The IKE daemon obtains configuration information from two sources.
The IKE daemon configuration file contains the IkeConfig statement. Parameters on the IkeConfig statement are global IKE daemon operational parameters. For details on the IKE daemon configuration file and the IkeConfig statement, see z/OS Communications Server: IP Configuration Reference.
The IKE daemon configuration file is read when the IKE daemon initializes and can be reread dynamically. For more information, see Controlling the IKE daemon.
IP security policy includes dynamic IPSec tunnel configuration information required by the IKE daemon. The IKE daemon obtains IP security policy from the Policy Agent. The IKE daemon obtains IP security policy when connecting to the Policy Agent and whenever the Policy Agent informs the IKE daemon of a change in IP security policy. The IKE daemon connects only to stacks configured with IPCONFIG IPSECURITY, if there is an IP security policy defined for a stack. For details on configuring IP security policy, see Configuring specific security models.