Db2 for z/OS & Db2ZAI

 View Only
Expand all | Collapse all

DSNL511I -dsnx DSNLIENO TCP/IP CONVERSATION FAILED, what triggers this message?

  • 1.  DSNL511I -dsnx DSNLIENO TCP/IP CONVERSATION FAILED, what triggers this message?

    Posted Fri December 13, 2024 11:04 AM

    Hello, 

    what is triggering the DSNL511I messages at the masters?

    What is the event that make them appear, sometimes it seems to be every X minutes, following a pattern, but not always.

    I would like to review from where does Db2 take these Locations and try to contact them. Or is it something contacting it? Is there a way or a place to know it?

    Thanks,

    20.03.58 STC04401  DSNL511I  -dsnx DSNLIENO TCP/IP CONVERSATION FAILED  052    
       052                        TO LOCATION ::FFFF:1x1.xx6.20x.xx9                
       052                        IPADDR=::FFFF:1xx.3x.xx3.1x9 PORT=55555          
       052                        SOCKET=RECV RETURN CODE=1121 REASON CODE=744A733D
    21.53.40 STC04401  DSNL511I  -dsnx DSNLIENO TCP/IP CONVERSATION FAILED  328    
       328                        TO LOCATION ::FFFF:1x.xx0.x6.1xx                 
       328                        IPADDR=::FFFF:1x.xx0.x6.1xx PORT=99999           
       328                        SOCKET=RECV RETURN CODE=1127 REASON CODE=769E0291



    ------------------------------
    Soledad Martinez
    Volkswagen Group Services
    Salinas - Asturias
    ------------------------------


  • 2.  RE: DSNL511I -dsnx DSNLIENO TCP/IP CONVERSATION FAILED, what triggers this message?

    Posted Mon December 16, 2024 01:38 AM

    Hello ,

    Looking at messages you are seeing at the console , could find a APAR PH55511 which describes the scenario.

    Check this , if this applies to your Db2 and AT-TLS policy.

    https://www.ibm.com/support/pages/apar/PH55511

    Regards,

    Manoj K Jadwani



    ------------------------------
    Manoj Jadwani
    Product Manager
    BMC Software
    ------------------------------



  • 3.  RE: DSNL511I -dsnx DSNLIENO TCP/IP CONVERSATION FAILED, what triggers this message?

    Posted Mon December 16, 2024 01:49 AM
    Edited by Diego Cardalliaguet Mon December 16, 2024 01:51 AM

    Hi, 

    It looks like the remote client has reset the connection

    If you look at the first message with RETURN CODE: 1121, it seems clear. What I don't find is the reason code  

    The message after it with RETURN CODE: 1127 which seems to be a long time after the first one is a connection timeout and looks like a complete different IP address. It doesn't look like related events. 

    That's all we can find with this information. It could be the APAR stated by Manoj. 

    Hope it helps. 

    D.



    ------------------------------
    Diego Cardalliaguet
    IBM Data&AI zStack Leader for EMEA
    IBM
    ------------------------------



  • 4.  RE: DSNL511I -dsnx DSNLIENO TCP/IP CONVERSATION FAILED, what triggers this message?

    Posted Mon December 16, 2024 03:46 AM

    Hello Manoj, Diego, 

    thanks a lot for your replies.

    I showed the APAR to one of my colleagues at Networks Team, and he told me that this doesn't apply to us.

    At our installation the authentification is done by the server (handshakerole), so as ClientAuth Type we have the default ("Required")

    The messages I posted were just an example, they are from different locations yes, sorry for not making that clear. 

    We have others, similar but with different reason codes, for example, we also have: 77B17343 and 77B77221 RCs.

    Thanks!

    ClientAuthType

    Specifies the type of client certificate validation to be performed for connections in this AT-TLS environment. Client certificates are requested only if HandshakeRole is set to ServerWithClientAuth. Valid values are:

    PassThru

    Bypasses client certificate validation.

    Full

    Performs client certificate validation if the client presents a certificate.

    Required

    Requires the client to present a certificate and performs client certificate validation. This is the default.

    SAFCheck

    Requires the client to present a certificate, performs client certificate validation and requires the client certificate to have an associated user ID defined to the security product.



    ------------------------------
    Soledad Martinez
    Volkswagen Group Services
    Salinas - Asturias
    ------------------------------