AES-GCM

When the AES-GCM combined-mode encryption and authentication algorithm is negotiated for an SA, decapsulation of all packets over that SA occurs on the distributing stack, and the decapsulated packets are forwarded to the target stack. In NAT traversal configurations, the target stack that is at a V1R12 or earlier release level expects the forwarded packets to be UDP-encapsulated packets. If a V1R12 target system is to participate in the workload distribution of traffic over a UDP-encapsulated mode SA that is using the AES-GCM algorithm, then the V1R12 PTF for APAR PM29788 must be applied because all the received packets are decapsulated on the distributing stack. APAR PM29788 enables a target stack to handle decapsulated packets from the distributing stack that were received over a UDP-encapsulated mode SA.