Hi,

A recent entry in the category of interesting APARs is PK40178 IPSec offload to 
zIIPs.  Bob Rogers talked about this in the z/OS R9 Sysprog Goody Bag at SHARE 
in San Diego.  This is new function for z/OS R9 rolled back to z/OS R8 by this 
APAR.  We don't use IPSec and I expect a lot of other folks handle this 
requirement with off platform firewalls also.  If you do use IPSec installing 
the service and measuring what it can save you seems like a no brainer.  Since 
we don't stand to benefit immediately I expect we will wait for it to roll into 
an RSU update.


IPSec offload to zIIPs
_ z/OS Communications Server IPSec processing to use zIIPs if they
are available
_ Eligible enclave-mode SRB processing will be offloaded:
_ Encryption processing
_ Cryptographic validation of message integrity
_ IPSec header processing
_ All IPSec enclave SRB work is made eligible to run on a zIIP
_ Also planned to be available on z/OS R8 with APAR PK40178
_ Specify GLOBALCONFIG ZIIP IPSECURITY=YES in your
TCPPARMS data set
_ Note: To enable IPSec, specify IPCONFIG IPSECURITY (IPv4) and/or
IPCONFIG6 IPSECURITY (IPv6)


APAR Identifier ...... PK40178      Last Changed ........ 07/08/14
  NEW FUNCTION FOR IPSEC EXPLOITATION OF ZIIP    D/T2094
  
  PTF List:
  Release 180   : UK27062 available 07/08/14 (1000 )
  Release 189   : UK27063 available 07/08/14 (1000 )
 
  ERROR DESCRIPTION:
  NEW FUNCTION APAR to ship IPSEC exploitation of zIIP.

        Best Regards, 

                Sam Knutson, GEICO 
                System z Performance and Availability Management 
                mailto:[EMAIL PROTECTED] 
                (office)  301.986.3574  
            
"Think big, act bold, start simple, grow fast..." 


====================
This email/fax message is for the sole use of the intended
recipient(s) and may contain confidential and privileged information.
Any unauthorized review, use, disclosure or distribution of this
email/fax is prohibited. If you are not the intended recipient, please
destroy all paper and electronic copies of the original message.

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to