) initially that enables saves to generic disk of any
kind
• To deploy to the cloud, Cloud Storage Solutions groups the tape objects into cloud objects
Cloud objects will be transmitted asynchronously to a cloud provider.
• IBM i will leverage BRMS to manage save process from virtual tape to public cloud

© Copyright IBM Corp. 1995, 2017 16-50


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%0L&ORXG6WRUDJH6ROXWLRQVIRUL RI 

7&3,3 6RIW/D\HU$:63ULYDWH
&ORXG

‡ 6WUDWHJLFIHDWXUHV
ƒ 8WLOL]H6WDQGDUG&ORXG2EMHFW6WRUDJH
ƒ 6XSSRUWIRU,)6)LOH0LUURU6KDULQJ
ƒ 9LUWXDOWDSHZLWK%506IRUEDFNXSUHFRYHU\
ƒ *8,PDQDJHPHQW
ƒ 6HFXUHFRQQHFWLRQZLWKFRPSUHVVLRQ
ƒ $3,IRU+\EULG&ORXGFDSDELOLW\
ƒ (QDEOHPHQWIRUGHGLFDWHGFORXG063V
ƒ ([SORLWDWLRQRI,%0VWRUDJHDQGVROXWLRQVVXFKDV6SHFWUXPH[SDQGLQJWKH
PDUNHWWRPHGLXPDQGODUJHHQWHUSULVHV

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-42. IBM i Cloud Storage Solutions for i (1 of 2)

Strategic features:
• Utilize Standard Cloud Object Storage
• Support for IFS File Mirror/Sharing
• Virtual tape with BRMS for backup recovery
• GUI management
• Secure connection with compression
• API for Hybrid Cloud capability
• Enablement for dedicated cloud MSPs
• Exploitation of IBM storage and solutions such as Spectrum expanding the market to medium
and large enterprises

© Copyright IBM Corp. 1995, 2017 16-51


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%0L&ORXG6WRUDJH6ROXWLRQVIRUL RI 

7&3,3 6RIW/D\HU$:63ULYDWH
&ORXG

‡ 9DOXHSURSRVLWLRQ
ƒ 'RLW\RXUVHOIEDFNXSDUFKLYHRSHUDWLRQVWRDSXEOLFFORXG
ƒ *HWVGDWDRIIVLWHDXWRPDWLFDOO\
ƒ (OLPLQDWHVWKHQHHGIRUDIXOOVHUYLFHWKLUGSDUW\
ƒ (QDEOHVHDV\WRXVHUHFRYHU\RSHUDWLRQV
ƒ (QDEOHVILOHVKDULQJ
ƒ $GYDQFHGEDFNXSUHFRYHU\VHUYLFHVWRGHGLFDWHG063V
ƒ :LOOHOLPLQDWHWKHQHHGIRUDORFDOWDSHGHYLFH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-43. IBM i Cloud Storage Solutions for i (2 of 2)

Value proposition:
• Do it yourself backup/archive operations to a public cloud
• Gets data off site automatically
• Eliminates the need for a full service third party
• Enables easy to use recovery operations
• Enables file sharing
• Advanced backup recovery services to dedicated MSPs
• Will eliminate the need for a local tape device

© Copyright IBM Corp. 1995, 2017 16-52


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
16.2. Topic 2: Overview of IBM Navigator for i
and BRMS

© Copyright IBM Corp. 1995, 2017 16-53


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

7RSLF2YHUYLHZRI
,%01DYLJDWRUIRULDQG%506

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-44. Topic 2: Overview of IBM Navigator for i and BRMS

© Copyright IBM Corp. 1995, 2017 16-54


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

,%01DYLJDWRUIRUL

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-45. IBM Navigator for i

When you connect to system with installed BRMS the BRMS plug-in will available BRMS function
to run under IBM Navigator for i. You do not need to install anything else.
1. Login to the IBM i using web browser using [Link] address or system
name>:2001.
2. On the left pane click Backup Recovery and Media Services.
3. On the main pane click Advanced button.
4. On the main pane you will be see all available group tasks to work with.
5. Click double arrow next to selected group and from pop-up menu you can choose task.
Note some functions of BRMS can only be accessed by GUI. For example, Enterprise services can
only be manage by IBM Navigator for i.

© Copyright IBM Corp. 1995, 2017 16-55


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty
16.3. Topic 3: Reference material

© Copyright IBM Corp. 1995, 2017 16-56


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

7RSLF5HIHUHQFHPDWHULDO

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-46. Topic 3: Reference material

© Copyright IBM Corp. 1995, 2017 16-57


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506ZLNLVGHYHORSHU:RUNVSDJH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-47. BRMS wikis: developerWorks page

The IBM developerWorks Wikis page is a good resource for BRMS information you can find here
many actual materials and comments.
[Link]
Recovery%20and%20Media%20Services%20%28BRMS%29%20for%20i

© Copyright IBM Corp. 1995, 2017 16-58


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

%506.QRZOHGJH&HQWHU

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-48. BRMS Knowledge Center

IBM Knowledge Center is also very good place to looking for BRMS information.
[Link]

© Copyright IBM Corp. 1995, 2017 16-59


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

3XEOLFDWLRQV
‡ 5HIHUWRWKLVSXEOLFDWLRQIRUPRUHLQIRUPDWLRQ
ƒ Backup Recovery Media Services
í ,%0L6&

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-49. Publications

© Copyright IBM Corp. 1995, 2017 16-60


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

:KHUHFDQ,JHWHGXFDWLRQ"
‡ (GXFDWLRQ
ƒ $6* BRMS for IBM i, including Cloud Storage Solutions for i

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-50. Where can I get education?

[Link]
rseCode=AS28G

© Copyright IBM Corp. 1995, 2017 16-61


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH,I\RXRQO\QHHGWRVDYHDQGUHVWRUH\RXUGDWD
\RXRQO\QHHGWRLQVWDOOWKH %DVH%506VRIWZDUH

 7UXHRUIDOVH,QRUGHUWRGRVRIWZDUHHQFU\SWLRQDVSDUWRI
\RXUVDYH\RXZRXOGQHHGWRLQVWDOO%5062SWLRQ
1HWZRUNLQJVRIWZDUH

 7UXHRUIDOVH%506UHTXLUHVWKDWDOORIWKHYROXPHVWKDWLWLV
JRLQJWRPDQDJHPXVWKDYHDXQLTXHYROXPH,'

 7UXHRUIDOVH%506ZLOOZRUNV\VWHPVWKDWDUHSDUWRIDQ
6$1

 7UXHRUIDOVH%506SURYLGHVVXSSRUWWRGREDFNXSDQG
UHFRYHU\DVZHOODVDUFKLYHDQGUHWULHYDO

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-51. Review questions

© Copyright IBM Corp. 1995, 2017 16-62


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH,I\RXRQO\QHHGWRVDYHDQGUHVWRUH\RXUGDWD\RXRQO\
QHHGWRLQVWDOOWKH %DVH%506VRIWZDUH
7KHDQVZHULVWUXH

 7UXHRUIDOVH,QRUGHUWRGRVRIWZDUHHQFU\SWLRQDVSDUWRI\RXUVDYH
\RXZRXOGQHHGWRLQVWDOO%5062SWLRQ1HWZRUNLQJVRIWZDUH
7KHDQVZHULVIDOVH

 7UXH RUIDOVH%506UHTXLUHVWKDWDOORIWKHYROXPHVWKDWLWLVJRLQJWR
PDQDJHPXVWKDYHDXQLTXHYROXPH,'
7KHDQVZHULVWUXH

 7UXH RUIDOVH%506ZLOOZRUNV\VWHPVWKDWDUHSDUWRIDQ6$1
7KHDQVZHULVWUXH

 7UXH RUIDOVH%506SURYLGHVVXSSRUWWRGREDFNXSDQGUHFRYHU\DV
ZHOODVDUFKLYHDQGUHWULHYDO
7KHDQVZHULVWUXH

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-52. Review answers

© Copyright IBM Corp. 1995, 2017 16-63


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 16. Introduction to Backup Recovery and Media Services

Uempty

8QLWVXPPDU\
‡ 'HVFULEHWKHIHDWXUHVDQGIXQFWLRQVSURYLGHGE\%506
‡ /LVWWKHGLIIHUHQWVRIWZDUHWKDWPDNHVXSWKH%506SURGXFW
‡ 'LVFXVVWKHEHQHILWVRIXVLQJ%506IXQFWLRQV
‡ 'LVFXVVWKHEHQHILWVRIXVLQJWKH%506&ORXG6ROXWLRQV
‡ 'LVFXVVWKHEHQHILWVRIXVLQJ%5061HWZRUNDQG(QWHUSULVHVHUYLFHV
‡ 'HVFULEHWKHIXQFWLRQVVXSSRUWHGIRU%506E\,%01DYLJDWRUIRUL

,QWURGXFWLRQWR%DFNXS5HFRYHU\DQG0HGLD6HUYLFHV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 16-53. Unit summary

© Copyright IBM Corp. 1995, 2017 16-64


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

Unit 17. Power HA/DR solutions


Estimated time
00:45

Overview
This unit provides an overview of the current availability of PowerHA/DR (high availability disaster
recovery) solutions. It is not intended to teach students how to set up any of these solutions, but
administrators should know what is currently available in order to choose the best solutions for their
organizations.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 17-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHWKHIHDWXUHVDQGIXQFWLRQVSURYLGHGE\%506
‡ /LVWDYDLODEOHKLJKDYDLODELOLW\+$DQG'5VROXWLRQV
‡ 'LVFXVVFRPSOH[VROXWLRQVWRDFKLHYHUHTXLUHG+$'5OHYHO

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 17-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty
17.1. Topic 1: PowerHA overview

© Copyright IBM Corp. 1995, 2017 17-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

7RSLF3RZHU+$RYHUYLHZ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-2. Topic 1: PowerHA overview

© Copyright IBM Corp. 1995, 2017 17-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

3RZHU+$6\VWHP0LUURU
‡ &RPSOHWH,%03RZHU6\VWHPVLQWHJUDWHGHQGWRHQGVROXWLRQVIRU+$'5
ƒ )RFXV[$SSOLFDWLRQDYDLODELOLW\WKURXJKSODQQHGRUXQSODQQHGRXWDJHHYHQWV
ƒ 'HHSO\LQWHJUDWHGH[WHQVLRQRI,%0L LPSOHPHQWHGLQ/,&DQGWKH26

‡ &OXVWHULQJWHFKQRORJ\
ƒ 3URYLGHVWKHDSSOLFDWLRQVZLWKDFRPSOHWHUHVLOLHQF\LQIUDVWUXFWXUH
ƒ 0RQLWRUVDQGPDQDJHVSULPDU\DQGVHFRQGDU\UHVRXUFHVIRU+$DQG'5RSHUDWLRQV

‡ 6WRUDJHEDVHGGDWDUHVLOLHQF\
ƒ 'DWDUHVLOLHQF\LVDQH[WHQVLRQRIWKHKRVWV\VWHPVWRUDJHPDQDJHPHQWDUFKLWHFWXUH
ƒ 6WRUDJHYROXPHVDUHHLWKHUVZLWFKDEOHRUPLUURUHGEHWZHHQQRGHVLQWKHFOXVWHU
ƒ +DUGZDUHEDVHGUHSOLFDWLRQVHUYLFHVIRU0XOWL6LWH2SHUDWLRQV
í +RVW%DVHG5HSOLFDWLRQ *HRJUDSKLFPLUURULQJIRU,%0L 
í 6WRUDJH%DVH5HSOLFDWLRQ 0HWUR0LUURURU*OREDO0LUURU

