Configuring secure IP tunnels between the mover service partitions on the source and destination servers
With Virtual I/O Server (VIOS) 2.1.2.0, or later, you can configure secure IP tunnels between the mover service partitions (MSPs) on the source and destination servers. However, when both the source and destination servers are using the Virtual I/O Server 2.2.2.0, or later, the tunnels are created automatically depending on the security profile applied on the source VIOS.
Before you begin
Consider enabling secure IP tunnels between the MSP on the source server and the MSP on the
destination server. For example, you might want to enable secure IP tunnels when the source and
destination servers are not on a trusted network. Secure IP tunnels encrypt the partition state data
that the MSP on the source server sends to the MSP on the destination server during active partition mobility.
Note: If the source server and target server are
at firmware level FW920, or later, the PowerVM Hypervisor automatically encrypts the data that is
transmitted by the MSPs so that you might not enable secure IP tunnels.
Before you start, complete the following tasks:
- Verify that the MSPs on the source and destination servers are at version 2.1.2.0, or later, by using the ioslevel command.
- Obtain the IP address of the MSP on the source server.
- Obtain the IP address of the MSP on the destination server.
- Obtain the preshared authentication key for the source and destination MSPs.