Skip to Main Content
IBM Z Hardware and Operating Systems Ideas Portal


This is the public portal for all IBM Z Hardware and Operating System related offerings. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Future consideration
Workspace z/OS
Created by Guest
Created on Mar 29, 2023
Merged idea
This idea has been merged into another idea. To comment or vote on this idea, please visit ZOS-I-4009 zERT Analyzer - Allow for inverted filters for TCP/EE Endpoints.

zERT - Allow Exclude IPs from Reports Merged

For some Reports like "show unencrypted communications" it would reduce the List if we can exclude some ip addresses. Even the "local IP" 127.0.0.1 should be excludable

The same situation, when server ip and client ip are equal.

Idea priority Medium
  • Guest
    Reply
    |
    Aug 23, 2024
    Duplicate of ZOS-I-4009 (https://ibm-z-hardware-and-operating-systems.ideas.ibm.com/ideas/ZOS-I-4009), but note that the additional aspect of ?server ip = client ip? will be added to the notes for ZOS-I-4009.
  • Guest
    Reply
    |
    Jul 25, 2023
    We closed ZOS-I-515 (zERT Sessions Exclusion) about a year ago as part of a z/OS-wide effort to aggressively reduce the Idea backlog. This Idea (ZOS-I-3630) is indeed a similar Idea and when reviewing it, we decided with the continued customer interest that we should accept it as a candidate ("future consideration").
  • Guest
    Reply
    |
    Jul 19, 2023

    Hello,

    when you refer to https://ibm-z-hardware-and-operating-systems.ideas.ibm.com/ideas/ZOS-I-515 and close this as a duplicate. How can ZOS-I-515 then be in the 'Not under consideration' state and this one here in 'Future consideration'?

  • Guest
    Reply
    |
    Apr 17, 2023

    Hello,

    if i understand ZOS-I-515 correct, they only want a exclude for 127.0.0.1.

    We need three different exclude-Options (or a list of exclude-IPs):
    1) 127.0.0.1, because traffic in the machine seems to be ok - even unprotected.

    2) machine ip to machine ip: Is also localhost, but is not 127.0.0.1
    For example: 192.168.178.10 <any Port> to 192.168.178.10 Port 448
    Is in the same machine, like java-access to a db2-subsystem - or many more examples

    3) a special external machine: we use a security vulnerability scanner. This enginge tries to connect with no - with sslv2 - with sslv3 - with TLS 1.0... Security, testing for bad ciphers and so on.
    And so we have "nonsecure" communication on a port which definitively has only TLS 1.2 and good ciphers.
    But this is for all our opened ports - an a z/OS system has many of them...
    So we also need to exclude in the Report only one really external IP.

    The Monitoring of the "localhost"-connections should still be working. Only the filtering of the report is neccessary.

    Guenter

  • Guest
    Reply
    |
    Apr 7, 2023
    Thanks for submitting this idea. Just want to clarify whether you are looking for this function to be added to the zERT Network Analyzer z/OSMF plugin or if you want it added to the actual zERT monitoring function in the TCP/IP stack.

    If it's the Network Analyzer plugin, please add your vote to https://ibm-z-hardware-and-operating-systems.ideas.ibm.com/ideas/ZOS-I-515 and we will close this Idea as a duplicate of ZOS-I-515. If we do that, we will link this Idea to ZOS-I-515 so the additional detail you have included will be preserved.

    If it is the monitoring function itself, we would not be inclined to add such selectivity to that function for a variety of reasons.