IBM Support

Guardium ATAP Configuration with Multiple Database Instances

Question & Answer


Question

You have more than one database instance running on a server and you want to use ATAP.  ATAP is configured to intercept unencrypted traffic by providing database environment information.  How should you plan to configure and activate ATAP in this scenario?

Cause

The db_instance parameter is a name for each ATAP configuration on the server.  It does not need to be the actual database instance name but using it can be helpful to distinguish the ATAP configurations if there is more than one.  
One of the parameters, db_home, is the path where the database instance is installed. 

Answer

For a multi-instance configuration where a single executable is used for all of the instances, guardctl activate should only be done once as it will be effective for all instances.  If all instances share the same database executable, ATAP will have the database re-linked after the initial activate.  

If the database instances do not share the same home directory, then you must activate ATAP for each instance.  

If you have one instance that has encrypted traffic and one that does not, you do not need to configure them both since ATAP is activated on a particular database executable.  

 

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSCJM6A","label":"IBM Security Guardium S-TAP for IMS on z\/OS"},"ARM Category":[{"code":"a8m0z0000001gcKAAQ","label":"A-TAP"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Product Synonym

Guardium; S-TAP; STAP

Document Information

Modified date:
13 November 2020

UID

ibm16366685