Sysplex-wide security associations for IPv6

z/OS® V2R1 Communications Server provides the support for IPv6 in a sysplex-wide security association (SWSA) environment. Sysplex distribution provides better workload balancing because it performs the following actions: SWSA adds to the sysplex function, distributing the IPSec cryptographic processing for an IPSec security association (SA) among systems in a sysplex environment. SWSA also allows workloads with IPSec-protected traffic to use the dynamic virtual IP address (DVIPA) takeover function. You can associate IPSec-protected workloads with DVIPAs that can be recovered by other systems in the case of a failure or planned takeover. IPSec SAs are automatically reactivated on another system in the sysplex when a DVIPA takeover occurs.
Restrictions:
  • All target systems must be at V2R1 or later to distribute workload for IPv6 traffic that is protected by an SA.
  • The backup TCP/IP stack must be on a system that is V2R1 or later to take over IPSec-protected workloads with IPv6 DVIPAs.

Using the support for IPv6 in a sysplex-wide security association (SWSA) environment

To use the support for IPv6 in a SWSA environment, perform the appropriate tasks in Table 1.
Table 1. Sysplex-wide security associations for IPv6
Task Reference
Learn about SWSA. Sysplex-wide security associations and IP security in z/OS Communications Server: IP Configuration Guide
Configure IPCONFIG6 IPSECURITY and IPSEC DVIPSEC in the distributor stack TCP/IP profile to enable IPv6 SWSA. IPCONFIG6 statement and IPSEC statement in z/OS Communications Server: IP Configuration Reference
Use the ipsec command to display whether SWSA is enabled. The ipsec command general report concepts in z/OS Communications Server: IP System Administrator's Commands