SNA and VTAM basics, and troubleshooting connectivity
SNA is IBM's original networking architecture and VTAM is its z/OS implementation. It still carries 3270 sessions and some application traffic, often over IP today. When something cannot connect, work through the layers in order with a few reliable commands.
Why SNA still matters
Before TCP/IP was common, mainframe networks used SNA (Systems Network Architecture). Many applications were written for it, especially CICS and IMS terminal programs and program-to-program links. Most physical SNA networks have gone, but the concepts remain: every 3270 session, including those arriving through TN3270, is still an SNA session inside z/OS, and some partners still talk SNA, usually carried over IP.
VTAM and its resources
VTAM (Virtual Telecommunications Access Method) is the SNA half of Communications Server and runs as a started task (commonly NET). It manages resources, defined in major nodes (members in VTAM's definition library, VTAMLST) and activated when needed.
| Term | Meaning |
|---|---|
| LU (logical unit) | An end point of a session: a terminal, a printer, or an application |
| Application (APPL) | An LU that represents a program such as a CICS region, IMS or TSO, identified by its APPLID |
| LU type 2 | 3270 display terminals |
| LU 6.2 (APPC) | Program-to-program communication, used for example between CICS regions or with partner systems |
| Session | A connection between two LUs, such as a terminal and CICS |
| Major node | A group of resource definitions activated or deactivated together |
APPN and Enterprise Extender
APPN (Advanced Peer-to-Peer Networking) replaced hand-built SNA routing with dynamic discovery: network nodes find resources and compute routes. HPR (High-Performance Routing) improved it further. Enterprise Extender (EE) carries HPR traffic inside UDP over an IP network, so SNA applications keep working while the network underneath is pure IP. EE uses UDP ports 12000 to 12004, which matters when firewalls are involved.
VTAM commands
D NET,APPLSD NET,ID=CICSPRD1,ED NET,MAJNODESV NET,ACT,ID=nameV NET,INACT,ID=nameVTAM messages begin with IST. TCP/IP stack messages use prefixes beginning with EZ (such as EZA, EZB, EZD and EZZ). Knowing the prefix tells you which half of Communications Server is talking.
Troubleshooting connectivity, layer by layer
- Name: does the host name resolve to the address you expect? A wrong DNS entry looks like a network failure.
- Reachability:
PINGthe address from z/OS and from the client side. No reply may be normal if ICMP is blocked, so do not stop there. - Path:
TRACERTEshows where packets stop. A break outside the mainframe belongs to the network team. - Listener:
NETSTAT CONN(orD TCPIP,,NETSTAT,CONN) shows whether the server is in Listen state on the right port and stack. - Port reservation: a PORT statement may reserve the port for a different job name, so the server cannot bind.
- Security: firewalls, z/OS IP filtering, AT-TLS policy or RACF access to the port can all refuse a connection that otherwise looks healthy.
- SNA side: for 3270 or LU 6.2 problems, check the application with
D NET,ID=applid,Eand whether it accepts logons.
USER ID CONN STATE ZCONSRV 0000004A LISTEN LOCAL SOCKET: ::..9443 FOREIGN SOCKET: ::..0 TN3270A 00000031 LISTEN LOCAL SOCKET: ::..23 FOREIGN SOCKET: ::..0
For deeper problems, network specialists use packet and component traces (the TCP/IP packet trace runs under component trace as SYSTCPDA) and SMF records for connection statistics. These are usually started on request, under change or incident control, because they can affect performance and capture sensitive data.
Common mistakes
Many networks block ICMP. Check the listener with NETSTAT and test the actual port before declaring an outage.
If NETSTAT shows no listener, the problem is on z/OS: the server is down, could not bind, or is on another stack. Read the server's job log.
A TN3270 connection can succeed while the target application is inactive or refusing logons. Check it with D NET,ID=applid,E.
What you will see at work
- Connectivity tickets go faster when you supply the host name, address, port, time, and what PING, TRACERTE and NETSTAT showed.
- CICS and IMS teams still talk about APPLIDs and LU 6.2 links daily, even in IP-only networks.
- Firewall requests for Enterprise Extender must include its UDP ports, which surprises teams that only think in TCP.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.