z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZD1105I

z/OS Communications Server: IP Messages Volume 2 (EZB, EZD)
SC27-3655-01

EZD1105I
IKE detected a NAT while initiating a new dynamic tunnel using both tunnel and transport mode IpDataOffers with a non-z/OS peer

Explanation

The Internet Key Exchange (IKE) daemon is attempting to initiate a phase 2 Security Association (SA) for a new dynamic tunnel with a non-z/OS peer. The SA traverses a NAT. Both tunnel-mode and transport-mode IpDataOffers are proposed. If the peer selects a tunnel-mode proposal, interoperability issues might exist with the non-z/OS peer. z/OS® is providing NAT Traversal support for a defined group of configurations where z/OS is running the IKE daemon. See the information about IP security in z/OS Communications Server: IP Configuration Guide for a description of the supported configurations and interoperability considerations.

System action

The SA negotiation continues.

Operator response

If the SA negotiation fails or if data cannot be successfully sent over the SA, contact the system programmer.

System programmer response

If the SA negotiation fails or if data cannot be successfully sent over the SA, see the information about IP security in z/OS Communications Server: IP Configuration Guide to determine if there is an interoperability concern that caused the SA negotiation or data to fail. Contact the remote peer's administrator to understand any interoperability considerations for the non-z/OS platform.

Module

oakley_phaseII.cpp

Procedure name

None.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014