IBM Support

IZ69898: FIRST PACKET DENIED WITH ONDEMAND IPSEC TUNNEL APPLIES TO AIX 5300-09

A fix is available

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • When an IPSec tunnel is set up with OnDemand set to yes,
    the first packet sent is denied.  This often cases the
    application to receive back an error and causes the
    application to fail.
    
    An example of this is with ftp.  For example with ftp
    a user will see the message:
    
    ftp: connect: The file access permissions do not allow
    the specified action.
    

Local fix

Problem summary

  • "ftp" application fails with ODT tunnels
    

Problem conclusion

  • Condition is added to check the state of Tunnels. If it is in
    dormant state, then tunnels are activated.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IZ69898

  • Reported component name

    AIX 5.3

  • Reported component ID

    5765G0300

  • Reported release

    530

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Submitted date

    2010-02-09

  • Closed date

    2010-04-29

  • Last modified date

    2013-03-28

Fix information

  • Fixed component name

    AIX 5.3

  • Fixed component ID

    5765G0300

Applicable component levels

  • R530 PSY U837786

       UP10/09/21 I 1000

PTF to Fileset Mapping

[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11P","label":"APARs - AIX 5.3 environment"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"530","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
28 March 2013