Rabia, this is my understanding of how it should work, although I haven’t tested it:
You would need to relate the security to a user (or group). Thus for TCP/IP, you would have the rules:
- allow user(rpcuser) resource(100.100.100.100) read
- deny user() resource(100.100.100.100)
-
allow user() resource(*) read
(the specific syntax for the “allow” “deny” will depend on your SAF product)
User “rpcuser” would be given access authority (read) to the class/server/service, same as you would do without TCP/IP security. If “rpcuser” is the only user allowed to that class/server/service and only that user is allowed to use that tcp/ip address, you should be tightened down.
Let me know how it goes!
Douglas Kelly,
Principal Consultant
Software AG, Inc
Sacramento, California
#EntireX#webMethods#Mainframe-Integration