Identification in a BNA Network

The NW (Network Prefix) BNA commands described in Network Prefix (NW) BNA Commands perform the following functions:

  • Assign identity.

  • Designate valid nodes.

  • Establish security-related checking in a BNA network.

Users can enter these commands from an operator display terminal (ODT). Authorized users can enter them from a remote terminal by using the NW (Network Prefix) system command.

These commands often appear in the NETINIT load file, which is used to initialize the network.

Table 34. Network Prefix (NW) BNA Commands

Command

Function

LOCALIDENTITY

Assign a host its node address with the command. Assign each node a node address that is unique in the network.

The host name and node address are used for identification purposes when a BNA network is configured and when validation is requested.

For information about suggestions for usercode management in a BNA network, refer to the System Software Utilities Operations Reference Manual.

VALIDATE

Validates the authenticity of a host name/node address.

Validation is controlled by the value of the VALIDATE attribute, which is assigned a value with the VALIDATE command.

If validation fails

  • At any level, higher-level communication with the target host is denied.

  • At the router level, the target host does not act as an intermediate node for traffic from the node that failed validation.

Validation can be applied to hosts in general or to neighboring nodes.

ADD

Checks the authenticity of host name/node-address pairs.

  • The ADD CONNECTION command checks for validation at the link level.

  • The ADD NEIGHBOR command checks for validation at the router level.

  • The ADD HOST command checks for validation at the port level. This command makes valid the host name/node address at both the router level and the port level.

If the local host is to act only as a communications conduit for another node, the other node should be granted access only at the link layer and router levels, and the foreign host should not be granted access at the port level.