A refresh or activation request could not be completed because of an error with the Security Association negotiation. The error might be a problem with the configuration or an internal error with the IKE daemon.
The ipsec command processing ends.
Look at the syslog daemon syslog file that covers the time of the command failure. The negotiation failure might be caused by a configuration problem or by an internal error. Messages that see policy might indicate that the request failed because of the policy configuration. See the information about Policy Agent and policy applications in z/OS Communications Server: IP Configuration Reference for more information about configuring policy. If the failure is caused by an IKE daemon internal error, contact IBM® software support services and provide a syslog daemon syslog file that covers the time of the command failure. If available, provide a CTRACE for component SYSTCPIK. See the information about diagnosing IKE daemon problems in z/OS Communications Server: IP Diagnosis Guide for more information about CTRACE.
Contact the system programmer.
ipsec.c
None.