‡ 2YHUDOOVROXWLRQFKDUDFWHULVWLF
ƒ $XWRPDWLRQPLQLPDO,7RSHUDWLRQVLQYROYHPHQW
ƒ 'DWDEHWZHHQSULPDU\DQGVHFRQGDU\QRGHVDOZD\VLQV\QFDOZD\VUHDG\IRUD
IDLORYHUHYHQW
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-3. PowerHA SystemMirror

• Complete IBM Power Systems integrated end to end solutions for HA DR


▪ Focus: 24 x 7 Application availability through planned or unplanned outage events
▪ Deeply integrated extension of IBM i (implemented in LIC and the OS)
• Clustering technology
▪ Provides the applications with a complete resiliency infrastructure
▪ Monitors and manages primary and secondary resources for HA and DR operations
• Storage based data resiliency
▪ Data resiliency is an extension of the host system storage management architecture
▪ Storage volumes are either switchable or mirrored between nodes in the cluster
▪ Hardware based replication services for Multi-Site Operations
- Host Based Replication (Geographic mirroring for IBM i)
- Storage Base Replication (Metro Mirror or Global Mirror)
• Overall solution characteristic
▪ Automation, minimal IT operations involvement
▪ Data between primary and secondary nodes always in sync always ready for a failover
event

© Copyright IBM Corp. 1995, 2017 17-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/DEVHUYLFHV
‡ /DEVHUYLFHV3RZHU6\VWHPV
‡ PowerHA Tools for IBM i
ƒ 6PDUW$VVLVWIRU3RZHU+$RQ,%0L
í )RUPHUO\3RZHU+$7RROV
ƒ ,$63&RS\6HUYLFHV0DQDJHU ,&60
í )RUPHUO\$GYDQFHG&RS\6HUYLFHV $&6 7RRONLW
ƒ )XOO6\VWHP&RS\6HUYLFHV0DQDJHU )6&60
í )RUPHUO\)XOO6\VWHP)ODVK&RS\
ƒ )XOO6\VWHP5HSOLFDWLRQ0DQDJHU )650
í )RUPHUO\7RRONLW

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-4. Lab services

These are the available products that are offered by IBM Lab Services, which can add more
automations and functionality to offered PowerHA solution.

© Copyright IBM Corp. 1995, 2017 17-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty
17.2. Topic 2: PowerHA solutions

© Copyright IBM Corp. 1995, 2017 17-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

7RSLF3RZHU+$VROXWLRQV

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-5. Topic 2: PowerHA solutions

© Copyright IBM Corp. 1995, 2017 17-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

*HRJUDSKLF0LUURULQJ RI
‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ 2QH,$63WZRFRSLHV WZRVHWVRIGLVNV/81V
‡ 7\SLFDOO\IRULQWHUQDOVWRUDJH
‡ 5HSOLFDWLRQKDQGOHGDW,%0L6/,&VWRUDJHPDQDJHPHQWOHYHO

352' %&.3

,QWHUQDO ,QWHUQDO
'LVNV *HR0LUURU 'LVNV

3URGXFWLRQ 0LUURU&RS\
&RS\,$63 ,$63
,%0L ,%0L

&DQEHH[WHUQDOVWRUDJHEXWQRWDVFRPPRQ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-6. Geographic Mirroring (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

*HRJUDSKLF0LUURULQJ RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ 5HSOLFDWLRQKDQGOHGDW6/,&6WRUDJH0DQDJHPHQWOHYHODVRSSRVHGWR26
DQGUHPRWHMRXUQDOLQJ IRUH[DPSOHORJLFDOUHSOLFDWLRQVROXWLRQV
ƒ 0DQDJHGE\XVLQJ3RZHU+$
ƒ 7UXHDV\QFKURQRXVWUDQVPLVVLRQRSWLRQDW,%0L
‡ /LPLWDWLRQV
ƒ 5HTXLUHVVXIILFLHQWEDQGZLGWKEHWZHHQVLWHVWRPDLQWDLQFRQVLVWHQWFRSLHV
DQGDYRLGDXWRVXVSHQGLVVXHV
ƒ 5HFRPPHQGHGWRKDYHHTXDOTXDQWLW\FDSDFLW\DQGW\SHRIGLVNVDWERWK
VLWHVWRPDLQWDLQFRQVLVWHQF\
ƒ 5HSOLFDWLRQSRUWVXVHUDQGRPHSKHPHUDO  7&3SRUWVQRWVSHFLILF
SRUWV

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-7. Geographic Mirroring (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/81OHYHOVZLWFKLQJ RI
‡ 7ZRRUPRUH,%0LSDUWLWLRQV VDPHRUGLIIHUHQWSK\VLFDO&(&
‡ 2QHVHWRIGLVNV/81VGHILQLQJWKHVWRUDJHSRRO
‡ )XQFWLRQLVDIHDWXUHRIH[WHUQDOVWRUDJHVXEV\VWHPV

352' %&.3

3URGXFWLRQ
,%0L ,$63

6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-8. LUN-level switching (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/81OHYHOVZLWFKLQJ RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ VROXWLRQ
í &DQQRWPRYHUHVRXUFHVLISURGXFWLRQLQD³IDLOHG´VWDWH IRUH[DPSOH06'
ƒ $XWRPDWHGIDLORYHUWKURXJK3RZHU+$DWY
ƒ 0DQDJHGE\XVLQJ3RZHU+$ '6.69&6WRUZL]H RU,&60 '6RQO\
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG
‡ /LPLWDWLRQV
ƒ 6LQJOHFRS\RIGDWD
ƒ 'HSHQGLQJRQ5$,'SDULW\XVHGHQRXJKGLVNHUURUVFDQFDXVHORVVRIHQWLUH
,$63
ƒ 1RWD'LVDVWHU5HFRYHU\ '5 6ROXWLRQ
ƒ /LPLWHGWR'669&999

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-9. LUN-level switching (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\6LQJOH,$63PXOWLSOHWLPHVWRVLQJOHWDUJHW
RI
‡ 7ZR,%0LSDUWLWLRQV
‡ 2QH³VRXUFH´DQGPXOWLSOH³WDUJHW´VHWVRIGLVNV/81V
‡ (DFK³WDUJHW´FDQEHFRQQHFWHGWRWKH)ODVK&RS\SDUWLWLRQEXWRQO\RQH
VHWRIGLVNVDWDWLPH

352'

352')&
3URGXFWLRQ
,$63
,%0L
)ODVK&RS\
&RS\

)ODVK&RS\
&RS\
6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-10. FlashCopy: Single IASP multiple times to single target (1 of 4)

© Copyright IBM Corp. 1995, 2017 17-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\6LQJOH,$63PXOWLSOHWLPHVWRVLQJOHWDUJHW
RI
‡ %HQHILWV
ƒ 3URYLGHVVHYHUDOSRLQWLQWLPH³FRSLHV´RISURGXFWLRQGDWD
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQEDFNXSV
í 0XOWLSOHEDFNXSVFDQEHVWDJJHUHGEDFNWREDFN
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG
ƒ &DQEHPDQDJHGWKURXJK3RZHU+$RU,&60
‡ /LPLWDWLRQV
ƒ 1RWD+LJK$YDLODELOLW\ +$ 25'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ 6LQJOHWDUJHWSDUWLWLRQFDQRQO\XVHRQHVHWRI)&WDUJHW/81VDWDWLPH
ƒ 0XOWLSOH)ODVK&RSLHVUHTXLUHVPRUH/81VWKDQVLQJOH)ODVK&RS\
ƒ )XOO&RS\DQG,QFUHPHQWDO&RS\UHTXLUHIXOO\SURYLVLRQHG³WDUJHW´/81V
ƒ :LWKVSDFHHIILFLHQW WKLQSURYLVLRQHG /81VWKHUHLVQRIXOOFRS\RQGLVN
HOVHZKHUH
í :RXOGUHTXLUHDUHVWRUHIURPPHGLD
í 6RPHSHUIRUPDQFHSHQDOWLHVPLJKWDSSO\DVPRVWUHDGVIURPVRXUFH/81V

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-11. FlashCopy: Single IASP multiple times to single target (2 of 4)

© Copyright IBM Corp. 1995, 2017 17-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\6LQJOH,$63PXOWLSOHWLPHVWRPXOWLSOHWDUJHWV
RI
‡ 0XOWLSOH,%0LSDUWLWLRQV
‡ 2QH³VRXUFH´DQGPXOWLSOH³WDUJHW´VHWVRIGLVNV/81V
‡ (DFK³WDUJHW´FDQEHFRQQHFWHGWRVHSDUDWH)ODVK&RS\SDUWLWLRQV
VHSDUDWHO\DQGLQGHSHQGHQWIURPRQHDQRWKHU

352'

352')&

352')&
3URGXFWLRQ
,$63
,%0L
)ODVK&RS\
&RS\

)ODVK&RS\
&RS\
6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-12. FlashCopy: Single IASP multiple times to multiple targets (3 of 4)

© Copyright IBM Corp. 1995, 2017 17-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\6LQJOH,$63PXOWLSOHWLPHVWRPXOWLSOHWDUJHWV
RI
‡ %HQHILWV
ƒ 3URYLGHVVHYHUDOSRLQWLQWLPH³FRSLHV´RISURGXFWLRQGDWD
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQEDFNXSV
í 0XOWLSOHEDFNXSVFDQEHVWDJJHUHGEDFNWREDFN
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG
ƒ &DQEHPDQDJHGWKURXJK3RZHU+$RU,&60
ƒ (DFKWDUJHWSDUWLWLRQFDQEHEURXJKWXSLQGHSHQGHQWO\
‡ /LPLWDWLRQV
ƒ 1RWD+LJK$YDLODELOLW\ +$ 25'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ 6LQJOHWDUJHWSDUWLWLRQFDQRQO\XVHRQHVHWRI)&WDUJHW/81VDWDWLPH
ƒ 0XOWLSOH)ODVK&RSLHVUHTXLUHVPRUH/81VWKDQVLQJOH)ODVK&RS\
ƒ )XOO&RS\DQG,QFUHPHQWDO&RS\UHTXLUHIXOO\SURYLVLRQHG³WDUJHW´/81V
ƒ :LWKVSDFHHIILFLHQW WKLQSURYLVLRQHG /81VWKHUHLVQRIXOOFRS\RQGLVN
HOVHZKHUH
í :RXOGUHTXLUHDUHVWRUHIURPPHGLD
í 6RPHSHUIRUPDQFHSHQDOWLHVPLJKWDSSO\DVPRVWUHDGVIURPVRXUFH/81V

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-13. FlashCopy: Single IASP multiple times to multiple targets (4 of 4)

© Copyright IBM Corp. 1995, 2017 17-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\PXOWLSOH,$63VWRVLQJOHWDUJHW RI
‡ 0XOWLSOH,%0LSDUWLWLRQV
‡ 0XOWLSOH³VRXUFH´DQGRQH³WDUJHW´VHWRIGLVNV/81V
‡ ³7DUJHW´/81VFDQEHIODVKHGWRDQGXVHGRQHSDUWLWLRQDWDWLPHEXW
FDQEHIODVKHGWRIURPPXOWLSOH³VRXUFH´SDUWLWLRQVDWGLIIHUHQWWLPHV

