Skip to main content

zERT IPSec Summary

This report lists zERT entries and encryption attributes for IPSec connections.

Entries are grouped by local and remote IP address, port and cryptographic attributes.

Report Parameters

ParameterDescription
SystemThe SMF ID of the system that wrote the record.
JobnameLocal job name.
UseridLocal userid.
IP AddressLocal or remote IP address
PortServer port
Exclude LoopbackExclude connections to the loopback address 127.0.0.1 or ::1 from the report.
Enc AlgFilter by tunnel encryption algorithm.
Auth AlgFilter by authentication algorithm.
DH GroupFilter by Diffie-Hellman group.
Pseudo Rand FuncFilter by pseudo-random function.
Sig MethodFilter by certificate signature method.
Cert Enc MethodFilter by certificate encryption method.
Cert Digest AlgFilter by certificate digest algorithm.
Key TypeFilter by certificate key type.
Encap ModeFilter by tunnel encapsulation mode.
Auth ProtocolFilter by message authentication protocol.

Columns

ColumnDescription
SystemThe system that wrote the record.
Server IPIP Address of the server end of the connection.
Client IPIP Address of the client end of the connection.
PortThe server port for the connection, or the starting value of the port range.
IKE ProtocolIKE protocol version.
Local Auth MethodLocal endpoint authentication method.
Remote Auth MethodRemote endpoint authentication method.
Tunnel Auth AlgTunnel authentication algorithm.
Tunnel Enc AlgTunnel encryption algorithm.
Local End PointLocal IP address of tunnel endpoint.
Remote End PointRemote IP address of tunnel endpoint.
EntriesThe number of entries in this grouping.
JobnameThe z/OS job name associated with the socket.
UseridThe z/OS userid associated with the socket.
FromThe start time of the first grouped interval.
ToThe end time of the last grouped interval.
ConnectionsThe count of connections in the group - the end connection count minus start connection count for each interval.
Short ConnectionsThe count of short connections (less than 10 seconds).
Partial ConnectionsThe count of partial connections: connections where the connection existed before or continued to exist after the security session.
Diffie-Hellman GroupDiffie-Hellman group used to generate the keying material for the IKE tunnel.
Pseudo-Random FuncPseudo-random function used for seeding key.
Local Cert Sig MethodLocal IKE certificate signature method.
Local Cert Enc MethodLocal IKE certificate encryption method.
Local Cert Digest AlgLocal IKE certificate digest algorithm.
Local Cert Key TypeLocal IKE certificate key type.
Local Cert Key LenLocal IKE certificate key length.
Remote Cert Sig MethodRemote IKE certificate signature method.
Remote Cert Enc MethodRemote IKE certificate encryption method.
Remote Cert Digest AlgRemote IKE certificate digest algorithm.
Remote Cert Key TypeRemote IKE certificate key type.
Remote Cert Key LenRemote IKE certificate key length.
PFS GroupDiffie-Hellman group used for perfect forward secrecy.
Encapsulation ModeTunnel encapsulation mode.
IPSec Auth ProtocolMessage authentication protocol.
IPSec Auth AlgTunnel authentication algorithm.
IPSec Enc AlgTunnel encryption algorithm.