Previous topic |
Next topic |
Contents |
Contact z/OS |
Library |
PDF
EZD1151I z/OS Communications Server: IP Messages Volume 2 (EZB, EZD) SC27-3655-01 |
|
EZD1151I KeyExchangeAction actionname prevents
the creation of a dynamic tunnel with source data endpoint specification source_ip and
destination data endpoint specification dest_ip ExplanationDynamic tunnel activation is denied as a result of a configured source or destination data IP address constraint. See the information about the KeyExchangeAction statement in z/OS Communications Server: IP Configuration Reference for an explanation of data address constraints. In
the message text:
System actionThe dynamic tunnel activation fails; IKE daemon processing continues. Operator responseContact the system programmer. System programmer responseIf the tunnel activation should be
permitted, then do one of the following to correct the configuration.
If the tunnel activation should not be permitted, then determine whether the tunnel was activated locally or remotely. If the source_ip value matches the IP address value in the Local IPSec Client ID information from the Security Association (SA) Context Information that was output with the message, then the tunnel was activated locally. Otherwise, the tunnel was activated remotely. If the tunnel was activated locally but should not be permitted, then correct the local IpFilterPolicy statement to block the activation. See the information about Policy Agent and policy applications in z/OS Communications Server: IP Configuration Reference for more information about configuring the IpFilterPolicy statement. If the tunnel was activated remotely but should not be permitted, then contact the owner of the remote system to request that the activation be blocked on that system. User responseNot applicable. Problem determinationNot applicable. Sourcez/OS Communications Server TCP/IP: IKE daemon Modulepolicymgr.cpp Routing codeNot applicable for syslog message. Descriptor codeNot applicable for syslog message. AutomationThis message goes to the syslog. Example
|
Copyright IBM Corporation 1990, 2014
|