352'$

352'%

352')&
3URGXFWLRQ
,$63$
,%0L
3URGXFWLRQ
,$63%

)ODVK&RS\
6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-14. FlashCopy multiple IASPs to single target (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)ODVK&RS\PXOWLSOH,$63VWRVLQJOHWDUJHW RI
‡ %HQHILWV
ƒ 3URYLGHVDELOLW\WRFUHDWHSRLQWLQWLPH³FRSLHV´RI',))(5(17SURGXFWLRQ
VHWVRIGDWD
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQEDFNXSV
í 0XOWLSOHEDFNXSVFDQEHVWDJJHUHGEDFNWREDFN
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG VDYHVRQGLVNVSDFHVKDULQJVDPHWDUJHW
/81V
ƒ &DQEHPDQDJHGWKURXJK3RZHU+$RU,&60
í 6XSSRUWDGGHGDW3RZHU+$IRUPXOWLSOHVRXUFHVWRRQHWDUJHW
‡ /LPLWDWLRQV
ƒ 1RWD+LJK$YDLODELOLW\ +$ 25'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ 6LQJOHWDUJHWSDUWLWLRQKDVRQO\RQH³FRS\´DWDWLPH
ƒ 0XOWLSOHSDUWLWLRQVLQYROYHG
ƒ )XOO&RS\DQG,QFUHPHQWDO&RS\UHTXLUHIXOO\SURYLVLRQHG³WDUJHW´/81V
ƒ :LWKVSDFHHIILFLHQW WKLQSURYLVLRQHG /81VWKHUHLVQRIXOOFRS\RQGLVN
HOVHZKHUH
í :RXOGUHTXLUHDUHVWRUHIURPPHGLD
í 6RPHSHUIRUPDQFHSHQDOWLHVPLJKWDSSO\DVPRVWUHDGVIURPVRXUFH/81V

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-15. FlashCopy multiple IASPs to single target (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\ RI
‡ ,%0LSDUWLWLRQPXVWEHIXOO\YLUWXDOL]HG 5HVWULFWHG,2
‡ &DQEHPDQDJHGE\VDPH+0&RUWZRFRPPXQLFDWLQJ+0&V
‡ $OORZVPLJUDWLRQRISURFHVVRUVWDWHPHPRU\YLUWXDOGHYLFHVDQG
DWWDFKHGXVHUVIURPRQHSK\VLFDOVHUYHUWRDQRWKHU
‡ 5HTXLUHV,%0L75RUODWHU32:(5RUKLJKHUDQG9,26
/30

352' 352'

+0&

,%0L ,%0L

6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-16. Live Partition Mobility (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\ RI
‡ %HQHILWV
ƒ )XOOV\VWHPVROXWLRQQRWOLPLWHGWR,$63HQYLURQPHQWV
ƒ +LJK$YDLODELOLW\ +$ VROXWLRQIRUSODQQHGRSHUDWLRQV
í &DQQRWPRYHUHVRXUFHVLISURGXFWLRQLQD³IDLOHG´VWDWH
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG
ƒ (DVHRI&(&XSJUDGHVPDLQWHQDQFH
ƒ :RUNORDGEDODQFHRUFRQVROLGDWLRQ
‡ /LPLWDWLRQV
ƒ 6LQJOHFRS\RIGDWDRQGLVNV
í ([SRVXUHWRPXOWLSOHGULYHIDLOXUHVFDXVLQJRXWDJHRIVLQJOHFRS\RISURGXFWLRQGDWD
ƒ 1RWD'LVDVWHU5HFRYHU\ '5 6ROXWLRQ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-17. Live Partition Mobility (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

+\SHU6ZDS RI
‡ 2QH,%0LSDUWLWLRQ
‡ 7ZRVHWVRIGLVNV/81VPLUURUFRSLHVRIHDFKRWKHUIURP0HWUR0LUURU

6WDQGE\
&RQQHFWLRQ )XOO&RS\
6<6%$6
352'
0HWUR0LUURU
$FWLYH
&RQQHFWLRQ

3URGXFWLRQ
6<6%$6 '6
,%0L

'6
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-18. HyperSwap (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

+\SHU6ZDS RI
‡ %HQHILWV
ƒ )XOOV\VWHPVROXWLRQQRWOLPLWHGWR,$63HQYLURQPHQWV
ƒ ,%0L3RZHU+$([SUHVVHGLWLRQDGGVVXSSRUWIRU+\SHU6ZDS
ƒ +LJK$YDLODELOLW\ +$ VROXWLRQIRUVWRUDJHUHGXQGDQF\
ƒ 7ZRIXOOV\QFKURQL]HGFRSLHVRIGDWDRQGLVN
ƒ &DQEHPDQDJHGYLDQHZHU,%0LFRPPDQGVLQ667
ƒ 5HSOLFDWLRQLVUHYHUVHGDXWRPDWLFDOO\RQSODQQHGVZDS
ƒ 3ODQQHGVZDSRUIDLORYHUFDQRFFXUYHU\IDVW VHF
‡ /LPLWDWLRQV
ƒ 1RWD'LVDVWHU5HFRYHU\ '5 VROXWLRQ
í ,QWKHHYHQWRIDVLWHZLGHGLVDVWHUZRXOGVWLOODWOHDVWUHTXLUHDQRIIVLWHVHUYHU DQG
IRUWKHEDFNXS'6 WREHLQDGLIIHUHQWORFDWLRQ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-19. HyperSwap (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\ RI
‡ 7KUHH,%0LSDUWLWLRQV
‡ 2QH³VRXUFH´DQGRQH³WDUJHW´VHWRIGLVNV/81V
‡ ³7DUJHW´SDUWLWLRQDEOHWRSHUIRUPIXOOV\VWHPVDYHVZLWKRXWSURGXFWLRQ
³VRXUFH´ SDUWLWLRQUHTXLULQJGRZQWLPH

352'

&21752/

352')&
3URGXFWLRQ
6<6%$6
,%0L

)ODVK&RS\

6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-20. Full System FlashCopy (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-23


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\ RI
‡ %HQHILWV
ƒ 3URYLGHVDIXOOV\VWHPSRLQWLQWLPH³FRS\´
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQIXOOV\VWHPVDYHV
ƒ 0DQDJHGE\XVLQJ)XOO6\VWHP&RS\6HUYLFHV0DQDJHU )6&60
ƒ 6LQJOHFRPPDQGLQLWLDWLRQRIHQWLUHSURFHVV
ƒ &DQLQWHJUDWHZLWK%506WRDOORZSURGXFWLRQV\VWHPWRFRQWDLQDOOQHHGHG
GDWDIRUIXOORUSDUWLDOV\VWHPUHFRYHU\
‡ /LPLWDWLRQV
ƒ 1RWD+LJK$YDLODELOLW\ +$ RU'LVDVWHU5HFRYHU\ '5 6ROXWLRQ
ƒ 5HTXLUHVDWKLUGSDUWLWLRQ RUH[LVWHQFHRIDWKLUGSDUWLWLRQ WRFRQWUROWKH
SURFHVVLQGHSHQGHQWRIWKH)ODVK&RS\³VRXUFH´DQG³WDUJHW´
ƒ )XOO&RS\DQG,QFUHPHQWDO&RS\UHTXLUHIXOO\SURYLVLRQHG³WDUJHW´/81V
ƒ :LWKVSDFHHIILFLHQW WKLQSURYLVLRQHG /81VWKHUHLVQRIXOOFRS\RQGLVN
HOVHZKHUH WKHIXOOFRS\LVRQPHGLDVRPHZKHUH
í :RXOGUHTXLUHDUHVWRUHIURPPHGLD
í 6RPHSHUIRUPDQFHSHQDOWLHVPLJKWDSSO\DVPRVWUHDGVIURPVRXUFH/81V

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-21. Full System FlashCopy (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-24


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP5HSOLFDWLRQ RI
‡ 7ZR,%0LSDUWLWLRQV GLIIHUHQW³VLWHV´
‡ 2QH³SURGXFWLRQ´DQGRQHRUWZRVHWVRIGLVNV/81VIRUPLUURUFRS\DQG
LIQHHGHG FRQVLVWHQF\JURXSFRS\ QRWVKRZQ
‡ 7DUJHW26LVRIIOLQHIXOO,3/UHTXLUHGIRUVZDSRUIDLORYHU
‡ 5HTXLUHVH[WHUQDOVWRUDJHIRUUHSOLFDWLRQ
‡ 5HTXLUHV3RZHU+$FOXVWHU

352' %&.3
0HWUR0LUURURU
*OREDO&RS\0LUURU

3URGXFWLRQ )XOO&RS\
6<6%$6 6<6%$6
,%0L ,%0L

6$16WRUDJH 6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-22. Full System Replication (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-25


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP5HSOLFDWLRQ RI
‡ %HQHILWV
ƒ 3URYLGHVD+LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQDQG
FRXOGEHOHYHUDJHGWRSHUIRUPIXOOV\VWHPVDYHVGHSHQGLQJRQFRPELQDWLRQ
RIRSWLRQVXVHG
ƒ 3URYLGHVIXOOV\VWHP&23<RISURGXFWLRQGDWD

‡ /LPLWDWLRQV
ƒ &XUUHQWO\QRWPDQDJHGXVLQJ3RZHU+$
ƒ 5HTXLUHVH[WHUQDOVWRUDJH
ƒ 7DUJHW6\VWHP26LVFRPSOHWHO\RIIOLQH)XOOV\VWHP,3/UHTXLUHG
ƒ &XUUHQWO\VWLOOEHLQJGHVLJQHGWRH[WHQGWRPXOWLSOHUHSOLFDWLRQVROXWLRQVDQG
LQWHJUDWHZLWKH[LVWLQJ,$63&RS\6ROXWLRQV0DQDJHU ,&60 IRUHDVHRI
PDQDJHPHQWDQGLPSOHPHQWDWLRQRIHQGWRHQGVROXWLRQ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-23. Full System Replication (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-26


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

,QGHSHQGHQW&RS\6HUYLFHV0DQDJHU
‡ 7ZRRUPRUH,%0LSDUWLWLRQV
‡ 2QH,$63DXWRPDWLRQDQGPDQDJHPHQWRI)ODVK&RS\ XVLQJDVHWRI
FRPPDQGV\RXFDQXVHWRFUHDWHD³SRLQWLQWLPH´FRS\RIDQ,QGHSHQGHQW
$X[LOLDU\6WRUDJH3RRO ,$63 
‡ 5HTXLUHVH[WHUQDOVWRUDJH
,%0L ,%0L
3URGXFWLRQ %DFNXS+$
DFWLYH DFWLYH

6<6%$6 6<6%$6

3URGXFWLRQ&RS\,$63
,$637DUJHW&RS\
,%0L ,%0L
%$&.83 0HWURRU %$&.83
SDUWLWLRQRQ *OREDO0LUURU SDUWLWLRQRQ
352'VLWH %$&.83
DFWLYH ,$63 ,$63 VLWHDFWLYH

'6
'6
6<6%$6 6<6%$6
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-24. Independent Copy Services Manager

© Copyright IBM Corp. 1995, 2017 17-27


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

0HWUR*OREDO0LUURU RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ $XWRPDWLFDOO\FKHFNIRU)ODVK&RS\UHDGLQHVV,VVXHD)ODVK&RS\
ƒ 9DU\RQWKH,$63WRWKH%DFNXS)ODVK&RS\QRGH
ƒ (DVHRIPDQDJHPHQWXWLOLWLHVDFURVVPXOWLSOHQRGHVLQWKH3RZHU+$FOXVWHU
ƒ &RPSOLPHQWVDQGSURYLGHVHQKDQFHGIXQFWLRQDOLW\WR,%0L3RZHU+$
ƒ )ODVK&RS\HQYLURQPHQWV,QWHJUDWLRQDQGDXWRPDWLRQRI%506EDFNXS
IXQFWLRQVZLWKWKH,$63
ƒ $OORZFXVWRPL]HGHQKDQFHPHQWVWR)ODVK&RS\HQYLURQPHQWV UHYHUVHIODVK
IODVKIURP+$ 
‡ /LPLWDWLRQV
ƒ 5HTXLUHV3RZHU+$FOXVWHU
ƒ 5HTXLUHV([WHUQDOVWRUDJH
ƒ 5HSOLFDWLRQ,$63RQO\6<6%$6GDWDSDUWLDOO\UHSOLFDWHGE\&OXVWHU
$GPLQLVWUDWLYH'RPDLQ

