IBM Support

Using stack default IPSEC FilterRules in a CINET environment

Troubleshooting


Problem

IPSec using the TCPIP profile default FilterRules to allow all traffic was enabled in the following environment. Multiple TCPIP stacks were active in a CINET enviroment, named in this context TCPIPA and TCPIPB. TCPIPA had network connectivity via OSA devices, and TCPIPB communicated to the network via a SAMEHOST/HiperSockets link via TCPIPA. TCPIPA was enabled for IPSec only using the default profile IPSec definitions to allow all traffic using the following TCPIP profile definitions: IPSEC IPSECRule * * NOLOG PROTO * ENDIPSEC When TCPIPA was enabled using these filterRules, TCPIPB lost all connectivity to the network via TCPIPA.

Cause

The IPSECRule defaults to ROUTING LOCAL.

Resolving The Problem

Code ROUTING EITHER in the IPSECRule statement.

[{"Product":{"code":"SSSN3L","label":"z\/OS Communications Server"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"All","Platform":[{"code":"PF035","label":"z\/OS"}],"Version":"2.1;2.2;2.3","Edition":"Enterprise","Line of Business":{"code":"LOB35","label":"Mainframe SW"}}]

Document Information

Modified date:
15 June 2018

UID

swg21469136