z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZD1036I

z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
SC27-3655-01

EZD1036I
Phase 2 Security Association for DVIPA dvipa_address is not re-established with remote security endpoint ip_addr

Explanation

The Internet Key Exchange (IKE) daemon detected that the phase 2 Security Association (SA) for the dynamic virtual IP address (DVIPA). was not re-established with its remote security endpoint. An error might have occurred during the phase 2 SA negotiation process.

Additional diagnostic messages that have the same message instance number will be issued to identify the impacted SA. The message instance number precedes the message number in the log output and is used to group related messages from the IKE daemon.

dvipa_address is the dynamic virtual IP address.

ip_addr is the IP address of the remote security endpoint.

System action

The IKE phase 2 SA was not re-established for the DVIPA; IKE daemon processing continues.

Operator response

Check the IKE log for an entry indicating what the phase 2 SA negotiation error might be. Also, try to manually establish a phase 2 SA with the remote security endpoint by issuing the ipsec -y activate command.

See the information about the managing network security in z/OS Communications Server: IP System Administrator's Commands or issue the man ipsec command in a z/OS® UNIX shell to obtain information about the ipsec command syntax and options.

System programmer response

None.

Module

phaseII_sa.cpp

Procedure name

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014