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-25. Metro-Global Mirror (1 of 3)

© Copyright IBM Corp. 1995, 2017 17-28


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

0HWUR*OREDO0LUURU RI
‡ 7KUHH,%0LSDUWLWLRQV WKUHH³VLWHV´
‡ 2QH,$63WKUHHIXOOFRSLHVSOXVRQHDGGLWLRQDOVHWRIGLVNV/81VIRU
&RQVLVWHQF\*URXS &* )ODVK&RS\
‡ 5HTXLUHV'6H[WHUQDOVWRUDJHDQG73&5

,%0L ,%0L ,%0L

352' %&.3+$ %&.3'5

00LU7DUJHW
*0LU6RXUFH

335&7DUJHW
3URGXFWLRQ 0HWUR0LUURU *OREDO&RS\
&RS\
&RS\,$63
&*&RS\

'6 '6 '6


3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-26. Metro-Global Mirror (2 of 3)

© Copyright IBM Corp. 1995, 2017 17-29


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

0HWUR*OREDO0LUURU RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ /RFDOVLWHKDVFRQVLVWHQWV\QFKURQL]HGFRS\RIGDWDZKLOHUHPRWHVLWHVWLOO
SURYLGHVDQHDUFRQVLVWHQW'5VROXWLRQ
ƒ )DVWIDLORYHUDQGIDLOEDFN
ƒ 5DSLGUHHVWDEOLVKPHQWRIVLWHPLUURULQJZLWKRXWSURGXFWLRQRXWDJHV
ƒ $ELOLW\WRWHVW'5DWUHPRWHVLWHZKLOHPDLQWDLQLQJDORFDO³'5´VROXWLRQ
ƒ ,&60FDQPDQDJHWKHHQYLURQPHQWWRHDVHGDLO\XVDJH
‡ /LPLWDWLRQV
ƒ 5HTXLUHVDGGLWLRQDOVWRUDJHDQGVHWVRIGLVNV
ƒ 5HTXLUHV73&5IRUPDQDJHPHQW
ƒ 5HTXLUHV'6VWRUDJH

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-27. Metro-Global Mirror (3 of 3)

© Copyright IBM Corp. 1995, 2017 17-30


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty
17.3. Topic 3: PowerHA/DR complex
combinations

© Copyright IBM Corp. 1995, 2017 17-31


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

7RSLF3RZHU+$'5FRPSOH[
FRPELQDWLRQV

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-28. Topic 3: PowerHA/DR complex combinations

© Copyright IBM Corp. 1995, 2017 17-32


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

0HWUR*OREDO0LUURU)ODVK&RS\ RI
‡ 7KUHH,%0LSDUWLWLRQV WKUHH³VLWHV´
‡ 2QH,$63WKUHHIXOOFRSLHVSOXVIRXUDGGLWLRQDOVHWVRIGLVNV/81VIRU
*0LU&*DQG)ODVK&RS\
‡ 5HTXLUHVH[WHUQDOVWRUDJHDQG73&5

,%0L ,%0L ,%0L

352' %&.3+$ %&.3'5

00LU7DUJHW
*0LU6RXUFH

335&7DUJHW
3URGXFWLRQ 0HWUR0LUURU *OREDO&RS\
&RS\
&RS\,$63
&*&RS\

)ODVK&RS\ 00LU )ODVK&RS\ 00LU )ODVK&RS\


7DUJHW 7DUJHW *0LU7DUJHW
'6 '6 '6
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-29. Metro-Global Mirror + FlashCopy (1 of 2)

IBM TotalStorage Productivity Center for Replication TPC-R more at


[Link]
cr_domain.html.

© Copyright IBM Corp. 1995, 2017 17-33


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

0HWUR*OREDO0LUURU)ODVK&RS\ RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ )ODVK&RS\SURYLGHVDGGLWLRQDOVROXWLRQVIRUEDFNXSDWHLWKHUDQ\VLWH
ƒ /RFDOVLWHKDVFRQVLVWHQWV\QFKURQL]HGFRS\RIGDWDZKLOHUHPRWHVLWHVWLOO
SURYLGHVDQHDUFRQVLVWHQW'5VROXWLRQ
ƒ )DVWIDLORYHUDQGIDLOEDFN
ƒ 5DSLGUHHVWDEOLVKPHQWRIVLWHPLUURULQJZLWKRXWSURGXFWLRQRXWDJHV
ƒ $ELOLW\WRWHVW'5DWUHPRWHVLWHZKLOHPDLQWDLQLQJDORFDO³'5´VROXWLRQ
ƒ ,&60FDQPDQDJHWKHHQYLURQPHQWWRHDVHGDLO\XVDJH
‡ /LPLWDWLRQV
ƒ 5HTXLUHVDGGLWLRQDOVWRUDJHDQGVHWVRIGLVNV
ƒ 5HTXLUHV73&5IRUPDQDJHPHQW5HTXLUHV'6VWRUDJH
ƒ 5HTXLUHV/DE6HUYLFHV

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-30. Metro-Global Mirror + FlashCopy (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-34


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\/81OHYHOVZLWFKLQJ RI
‡ 7ZR6HUYHUVZLWKVKDUHG6$16WRUDJH
‡ 7ZR,%0L75RUODWHUSDUWLWLRQVIRU/30 6<6%$6(DQG,$63
‡ 2U3RZHU+$/81/HYHOVZLWFKLQJ352'WR%.83 ,$63RQO\
‡ 2QHVHWRIGLVNV/81VGHILQLQJHDFKVWRUDJHSRRO

/30

352' 352'

%&.3

3URGXFWLRQ
6<6%$6 /81/HYHO
,%0L ,%0L
6ZLWFK

3URGXFWLRQ
&RS\,$63

6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-31. Live Partition Mobility + LUN-level switching (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-35


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\/81OHYHOVZLWFKLQJ RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ VROXWLRQ
ƒ )XOOV\VWHPVROXWLRQIRU/30
ƒ /LPLWHGDPRXQWRIGLVNUHTXLUHG
ƒ (DVHRI&(&XSJUDGHVPDLQWHQDQFH /30
ƒ :RUNORDGEDODQFHRUFRQVROLGDWLRQ /30
ƒ $XWRPDWHGIDLORYHURI,$63WKURXJK3RZHU+$DWY /81VZLWFK
ƒ /81/HYHO6ZLWFKLQJPDQDJHGYLD3RZHU+$RU,&60
‡ /LPLWDWLRQV
ƒ 6LQJOHFRS\RIGDWD
ƒ 1RWD'LVDVWHU5HFRYHU '5 VROXWLRQ VLQJOHGDWDFHQWHU
ƒ /30QRWPDQDJHGYLD3RZHU+$RU/%67RRONLWVEXW/DE6HUYLFHVWHDPFDQ
DVVLVWZLWKLPSOHPHQWDWLRQVNLOOWUDQVIHUDQGFXVWRPFRGH

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-32. Live Partition Mobility + LUN-level switching (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-36


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\0HWUR*OREDO0LUURU RI
‡ )RXU,%0LSDUWLWLRQVWZRRUWKUHH³ORFDO´
‡ 2QH,$63WKUHHIXOOFRSLHVSOXVRQHDGGLWLRQDOVHWRIGLVNV/81VIRU
&RQVLVWHQF\*URXS &* )ODVK&RS\
‡ 5HTXLUHVH[WHUQDOVWRUDJHDQG73&5

,%0L ,%0L ,%0L ,%0L

352' 352' %&.3+$ %&.3'5

335&7DUJHW
3URGXFWLRQ 0HWUR0LUURU *OREDO&RS\
&RS\
&RS\,$63
00LU7DUJHW
*0LU6RXUFH &*&RS\

'6 '6 '6


3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-33. Live Partition Mobility + Metro-Global Mirror (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-37


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

/LYH3DUWLWLRQ0RELOLW\0HWUR*OREDO0LUURU RI
‡ %HQHILWV
ƒ +LJK$YDLODELOLW\ +$ DQG'LVDVWHU5HFRYHU\ '5 VROXWLRQ
ƒ )XOOV\VWHPVROXWLRQIRU/30$GGHGEHQHILWVIURP/30
ƒ )ODVK&RS\ QRWSLFWXUHG FRXOGSURYLGHDGGLWLRQDOVROXWLRQVIRUEDFNXSDW
HLWKHUDQ\VLWH
ƒ /RFDOVLWHKDVFRQVLVWHQWV\QFKURQL]HGFRS\RIGDWDZKLOHUHPRWHVLWHVWLOO
SURYLGHVDQHDUFRQVLVWHQW'5VROXWLRQ
ƒ )DVWIDLORYHUDQGIDLOEDFN
ƒ 5DSLGUHHVWDEOLVKPHQWRIVLWHPLUURULQJZLWKRXWSURGXFWLRQRXWDJHV
ƒ $ELOLW\WRWHVW'5DWUHPRWHVLWHZKLOHPDLQWDLQLQJDORFDO³'5´VROXWLRQ
ƒ ,&60FDQPDQDJHWKHHQYLURQPHQWWRHDVHGDLO\XVDJH
‡ /LPLWDWLRQV
ƒ 5HTXLUHVDGGLWLRQDOVWRUDJHDQGVHWVRIGLVNV
ƒ 5HTXLUHVDGGLWLRQDOSDUWLWLRQVIRU/30
ƒ 5HTXLUHV'6VWRUDJHDQG73&5IRUPDQDJHPHQW

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-34. Live Partition Mobility + Metro-Global Mirror (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-38


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\IRU6\VWHPZLWK,$63 RI
‡ 7KUHH,%0LSDUWLWLRQV
‡ 7ZRVHWVRIGLVNV/81VIRU6<6%$6WZRVHWVRIGLVNV/81VIRU,$63
‡ 6<6%$6DQG,$63DUHIXOO\FRSLHGWRDOORZIRUIXOOV\VWHPVDYHV
ZLWKRXWLQWHUUXSWLRQWRSURGXFWLRQ

3URGXFWLRQ
6<6%$6

352'
3URGXFWLRQ
&21752/ ,$63
)ODVK&RS\
352')&
,$63

,%0L
)ODVK&RS\
6<6%$6 6$1
6WRUDJH

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-35. Full System FlashCopy for System with IASP (1 of 2)

© Copyright IBM Corp. 1995, 2017 17-39


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\IRU6\VWHPZLWK,$63 RI
‡ %HQHILWV
ƒ 3URYLGHVDIXOOV\VWHPSRLQWLQWLPH³FRS\´
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQIXOOV\VWHPVDYHV
ƒ 0DQDJHGXVLQJ)XOO6\VWHP&RS\6HUYLFHV0DQDJHU )6&60
ƒ 6LQJOHFRPPDQGLQLWLDWLRQRIHQWLUHSURFHVV
ƒ %XLOWLQH[LWSURJUDPVZLWKLQ)6&60WRKDQGOH,$63YDU\RQRII
ƒ &DQLQWHJUDWHZLWK%506WRDOORZSURGXFWLRQV\VWHPWRFRQWDLQDOOQHHGHG
GDWDIRUIXOORUSDUWLDOV\VWHPUHFRYHU\
‡ /LPLWDWLRQV
ƒ 1RWD+LJK$YDLODELOLW\ +$ RU'LVDVWHU5HFRYHU\ '5 6ROXWLRQ
ƒ 5HTXLUHVDWKLUGSDUWLWLRQ RUH[LVWHQFHRIDWKLUGSDUWLWLRQ WRFRQWUROWKH
SURFHVVLQGHSHQGHQWRIWKH)ODVK&RS\³VRXUFH´DQG³WDUJHW´
ƒ )XOO&RS\DQG,QFUHPHQWDO&RS\UHTXLUHIXOO\SURYLVLRQHG³WDUJHW´/81V
ƒ :LWKVSDFHHIILFLHQW WKLQSURYLVLRQHG /81VWKHUHLVQRIXOOFRS\RQGLVN
HOVHZKHUH WKHIXOOFRS\LVRQPHGLDVRPHZKHUH

