AES-GCM and AES-GMAC in FIPS 140 mode

Security Associations (SAs) that are using the AES-GCM or AES-GMAC algorithms in FIPS 140 mode are not distributed when the distributing stack is at a V1R12 level. Connections over these SAs are handled on the distributing stack.

SAs that are using the AES-GCM or AES-GMAC algorithms in FIPS 140 mode can be distributed when the distributor is at a V1R13 or later level. However, the distributing stack distributes these SAs only to targets that are at a V1R12 level or later. Connection requests over these SAs are distributed only to target stacks that are at a V1R12 or later level. To ensure that the workload is distributed correctly, all target stacks should be at a V1R12 or later level.