Mainframe Path Start learning free
Applied11 min readLesson 3 of 3

SNA and VTAM basics, and troubleshooting connectivity

SNA is IBM's original networking architecture and VTAM is its z/OS implementation. It still carries 3270 sessions and some application traffic, often over IP today. When something cannot connect, work through the layers in order with a few reliable commands.

Why SNA still matters

Before TCP/IP was common, mainframe networks used SNA (Systems Network Architecture). Many applications were written for it, especially CICS and IMS terminal programs and program-to-program links. Most physical SNA networks have gone, but the concepts remain: every 3270 session, including those arriving through TN3270, is still an SNA session inside z/OS, and some partners still talk SNA, usually carried over IP.

VTAM and its resources

VTAM (Virtual Telecommunications Access Method) is the SNA half of Communications Server and runs as a started task (commonly NET). It manages resources, defined in major nodes (members in VTAM's definition library, VTAMLST) and activated when needed.

TermMeaning
LU (logical unit)An end point of a session: a terminal, a printer, or an application
Application (APPL)An LU that represents a program such as a CICS region, IMS or TSO, identified by its APPLID
LU type 23270 display terminals
LU 6.2 (APPC)Program-to-program communication, used for example between CICS regions or with partner systems
SessionA connection between two LUs, such as a terminal and CICS
Major nodeA group of resource definitions activated or deactivated together

APPN and Enterprise Extender

APPN (Advanced Peer-to-Peer Networking) replaced hand-built SNA routing with dynamic discovery: network nodes find resources and compute routes. HPR (High-Performance Routing) improved it further. Enterprise Extender (EE) carries HPR traffic inside UDP over an IP network, so SNA applications keep working while the network underneath is pure IP. EE uses UDP ports 12000 to 12004, which matters when firewalls are involved.

SNA application traffic over an IP network with Enterprise Extender
SNA applicatione.g. LU 6.2 in CICS
VTAMAPPN and HPR
Enterprise ExtenderUDP 12000 to 12004
IP networkrouters, firewalls
Partner VTAMor SNA gateway

VTAM commands

Everyday VTAM display and control commandsWhat it means
D NET,APPLS
Lists application LUs and their status
D NET,ID=CICSPRD1,E
Detailed status of one resource, including sessions
D NET,MAJNODES
Lists active major nodes
V NET,ACT,ID=name
Activates a resource or major node (change-controlled in production)
V NET,INACT,ID=name
Deactivates a resource or major node

VTAM messages begin with IST. TCP/IP stack messages use prefixes beginning with EZ (such as EZA, EZB, EZD and EZZ). Knowing the prefix tells you which half of Communications Server is talking.

Troubleshooting connectivity, layer by layer

  1. Name: does the host name resolve to the address you expect? A wrong DNS entry looks like a network failure.
  2. Reachability: PING the address from z/OS and from the client side. No reply may be normal if ICMP is blocked, so do not stop there.
  3. Path: TRACERTE shows where packets stop. A break outside the mainframe belongs to the network team.
  4. Listener: NETSTAT CONN (or D TCPIP,,NETSTAT,CONN) shows whether the server is in Listen state on the right port and stack.
  5. Port reservation: a PORT statement may reserve the port for a different job name, so the server cannot bind.
  6. Security: firewalls, z/OS IP filtering, AT-TLS policy or RACF access to the port can all refuse a connection that otherwise looks healthy.
  7. SNA side: for 3270 or LU 6.2 problems, check the application with D NET,ID=applid,E and whether it accepts logons.
NETSTAT CONN showing a listener (illustrative)
USER ID  CONN     STATE
ZCONSRV  0000004A LISTEN
  LOCAL SOCKET:   ::..9443
  FOREIGN SOCKET: ::..0
TN3270A  00000031 LISTEN
  LOCAL SOCKET:   ::..23
  FOREIGN SOCKET: ::..0

For deeper problems, network specialists use packet and component traces (the TCP/IP packet trace runs under component trace as SYSTCPDA) and SMF records for connection statistics. These are usually started on request, under change or incident control, because they can affect performance and capture sensitive data.

Common mistakes

Concluding the host is down because PING fails

Many networks block ICMP. Check the listener with NETSTAT and test the actual port before declaring an outage.

Looking only at the network when the server is not listening

If NETSTAT shows no listener, the problem is on z/OS: the server is down, could not bind, or is on another stack. Read the server's job log.

Forgetting the SNA layer for 3270 problems

A TN3270 connection can succeed while the target application is inactive or refusing logons. Check it with D NET,ID=applid,E.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← VIPA, Sysplex Distributor and the TN3270 serverBack to z/OS networking: TCP/IP and SNA