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-36. Full System FlashCopy for System with IASP (2 of 2)

© Copyright IBM Corp. 1995, 2017 17-40


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\5HSOLFDWLRQ RI
‡ )RXU,%0LSDUWLWLRQVSOXVRQHIRUVZLWFKRYHU
‡ 7KUHHVHWVRIGLVNV/81VWKUHHIXOOFRSLHV
‡ )XOOV\VWHPEDFNXSVSHUIRUPHGZLWK12LPSDFWWRSURGXFWLRQVHWRI
/81VIURPUHDG,2GXULQJEDFNXS

352' %&.3
0HWUR0LUURU
&21752/ RU*OREDO &21752/
&RS\
%&.3)&
3URGXFWLRQ )XOO&RS\
6<6%$6 6<6%$6
,%0L ,%0L

)ODVK&RS\
6$16WRUDJH 6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-37. Full System FlashCopy + Replication (1 of 3)

© Copyright IBM Corp. 1995, 2017 17-41


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\5HSOLFDWLRQ RI
‡ )RXU,%0LSDUWLWLRQVSOXVRQHIRUVZLWFKRYHU
‡ 7KUHHVHWVRIGLVNV/81VWKUHHIXOOFRSLHV
‡ )XOOV\VWHPEDFNXSVSHUIRUPHGZLWK12LPSDFWWRSURGXFWLRQVHWRI
/81VIURPUHDG,2GXULQJEDFNXS

352' %&.3
0HWUR0LUURU
&21752/ RU*OREDO &21752/
&RS\
%&.3)&
3URGXFWLRQ )XOO&RS\
6<6%$6 6<6%$6
,%0L ,%0L

)ODVK&RS\
6$16WRUDJH 6$16WRUDJH
3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-38. Full System FlashCopy + Replication (2 of 3)

© Copyright IBM Corp. 1995, 2017 17-42


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

)XOO6\VWHP)ODVK&RS\5HSOLFDWLRQ RI
‡ %HQHILWV
ƒ 3URYLGHVDIXOOV\VWHPSRLQWLQWLPH³FRS\´
í (OLPLQDWHVVFKHGXOHGRXWDJHWLPHIRUSURGXFWLRQIXOOV\VWHPVDYHV
ƒ 0DQDJHGXVLQJ)XOO6\VWHP&RS\6HUYLFHV0DQDJHU )6&60
ƒ 5HDG,2IRUEDFNXSVRFFXUVRQUHPRWHVHWRIGLVNV )ODVK&RS\UHODWLRQVKLS 
ZLWKQRLPSDFWWRSURGXFWLRQVHWRIGLVNV
ƒ 6LQJOHFRPPDQGLQLWLDWLRQRIHQWLUHSURFHVV
ƒ &DQLQWHJUDWHZLWK%506WRDOORZSURGXFWLRQV\VWHPWRFRQWDLQDOOQHHGHG
GDWDIRUIXOORUSDUWLDOV\VWHPUHFRYHU\
‡ /LPLWDWLRQV
ƒ 7KHPLUURULQJVROXWLRQLVWKH+LJK$YDLODELOLW\ +$ RU'LVDVWHU5HFRYHU\ '5 
6ROXWLRQQRWVSHFLILFDOO\WKH)6&60SURFHVVHV
ƒ )6&60GRHV127PDQDJHWKHPLUURULQJVROXWLRQHQWLUHO\
í $GGLWLRQDOH[LWSURJUDPVFDQEHLQWHJUDWHGWRDVVLVWZLWKWKDWWKURXJK/%6
ƒ 5HTXLUHVDFRQWUROOLQJSDUWLWLRQWRFRQWUROWKHSURFHVVLQGHSHQGHQWRIWKH
)ODVK&RS\³VRXUFH´DQG³WDUJHW´

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-39. Full System FlashCopy + Replication (3 of 3)

© Copyright IBM Corp. 1995, 2017 17-43


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH)6&60DOORZV\RXWR)ODVK&RS\,%0LV\VWHP
ZLWKRUZLWKRXW,$63DQGFDQEHLQWHJUDWHGZLWK%506

 7UXHRUIDOVH/LYH3DUWLWLRQ0RELOLW\DOORZV\RXWRPRYH
UHVRXUFHVZKHQ3URGXFWLRQIDLOHG

 7UXHRUIDOVH+\SHU6ZDS DOORZV\RXWRPRYHEHWZHHQ
H[WHUQDOVWRUDJHV

 7UXHRUIDOVH,&60DQG)65DUHXVLQJ3RZHU+$FOXVWHU

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-40. Review questions

© Copyright IBM Corp. 1995, 2017 17-44


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH)6&60DOORZV\RXWR)ODVK&RS\,%0LV\VWHP
ZLWKRUZLWKRXW,$63DQGFDQEHLQWHJUDWHGZLWK%506
7KHDQVZHULVWUXH

 7UXHRUIDOVH/LYH3DUWLWLRQ0RELOLW\DOORZV\RXWRPRYH
UHVRXUFHVZKHQ3URGXFWLRQIDLOHG
7KHDQVZHULVIDOVH

 7UXH RUIDOVH+\SHU6ZDS DOORZV\RXWRPRYHEHWZHHQ


H[WHUQDOVWRUDJHV
7KHDQVZHULVWUXH

 7UXH RUIDOVH,&60DQG)65DUHXVLQJ3RZHU+$FOXVWHU
7KHDQVZHULVWUXH

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-41. Review answers

© Copyright IBM Corp. 1995, 2017 17-45


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 17. Power HA/DR solutions

Uempty

8QLWVXPPDU\
‡ 'HVFULEHWKHIHDWXUHVDQGIXQFWLRQVSURYLGHGE\%506
‡ /LVWDYDLODEOHKLJKDYDLODELOLW\+$DQG'5VROXWLRQV
‡ 'LVFXVVFRPSOH[VROXWLRQVWRDFKLHYHUHTXLUHG+$'5OHYHO

3RZHU+$'5VROXWLRQV ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 17-42. Unit summary

© Copyright IBM Corp. 1995, 2017 17-46


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

Unit 18. Power SC for i


Estimated time
00:25

Overview
This unit provides an overview of IBM Lab Services PowerSC for i tools. This unit covers available
solutions to automate and simplify security management.

How you will check your progress


• Review questions

© Copyright IBM Corp. 1995, 2017 18-1


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

8QLWREMHFWLYHV
‡ 'HVFULEHH[LVWLQJ3RZHU6&IRULWRROV
‡ 'HVFULEHEHQHILWVRI3RZHU6&IRULWRROV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-1. Unit objectives

© Copyright IBM Corp. 1995, 2017 18-2


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

3RZHU6&7RROVIRU,%0, RI
‡ 3RZHU6&7RROVIRU,%0LKHOSV
FOLHQWVHQVXUHDKLJKHUOHYHORI
VHFXULW\DQGFRPSOLDQFH

‡ &OLHQW%HQHILWV
ƒ 6LPSOLILHVPDQDJHPHQWDQG
PHDVXUHPHQWRIVHFXULW\DQG
FRPSOLDQFH
ƒ 5HGXFHVFRVWRIVHFXULW\DQG
FRPSOLDQFH
ƒ 5HGXFHVVHFXULW\H[SRVXUHV
ƒ ,PSURYHVWKHDXGLWFDSDELOLW\WR
VDWLVI\UHSRUWLQJUHTXLUHPHQWV

3RZHU6&7RROVIRU,%0LLVDVHUYLFHRIIHULQJ
IURP,%06\VWHPV/DE6HUYLFHV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-2. PowerSC Tools for IBM I (1 of 3)

PowerSC Tools for IBM i are a set of service offerings available from IBM Systems Lab Services.
The tools are provided as a service offering, not a licensed program product.
Like the product PowerSC product that is targeted at AIX, the PowerSC Tools for IBM i help clients
ensure a higher level of security and compliance on their systems, networks and data.

© Copyright IBM Corp. 1995, 2017 18-3


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

3RZHU6&7RROVIRU,%0, RI
9 6LPSOLILHVPDQDJHPHQW DQGPHDVXUHPHQWRIVHFXULW\DQGFRPSOLDQFH
9 5HGXFHVFRVW RIVHFXULW\DQGFRPSOLDQFH
9 ,PSURYHVGHWHFWLRQ DQGUHSRUWLQJRIVHFXULW\H[SRVXUHV
9 ,PSURYHV WKHDXGLWFDSDELOLW\ WRVDWLVI\UHSRUWLQJUHTXLUHPHQWV

3RZHU6&7RROVIRU,%0L %HQHILWV
&RPSOLDQFH$VVHVVPHQWDQG 'HPRQVWUDWHDGKHUHQFHWRSUHGHILQHGDQGFXVWRPHUGHILQHG
5HSRUWLQJ VHFXULW\SROLFHVV\VWHPFRPSRQHQWLQYHQWRU\&HQWUDOL]H
VHFXULW\PDQDJHPHQWDQGUHSRUWLQJYLD'E:HE4XHU\
6HFXULW\'LDJQRVWLFV 5HGXFHVRSHUDWRUWLPHLQYROYHGLQUHPHGLDWLQJH[SRVXUHV
,%0/DE6HUYLFHVRIIHULQJVIRU
,%0L VHFXULW\ 3ULYLOHJHG$FFHVV&RQWURO (QVXUHVFRPSOLDQFHZLWKJXLGHOLQHVRQSULYLOHJHGXVHUV
$FFHVV&RQWURO0RQLWRU 3UHYHQWVXVHUDSSOLFDWLRQIDLOXUHVGXHWRLQFRQVLVWHQWFRQWUROV
9 IBM i Security 1HWZRUN,QWHUIDFH)LUHZDOO 5HGXFHVWKUHDWRIXQDXWKRUL]HGVHFXULW\EUHDFKDQGGDWDORVV
Assessment
&HUWLILFDWH([SLUDWLRQ0DQDJHU 3UHYHQWVV\VWHPRXWDJHVGXHWRH[SLUHGFHUWLILFDWHV
9 IBM i Single Sign On 3DVVZRUG9DOLGDWLRQ (QVXUHVXVHUSDVVZRUGVDUHQRWWULYLDODQGDUHLQ
Implementation 6\QFKURQL]DWLRQ72737ZR)DFWRU V\QFKURQL]DWLRQDFURVVDOO/3$5V,QVXUHVHUYLFHDFFRXQWV
$XWKHQWLFDWLRQ )$ DGKHUHWRSROLF\ LQFOXGLQJ695$87((QKDQFHDSSOLFDWLRQV
ZLWK)$VHUYLFHSURJUDP
9 IBM i Security
Remediation 6LQJOH6LJQ2Q 662 6XLWH 5HGXFHVIRUSDVVZRUGUHVHWVDQGVLPSOLILHVXVHUH[SHULHQFH

9 Password Validation,
3RZHU6&7RROVIRU,%0LLVDVHUYLFHRIIHULQJ
Synchronization, 2FA
IURP,%06\VWHPV/DE6HUYLFHV
9 IBM i Encryption

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-3. PowerSC Tools for IBM I (2 of 3)

This is a nice summary page of the offering.


