Setting Users who Are Never Disabled by the Firewall Intrusion Detection System

To create and modify the list of users whose accounts your Firewall intrusion detection system must never disable, press the F15 (Shift+F3) key from the Firewall Intrusion Detection System screen (STRFW > 81 > 5).

The Auto-Disable Exceptions screen appears:

                           ​ Auto-Disable Exceptions​                             
                                                                                
 Specify user names or generic* that should NEVER be disabled automatically.​    
                                               ​
 Position:  ​                     
 Type options, press Enter.​                                                     
  ​
 4=Delete​                                                                     
 Opt​ User​       ​ Description​                                                    
   ​  QSNADS    ​  IBM-supplied User Profile                         ​             
 ​
  ​  QSPL      ​  Internal Spool User Profile                       ​             
 ​
  ​  QSPLJOB   ​  Internal Spool User Profile                       ​             
 ​
  ​  QSRV      ​  Service User Profile                              ​             
 ​
  ​  QSRVBAS   ​  Basic Service User Profile                        ​             
 ​
  ​  QSYS      ​  Internal System User Profile                      ​             
 ​
  ​  QTCP      ​  Internal TCP/IP User Profile                      ​             
 ​
  ​  QTFTP     ​  IBM-supplied User Profile                         ​             
 ​
    QTIVOLI   ​  TIVOLI PRODUCTS OWNING PROFILE                    ​             
 ​
    QTIVROOT  ​  TIVOLI ALL OBJECT AUTHORITY PROFILE               ​             
 ​
    QTIVUSER  ​  TIVOLI GENERAL USER PROFILE                       ​             
 ​
  ​  QTSTRQS   ​  Test Request User Profile                         ​             
                                                                  ​
       Bottom​ 
 Users defined in the Auto-Disable exception list, are considered excluded.​     
 F3=Exit    F6=Add new    F12=Cancel​                                            
                                                                                
                                                                                

The body of the screen lists users whose accounts are never disabled by intrusion detection systems, even if Firewall rules say to disable the user.

Each line shows the User name and a free form Description of the account.

Some users cannot be removed from the list. Their User names appear in purple.

For accounts that can be removed from the list, the user name appears in green, preceded by an Opt field.

To remove one of these accounts from the list, enter 4 in the Opt field for the account. The account is removed from the list without prompting for confirmation, and the display returns to the top of the list.

To add accounts to the list, press the F6 key. The Add Users to Exception List screen appears, with a column of blank fields in which you can enter user names. For a list of all users from which you can select names, press the F7 key within that screen. The Apply to Selected Users window appears, in which you can select names by entering 1 in the Sel field for that user and pressing Enter.