When discussing our tools versus our security vendor competitors it is important to distinguish our
tools as niche - targeted at meeting specific requirements. They do the job. Analogy – MS Office
provides a lot of function – 80% of its function is not needed by most people that simply want a
document editor. Our tools are like that – providing specific functions and meeting specific
requirements.
Relative to competitive cost concerns with our security vendors. Some customers want to address
a specific issue and do not want to invest in a full robust product. Our niche solution approach gives
them an option to do just that at a generally affordable price.

© Copyright IBM Corp. 1995, 2017 18-4


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

3RZHU6&7RROVIRU,%0, RI
7RROV)HDWXUH )XQFWLRQ %HQHILW
&RPSOLDQFH$VVHVVPHQW 'DLO\FRPSOLDQFHGDVKERDUGUHSRUWVDW/3$5 (QDEOHVFRPSOLDQFHRIILFHUWRGHPRQVWUDWH
DQG5HSRUWLQJ7RRO V\VWHPRUHQWHUSULVHOHYHO DGKHUHQFHWRSUHGHILQHGVHFXULW\SROLFHV

5HSRUWVGHWDLOLQJVHFXULW\FRQILJXUDWLRQVHWWLQJV 5HGXFHVRSHUDWRUWLPHLQYROYHGLQ
6HFXULW\'LDJQRVWLFV
DQGLGHQWLI\LQJGHILFLHQFLHV UHPHGLDWLQJVHFXULW\H[SRVXUHV
(QVXUHVFRPSOLDQFHZLWKLQGXVWU\JXLGHOLQHV
3ULYLOHJHG$FFHVV&RQWURO &RQWUROVWKHQXPEHURISULYLOHJHGXVHUV
RQSULYLOHJHGXVHUV
0DQDJHVDQGFRQWUROVDFFHVVWRSRZHUIXO6$3 (OLPLQDWHVVKDULQJRI6$3DGPLQLVWUDWLYH
6HFXUH$GPLQLVWUDWRUIRU6$3
DGPLQLVWUDWLYHSURILOHV SURILOHVZLWKHQKDQFHGVHFXULW\DXGLWLQJ
0RQLWRUVVHFXULW\GHYLDWLRQVIURPDSSOLFDWLRQ 3UHYHQWVXVHUDSSOLFDWLRQIDLOXUHVGXHWR
$FFHVV&RQWURO0RQLWRU
GHVLJQ LQFRQVLVWHQWDFFHVVFRQWUROV
1HWZRUN,QWHUIDFH)LUHZDOO &RQWUROVDFFHVVWR([LW3RLQWLQWHUIDFHVVXFKDV 5HGXFHVWKUHDWRIXQDXWKRUL]HGVHFXULW\
IRU,%0L([LW3RLQWV 2'%&)73507&0'HWF EUHDFKDQGGDWDORVV
&RQVROLGDWHVDQGUHGXFHVVHFXULW\DXGLWMRXUQDO 6LPSOLILHVDXGLWDQDO\VLVIRUFRPSOLDQFH
$XGLW5HSRUWLQJ
LQIRUPDWLRQ RIILFHUDQGRUDXGLWRUV
6LPSOLILHVPDQDJHPHQWRIGLJLWDOFHUWLILFDWHV +HOSVRSHUDWRUVSUHYHQWV\VWHPRXWDJHVGXH
&HUWLILFDWH([SLUDWLRQ0DQDJHU
H[SLUDWLRQ WRH[SLUHGFHUWLILFDWHV
(QKDQFHV,%0LRSHUDWLQJV\VWHPSURWHFWLRQZLWK (QDEOHVVHFXULW\RIILFHUWRHQVXUHXVHU
3DVVZRUG9DOLGDWLRQ6\QFKURQL]DWLRQ
EHWWHUSDVVZRUGPDQDJHPHQWDQGLQWHJULW\ SDVVZRUGVDQG695$87(DUHQRWWULYLDO
6LPSOLILHVLPSOHPHQWDWLRQRI662DQGSDVVZRUG 5HGXFHVSDVVZRUGUHVHWVDQGVLPSOLILHVHQG
6LQJOH6LJQ2Q 662 6XLWH
V\QFKURQL]DWLRQ XVHUH[SHULHQFH
6LPSOLILHVLPSOHPHQWDWLRQRIFU\SWRJUDSK\XVLQJ +HOSVDSSOLFDWLRQGHYHORSHUVPHHWGDWD
(QFU\SWLRQ6XLWH
,%0LRSHUDWLQJV\VWHPFDSDELOLWLHV VHFXULW\VWDQGDUGVDQGSURWHFWFULWLFDOGDWD

3RZHU6&7RROVIRU,%0LLVDVHUYLFHRIIHULQJ
IURP,%06\VWHPV/DE6HUYLFHV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-4. PowerSC Tools for IBM I (3 of 3)

The PowerSC Tools for IBM i are a service offering, with each tool targeted to a specific security
function.
The tools provide a wide range of security and compliance capabilities that can enhance the
integrated security features of the IBM i operating system.
Each tool can be used independently and they are not integrated as a single program product.

© Copyright IBM Corp. 1995, 2017 18-5


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

&RPSOLDQFH$VVHVVPHQWDQG5HSRUWLQJ7RRO&HQWUDOL]HG
UHSRUWLQJRI,%0LVHFXULW\
ƒ $QDXWRPDWHGFROOHFWLRQDQDO\VLVDQGUHSRUWLQJWRRORQRYHUVHFXULW\UHODWHG
ULVNVLQIRUPDWLRQVWDWLVWLFVDQGGHPRJUDSKLFV$OOLQRQHORFDWLRQDQGHDV\WRXVH
ƒ &RYHUV ƒ (QDEOHVFRPSOLDQFHRIILFHUWRGHPRQVWUDWHDGKHUHQFH
 3DVVZRUGPDQDJHPHQW WRSUHGHILQHGRUFXVWRPHUGHILQHGVHFXULW\SROLFHV
 3URILOHDGPLQLVWUDWLRQ ƒ 6HFXULW\UHSRUWLQJPDGHHDV\
 6SHFLDODXWKRULWLHV
 *URXSLQKHULWDQFH
 1HWZRUNFRQILJXUDWLRQ
 1HW6HUYHUDWWULEXWHV
 2SHUDWLRQDOVHFXULW\
 6HFXULW\ULVNVDQGPRUH

ƒ 'DLO\FRPSOLDQFH
GDVKERDUGUHSRUWVDW90
SDUWLWLRQ V\VWHPRU
HQWHUSULVHOHYHO

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-5. Compliance Assessment and Reporting Tool Centralized reporting of IBM i security

The PowerSC Compliance Assessment and Reporting Tool provides centralized reporting of IBM i
security with easy to consume dashboards for rapid daily review of security.
While this tool is quite extensible its primary purpose is driving security compliance to client defined
policies and standards. Best practice comparisons are standard. Client defined policies and
exceptions can be implemented with interfaces included in the tool.

© Copyright IBM Corp. 1995, 2017 18-6


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

6HFXULW\GLDJQRVWLFV
,QGHSWKVHFXULW\FROOHFWLRQ
DQGUHSRUWLQJ

‡ 5HGXFHVVHFXULW\DGPLQLVWUDWRU
WLPHLQYROYHGLQUHPHGLDWLQJ
H[SRVXUHV
‡ 5HSRUWVRQ
ƒ 8VHUSURILOHV
ƒ $GRSWHGDXWKRULW\SURJUDPV
ƒ 7ULJJHUSURJUDPV
ƒ :RUN0DQDJHPHQW
ƒ $XGLWLQJFRQILJXUDWLRQ
ƒ 1HWZRUNDWWULEXWHV
ƒ ,QWHJUDWHG)LOH6\VWHP
ƒ 2YHUUHSRUWV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-6. Security diagnostics

The compliance assessment and reporting tool is good at day-to-day monitoring compliance and
pointing out exceptions in the enterprise.
When security exceptions are identified, the Security Diagnostics tool then used to drill down and
pinpoint the root cause of the issue.
Generally this tool is used by IBM consultants as part of a detailed security assessment or
remediation service but it can also be purchased for client remediation of their own environment.

© Copyright IBM Corp. 1995, 2017 18-7


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

3ULYLOHJHG$FFHVV&RQWURO
(QVXUHVFRPSOLDQFHWRLQGXVWU\JXLGHOLQHVRQSULYLOHJHGXVHUV
:LWKRXWFDUHIXOFRQWUROSULYLOHJHGXVHUVFDQSRVHDULVNWR\RXUV\VWHPVHFXULW\
7KLVWRROHQDEOHVWKHVHFXULW\DGPLQLVWUDWRUWRUHGXFHSULYLOHJHGDFFRXQWVZLWKD
PHFKDQLVPWRWHPSRUDULO\HOHYDWHSULYLOHJHVWRXVHUVZKHQQHHGHG
‡ 2SWLRQWRFKDQJH
LGHQWLW\IRU
WURXEOHVKRRWLQJ,)6
DFFHVVDQGREMHFW
RZQHUVKLS
UHTXLUHPHQWV
‡ )XOO\DXGLWHG
‡ $XWRPDWHGHPDLO
QRWLILFDWLRQVVHQWWR
GLVWULEXWLRQOLVWZKHQ
WRROLVLQYRNHGWKDW
LQFOXGHVDORJRI
DFWLYLWLHVSHUIRUPHG
‡ 6HUYLFH7LFNHW0DQDJHU
‡ &XVWRPL]DEOH

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-7. Privileged Access Control

Regardless of the operating system or platform, privileged access is one of the biggest security
concerns in IT. Generally, too many people have too much access.
One reason these privileged access is so prevalent is that they are often used for infrequent or ad
hoc administrative tasks. With the Privileged Access Control tool, the privileged access can be
elevated or provided only when needed, reducing the exposure of too many users with permanent
privileged access.

© Copyright IBM Corp. 1995, 2017 18-8


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

1HWZRUNLQWHUIDFHILUHZDOOIRU,%0LH[LWSRLQWV
5HGXFHVWKUHDWRIXQDXWKRUL]HGQHWZRUNDFFHVV
‡ ([LWSURJUDPVDOORZV\VWHPDGPLQLVWUDWRUVWRFRQWURO ‡ 8VHUVGHQLHGE\GHIDXOWIRUJUHDWHU
ZKLFKDFWLYLWLHVDXVHUDFFRXQWLVDOORZHGIRUHDFKRI VHFXULW\
WKHVSHFLILFVHUYHUV7KLVHDV\WRXVHLQWHUIDFH ‡ 8VHUVDOORZHGDUHDGGHGXVLQJPHQX
DGGUHVVHVWKHPRVWFRPPRQO\XVHGQHWZRUNLQWHUIDFHV
‡ $OORZDFFHVVWKURXJK*URXS3URILOHV
ƒ 5HVWULFWE\,3$GGUHVV5DQJH
ƒ /RJRQO\PRGH
ƒ &XUUHQWH[LWSRLQWFRYHUDJH
í '5'$''0
í ,)6
í )73
í 2'%&-'%&)LOH7UDQVIHU
í 5(;(&
í 507&0' KRQRUV/07&3%
í 64/&/,
í 7(/1(7 FXVWRPL]DWLRQRSWLRQDO
í +RVW6HUYHU 0XOWLSOH

‡ &XVWRPL]DWLRQIRUDGGLWLRQDOQHWZRUN
LQWHUIDFHVDYDLODEOH

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-8. Network interface firewall for IBM i exit points

Exit programs exist for many IBM i functions and applications. The purpose they serve is different
for each exit program and their associated application. However, many of them, such as Telnet and
FTP exit programs, can be used to perform additional checking during authentication or can be
used to control what an authenticated user can do. All exit programs have to be registered and the
Network Interface Firewall for IBM i Exit Point tool makes this process easier with a simple user
interface.
Logging and auditing is also, of course, a very important aspect when monitoring security. IBM i exit
programs enhance customer logging mechanisms for their various system applications. For
example, the FTP server does not provide a standard interface to enable logging of FTP
subcommands performed by a signed on user. However, with the help of this tool this information is
now logged.
The tool also addresses the challenge of remote command (RMTCMD) not honoring limited
capabilities settings in a users profile. This tool enforces that setting when a user connects outside
of the 5250 command line.

© Copyright IBM Corp. 1995, 2017 18-9


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

3DVVZRUGYDOLGDWLRQV\QFKURQL]DWLRQ
(QKDQFHGSURWHFWLRQWKURXJKVWULFWSDVVZRUGFULWHULD
‡ &KHFNVWKHSDVVZRUGWRVHHLILWFRQWDLQV
ƒ $Q\ZRUGVIURPDPDLQWDLQDEOHGLFWLRQDU\RIGLVDOORZHGZRUGV6HHGHG
ZLWKWRSSDVVZRUGVIRXQGLQUHSRUWHGEUHDFKHV 3DVVZRUGLVQRW
ƒ 3UHYLRXVSDVVZRUGVIURPDOO/3$5V FKDQJHG
FRPPDQG
‡ )HGHUDWHG'%RISURILOHVDFURVVDOO/3$5V UHWXUQVPHVVDJH
‡ 0DQDJHPHQWDFURVVDOO,%0L/3$56
‡ )LOWHUVLQFOXGHGIRUVXEVHWRIXVHUVRUV\VWHPV 12

4,%0B46<B9/'B
CHGPWD 'RHVSDVVZRUG
3$66:5' H[LW
FRPPDQGLV PHHWH[LWSURJUDP
SURJUDPLV
FDOOHG UHTXLUHPHQWV"
DXWRPDWLFDOO\UXQ

<(6 &RPPDQG
‡ 6HUYHUDXWKHQWLFDWLRQHQWULHVXSGDWHG
FRPSOHWHV
‡ $VVXUHVWKHVHFXULW\ DGPLQLVWUDWRUWKDWSDVVZRUGV SDVVZRUGLV
EHLQJHQWHUHGDUHQRWWULYLDO FKDQJHG
‡ &KHFNVDJDLQVWWKHSDVVZRUGUXOHVRIHDFKV\VWHP
‡ )XOO\DXGLWHG
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-9. Password validation / synchronization

Despite warnings, one-in-five users choose a non-compliant password to protect their identity.
While the IBM i operating system enables password rules, the Password Validation tool provides
tighter protection with stricter, client defined password criteria.
The Password Validation tool validates and ensures passwords meet company defined and
industry recommended rules and guidelines.
The tool also allows the security administrator to establish a dictionary of excluded terms, to further
tighten password security.

© Copyright IBM Corp. 1995, 2017 18-10


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

,%0LSDVVZRUGYDOLGDWLRQ
(QKDQFHGSURWHFWLRQWKURXJKDGGLWLRQDOSDVVZRUGFKHFNLQJ
‡ &KHFNVWKHSDVVZRUGWRVHHLILWFRQWDLQV
ƒ $Q\ZRUGVIURPDPDLQWDLQDEOHGLFWLRQDU\RIGLVDOORZHGZRUGV6HHGHGZLWK
WKHWRSSDVVZRUGVIRXQGLQJOREDOO\UHSRUWHGEUHDFKHV
ƒ 2ULJLQDOO\ZULWWHQIRUFXVWRPHUVXQDEOHWRPRYHIURP95LWLVXVHIXOIRUDOO
FXVWRPHUVZLVKLQJWRSUHYHQWXVHUVIURPHQWHULQJWULYLDOSDVVZRUGV WKHILUVW
OLQHRIGHIHQVHLQDGPLQLVWUDWLYHVHFXULW\

0RVW8VHG3DVVZRUGV

SDVVZRUG OHWPHLQ  EXVWHU KRFNH\


 PRQNH\ MRUGDQ WKRPDV JHRUJH
  VXSHUPDQ WLJJHU FKDUOLH
 DEF KDUOH\ UREHUW DQGUHZ
TZHUW\ PXVWDQJ  VRFFHU PLFKHOOH
 PLFKDHO IXFNPH IXFN ORYH
GUDJRQ VKDGRZ KXQWHU EDWPDQ VXQVKLQH
SXVV\ PDVWHU IXFN\RX WHVW MHVVLFD
EDVHEDOO MHQQLIHU WUXVWQR SDVV DVVKROH
IRRWEDOO  UDQJHU NLOOHU 
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-10. IBM i password validation

Despite warnings, one-in-five users choose a non-compliant password to protect their identity.
While the IBM i operating system enables password rules, the Password Validation tool provides
tighter protection with stricter, client defined password criteria.
The Password Validation tool validates and ensures passwords meet company defined and
industry recommended rules and guidelines.
The tool also allows the security administrator to establish a dictionary of excluded terms, to further
tighten password security.

© Copyright IBM Corp. 1995, 2017 18-11


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

7ZR)DFWRU$XWKHQWLFDWLRQ
/LPLWDFFHVVWRDSSOLFDWLRQVV\VWHPVWRSURSHUO\DXWKHQWLFDWHGXVHUV
‡ *HQHUDWHVKLJKO\VHFXUH5)&EDVHGRQHWLPHSDVVZRUGV 7273 
HQVXULQJWKDWRQO\SURSHUO\DXWKHQWLFDWHGXVHUVDUHDXWKRUL]HGDFFHVV
WRFULWLFDODSSOLFDWLRQVDQGGDWD
‡ ,%0LEDVHG45FRGHJHQHUDWRU
‡ 1RLQWHUQHWFRQQHFWLRQUHTXLUHG
‡ $XGLWRIUHJLVWUDWLRQDQGXVH
‡ 8VHDVDVLJQRQDSSOLFDWLRQRU
XVHSURYLGHGVHUYLFHSURJUDP
LQ\RXURZQDSSOLFDWLRQV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-11. Two Factor Authentication

Two Factor Authentication or 2FA.

© Copyright IBM Corp. 1995, 2017 18-12


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

$FFHVV&RQWURO0RQLWRU
0RQLWRUVHFXULW\GHYLDWLRQVIURPDSSOLFDWLRQGHVLJQ
‡ $GKRFRUVFKHGXOHGUHSRUWLQJWRFKHFNDQGUHSRUWRQDSSOLFDWLRQ
REMHFWVWKDWDUHRXWRIFRUSRUDWHVHFXULW\SROLF\VWDQGDUGVGDWD
FODVVLILFDWLRQVRURWKHUVHFXULW\UHODWHGFRQILJXUDWLRQV
‡ 3UHYHQWVXVHUDSSOLFDWLRQIDLOXUHVGXHWRLQFRQVLVWHQWDFFHVVFRQWUROV

‡ 0RQLWRUVFRPSOLDQFHRIOLEUDULHVREMHFWVDQGDXWKRUL]DWLRQ/LVWV
‡ &XVWRPHUH[WHQVLEOHWRDOORZDXWRPDWLRQRIREMHFWVEDFNLQWR
FRPSOLDQFH
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-12. Access Control Monitor

Many security assessments reveal inconsistent ownership, with overuse of *PUBLIC authorities
and excessive permissions granted to applications and files.
The Access Control Monitor tool allows the clients to define a policy or standard by which an
application should be secured and then report on exceptions when application components fall out
of compliance to those policies and standards.

© Copyright IBM Corp. 1995, 2017 18-13


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

&HUWLILFDWH([SLUDWLRQ0DQDJHU
6LPSOLILHVWKHPDQDJHPHQWRIGLJLWDOFHUWLILFDWHV
‡ 0DLQWDLQVDORJRIDOOH[SLUDWLRQ
DFWLYLWLHV
‡ 6HQGVQRWLILFDWLRQWKURXJKHPDLO
‡ (DV\WRXVHFRQILJXUDWLRQ*8,LV
LQFOXGHGIRUPDQDJLQJWKH;0/
VHWWLQJV
‡ 5XQVRQDQ\SODWIRUPWKDWVXSSRUWV
-DYD
‡ 3UHYHQWRXWDJHVGXHWRH[SLUHG
FHUWLILFDWHV

&HUWLILFDWH
8QLYHUVLW\RIWKH,QWHUQHW
,VVXH'DWH
'LVWLQJXLVKHG1DPH
3XEOLF.H\
([SLUDWLRQ'DWH
'LJLWDO6LJQDWXUHRI
&$

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-13. Certificate Expiration Manager

Certificates are issued/signed by certificate authorities (CAs) and are only valid for a specific time
range, typically one year. Most server services will not accept any new connection requests for
certificates that are expired. With the number of services that require a certificate increasing,
certificate expiration becomes more complex and important to prevent outages. The Certificate
Expiration Manager (CEM) tool simplifies the management of digital certificates and help prevent
outages due to expired certificates.
It is important to distinguish between well-known (public) CAs and private (intranet) CAs.
Well-known CAs charge money for issuing certificates. Privately operated CAs are typically free.
Generally, it is these privately operated CAs that are of most concern. Well-known CAs usually (but
not always) inform certificate requesters about upcoming certificate expiration. Privately operated
CAs must manage certificate expiration and renewal.

© Copyright IBM Corp. 1995, 2017 18-14


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

6LQJOH6LJQ2Q6XLWH
6LPSOLI\662LPSOHPHQWDWLRQUHGXFLQJ
KHOSGHVNFRVWV
‡ 6XLWHRIWRROVVROGLQGLYLGXDOO\RUjODFDUWH
ZLWKRUZLWKRXWLPSOHPHQWDWLRQVHUYLFHV
‡ 6LQJOH6LJQ2Q 662 6XLWHIRU'RPLQR
ƒ 'RPLQR6\QFKURQL]DWLRQ
ƒ '6$3,3OXJLQ

‡ 6LQJOH6LJQ2Q 662 6XLWHIRU(,0


‡ (,0&/&RPPDQGV
‡ (,03RSXODWRU
‡ (,00DQDJHPHQW8WLOLW\
‡ (,0%DVHG3DVVZRUG5HVHW
‡ (,0%DVHG&5786535)
‡ :LQGRZV$'3URILOH6\QFKURQL]DWLRQ

‡ 3DVVZRUG6\QFKURQL]DWLRQ7RRO

‡ 6LQJOH6LJQ2Q 662 IRU6$3

‡ $QHIIHFWLYHDOWHUQDWLYHWRPDQXDO
FRQILJXUDWLRQ
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-14. Single Sign On Suite

The Single Sign On (SSO) Suite tools simplify SSO implementation and help reduce help desk
costs associated with forgotten or expired passwords.
EIM CL Commands: Covers add and remove identifier, add and remove association, which is
useful for clients who want to add their own EIM related maintenance into their user provisioning CL
code.
EIM Management Utility: Provides everything on one screen rather than a series of windows
(fewer clicks to get to all information), and is used to back up your EIM (XML based).
EIM Based CRTUSRPRF: Exit programs that will automatically create the EIM identifier and
associations when CRTUSRPRF is run. As-is, it will assume that the user’s Windows ID is same as
IBM i user profile, but can be customized (for example to list the windows ID in the user profile
description). It also includes a DLTUSRPRF exit program that deletes the EIM identifier when
DLTUSRPRF is run.
Windows Active Directory (AD) Profile Synchronization: A Java program (can run wherever
there is a JRE) that runs on a scheduled basis and will poll Active Directory (AD) for users added to
or removed from groups that are defined in config XML. The program uses the IBM i Java Toolbox
to automatically create/delete profiles based on information from the AD poll, also enables or
disables profile based on AD account being enabled/disabled.

© Copyright IBM Corp. 1995, 2017 18-15


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty
The SSO Suite tools also enable SSO in an SAP environment on IBM i.

© Copyright IBM Corp. 1995, 2017 18-16


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

$XGLW5HSRUWLQJ
6HFXULW\DQGXVHUDXGLWLQJPDQDJHPHQWDQGDQDO\VLV
‡ :RUNZLWK4$8'-51MRXUQDOHQWULHVDQGVWDWLVWLFVWRXQGHUVWDQGWKH
GHPRJUDSKLFVWKDWGHILQH\RXUVHFXULW\RSHUDWLRQV
‡ (DVLO\YLHZV\VWHPDQGXVHUDXGLWLQJVWDWLVWLFVWRGHPRQVWUDWHWRPDQDJHPHQW
DQGDXGLWRUVWKDWVHFXULW\YLRODWLRQVDUHEHLQJREVHUYHGDQGKDQGOHG

‡ )LOWHUMRXUQDOHQWULHVE\
ƒ 8VHU3URILOH
ƒ 'DWH7LPH
‡ 0DQDJH
ƒ 8VHUREMHFWDQGDFWLRQ
DXGLWLQJYDOXHV
ƒ /LEUDU\)LOH,)6REMHFW
DXGLWLQJ
ƒ $XGLWLQJV\VWHPYDOXHV
ƒ -RXUQDOUHFHLYHUV
‡ 6FKHGXOHUWRDXWRPDWH
DFWLRQVDQGUHSRUWV
‡ 4XLFN$XGLWRI8VHUV
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-15. Audit Reporting

User activity and system/application auditing is a requirement for most companies.


The Audit Journal Analysis Tool simplifies the task of viewing entries in the IBM i security audit
journal. It provides flexibility and a statistical view of the number of entries occurring in each journal
entry.
The security administrator can select an entry by date, time or type, drill down for details and
optionally print or send an output file.
The tool also includes features for managing journal receivers, reporting on special authorities,
monitoring for the entries defined in the Security Exit Point Tool and a report scheduler.

© Copyright IBM Corp. 1995, 2017 18-17


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

6HFXUH$GPLQLVWUDWRUIRU6$3RQ,%0L
(OLPLQDWHVVKDULQJRISRZHUIXO6$3DGPLQLVWUDWRUXVHUSURILOHV
‡ 6$3SURYLGHGDGPLQLVWUDWRUXVHUSURILOHVDUHRIWHQVKDUHGOHDGLQJWRVHFXULW\H[SRVXUHVDQGLQHIIHFWLYHDXGLWLQJ
6HFXUH$GPLQLVWUDWRUIRU6$3RQ,%0LDGGUHVVHVWKLVH[SRVXUHE\SURYLGLQJDVHFXUHDQGDXGLWDEOHPHFKDQLVP
HQDEOLQJPXOWLSOH6$3DGPLQLVWUDWRUVWRXWLOL]HWKHVDPH6$3DGPLQLVWUDWRUXVHUSURILOHZLWKRXWVKDULQJWKHSURILOH
LWVHOI
%HIRUH6HFXUH$GPLQLVWUDWRUIRU6$3RQ,%0L
%HQHILWV Job:
‡ 6$3DGPLQLVWUDWRUVQRZRQO\QHHGWKHLU 867530/EP0ADM/QPADEV0002
,%0LXVHUSURILOHIRU6$3DGPLQLVWUDWLYH User Profile: EP0ADM
WDVNV
‡ 3URYLGHVWKHDELOLW\WRHIIHFWLYHO\DXGLW $IWHU 6HFXUH $GPLQLVWUDWRU IRU 6$3 RQ ,%0 L
6$3DGPLQLVWUDWRUXVHUSURILOHV
Job:
‡ /LPLWVDFFHVVWRDXWKRUL]HGXVHUV
867532/STEVE/QPADEV0003
‡ 6$3DGPLQLVWUDWRUXVHUSURILOHVQRORQJHU User Profile: EP0ADM
VKDUHG
‡ ,QWHUDFWLYHXVHRI6$3DGPLQLVWUDWRUXVHU &RPPDQGV
SURILOHVHOLPLQDWHG • CRTSUDOENV DQGDLTSUDOENV
‡ 0DQDJHPXOWLSOH6$3LQVWDOODWLRQV ƒ &UHDWHGHOHWHWKH6HFXUH$GPLQLVWUDWRUHQYLURQPHQW
UXQQLQJRQWKHVDPHSDUWLWLRQ IURPWKH • GRTSIDSUDO DQGRVKSIDSUDO
VDPHLQWHUDFWLYHVHVVLRQ
ƒ *UDQWUHYRNHXVHRIDGPLQLVWUDWRUIXQFWLRQVIRUGLIIHUHQW6$3LQVWDOODWLRQV
• LSTSIDSUDO
ƒ /LVW6HFXUH$GPLQLVWUDWRUHQYLURQPHQWVDQGXVHUVWKDWKDYHDFFHVVWR
HDFK6$3LQVWDOODWLRQ
• SIDSUDO
ƒ ([HFXWHFRPPDQGVXQGHUWKHDXWKRULW\DQGHQYLURQPHQWRIWKHVSHFLILHG
6$3DGPLQLVWUDWLYHXVHUSURILOH
3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-16. Secure Administrator for SAP on IBM i

The Secure Administrator for SAP tool provides a means to grant a set of named users the
capability to execute commands under the authority of <SID>ADM (where <SID> is the
three-character identifier of a chosen SAP software installation) while preserving the audit trail that
allows an auditor to trace which user has executed what commands under this higher authority.
Secure Administrator for SAP avoids the problem of a user profile with broad access authority that
must be used by multiple users to administer an SAP application from the IBM i command line. This
is an audit exposure because the user who was operating under the authority of this “super user”
cannot be traced.
Secure Administrator for SAP can be deployed directly into SAP client environments, with
consultant services assistance to ensure proper deployment and management.

© Copyright IBM Corp. 1995, 2017 18-18


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

,%0L6HFXULW\6HUYLFHVIURP,%06\VWHPV/DE6HUYLFHV
 ,%0L6HFXULW\$VVHVVPHQW
ƒ $QH[SHULHQFHG,%0LFRQVXOWDQWZLOOFROOHFWDQGDQDO\]H )RUPRUHLQIRUPDWLRQRQ3RZHU6&7RROV
GDWDXVLQJ3RZHU6&7RROVIRU,%0L7KHHQJDJHPHQW
UHVXOWVLQDFRPSUHKHQVLYHUHSRUWZLWKILQGLQJVDQG IRU,%0LRIIHULQJVDQGVHUYLFHVFRQWDFW
UHFRPPHQGDWLRQVIRULPSURYHGFRPSOLDQFHDQGVHFXULW\
UHPHGLDWLRQ &DURO:DUG
FSZDUG#XVLEPFRP
 ,%0L6LQJOH6LJQ2Q,PSOHPHQWDWLRQ
ƒ 662LPSURYHVHQGXVHUSURGXFWLYLW\DQGVDYHVKHOS 0LNH*RUGRQ
GHVNFRVWV,QWKLVVHUYLFHVHQJDJHPHQWDQ PJRUGR#XVLEPFRP
H[SHULHQFHG,%0FRQVXOWDQWZLOODGYLVHRQ662RSWLRQV
DQGSURYLGHLPSOHPHQWDWLRQDVVLVWDQFHOHYHUDJLQJWKH 7HUU\)RUG
662VXLWHFRPSRQHQWVRIWKH3RZHU6&7RROVIRU,%0L
WDIRUG#XVLEPFRP
3UDFWLFH/HDGHU6HFXULW\6HUYLFHV
 ,%0L6HFXULW\5HPHGLDWLRQ
ƒ $QH[SHULHQFHG,%0FRQVXOWDQWZLOODGYLVHRQEHVW
SUDFWLFHVWRDGGUHVV,%0LVHFXULW\DQGFRPSOLDQFH
LVVXHV7KHFRQVXOWDQWZLOOSURYLGHUHPHGLDWLRQ
DVVLVWDQFHOHYHUDJLQJWKH3RZHU6&7RROVIRU,%0L

 ,%0L(QFU\SWLRQ6HUYLFHV
ƒ $QH[SHULHQFHG,%0FRQVXOWDQWZLOODGYLVHRQEHVW
SUDFWLFHVWRLPSOHPHQWGDWDHQFU\SWLRQRQ,%0,
OHYHUDJLQJWKH3RZHU6&7RROVIRU,%0L(QFU\SWLRQ6XLWH
DVDSSURSULDWH7DSH(QFU\SWLRQLPSOHPHQWDWLRQ
VHUYLFHVDUHDOVRDYDLODEOH
ZZZLEPFRPV\VWHPVVHUYLFHVODEVHUYLFHV LEPVOV#XVLEPFRP

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-17. IBM i Security Services from IBM Systems Lab Services

The primary services and contact information is covered here. Besides these services, IBM
Systems Lab Services provides custom engagements and tooling as requested.

© Copyright IBM Corp. 1995, 2017 18-19


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

5HYLHZTXHVWLRQV
 7UXHRUIDOVH3RZHU6&WRROVIRULDOORZV\RXWRHDVLHU
LPSOHPHQWVHFXULW\LQ\RXUV\VWHP

 7UXHRUIDOVH8VLQJ3RZHU6&WRROV\RXFDQSUHSDUH
UHSRUWVIRUVHFXULW\DXGLW

 7UXHRUIDOVH7ZR)DFWRU$XWKHQWLFDWLRQJHQHUDWHVKLJKO\
VHFXUH5)&EDVHGRQHWLPHSDVVZRUGV 7273 
HQVXULQJWKDWRQO\SURSHUO\DXWKHQWLFDWHGXVHUVDUH
DXWKRUL]HGDFFHVVWRFULWLFDODSSOLFDWLRQVDQGGDWD

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-18. Review questions

© Copyright IBM Corp. 1995, 2017 18-20


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

5HYLHZDQVZHUV
 7UXH RUIDOVH3RZHU6&WRROVIRULDOORZV\RXWRHDVLHU
LPSOHPHQWVHFXULW\LQ\RXUV\VWHP
7KHDQVZHULVWUXH

 7UXH RUIDOVH8VLQJ3RZHU6&WRROV\RXFDQSUHSDUH
UHSRUWVIRUVHFXULW\DXGLW
7KHDQVZHULVWUXH

 7UXH RUIDOVH7ZR)DFWRU$XWKHQWLFDWLRQJHQHUDWHVKLJKO\
VHFXUH5)&EDVHGRQHWLPHSDVVZRUGV 7273 
HQVXULQJWKDWRQO\SURSHUO\DXWKHQWLFDWHGXVHUVDUH
DXWKRUL]HGDFFHVVWRFULWLFDODSSOLFDWLRQVDQGGDWD
7KHDQVZHULVWUXH

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-19. Review answers

© Copyright IBM Corp. 1995, 2017 18-21


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2
Unit 18. Power SC for i

Uempty

8QLWVXPPDU\
‡ 'HVFULEHH[LVWLQJ3RZHU6&IRULWRROV
‡ 'HVFULEHEHQHILWVRI3RZHU6&IRULWRROV

3RZHU6&IRUL ‹&RS\ULJKW,%0&RUSRUDWLRQ

Figure 18-20. Unit summary

© Copyright IBM Corp. 1995, 2017 18-22


Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Licensed to Deiver Hernandez for class on 3/1/2021
V11.2

backpg

© Copyright International Business Machines Corporation 1995, 2017.

Licensed to Deiver Hernandez for class on 3/1/2021

You might also like