VIPA, Sysplex Distributor and the TN3270 server
A virtual IP address (VIPA) is not tied to one adapter, so an application stays reachable if a card fails. Dynamic VIPA and Sysplex Distributor extend that across a sysplex. The TN3270 server is how almost everyone reaches green screens today.
Why a virtual IP address
A normal IP address belongs to one interface. If that OSA card or its cable fails, the address disappears with it. A VIPA (Virtual IP Address) belongs to the stack itself, not to any adapter. As long as at least one interface still works and routing knows how to reach the VIPA, clients keep connecting. This is why important z/OS services are usually published on a VIPA.
Dynamic VIPA
A static VIPA protects against adapter failure but stays on one system. A dynamic VIPA (DVIPA) can move between stacks in a sysplex. Each DVIPA has an owning stack and one or more backup stacks; if the owner fails, a backup takes over the address. Some DVIPAs are tied to an application: the address becomes active on whichever system the application starts on. All of this is defined in the VIPADYNAMIC section of the profile.
Sysplex Distributor
Sysplex Distributor goes a step further. One stack owns a distributed DVIPA and receives new connections, then spreads them across target stacks where the same application is running. It can use WLM information to favour systems with spare capacity or servers meeting their goals. Clients see a single address; the sysplex behaves like one server.
The TN3270 server
Users no longer have real 3270 terminals. They run a 3270 emulator on a PC, which speaks the TN3270E protocol over TCP/IP to the TN3270 server in Communications Server. The server converts each connection into an SNA session with VTAM, using a VTAM LU, so applications such as TSO, CICS and IMS see an ordinary 3270 terminal.
- The server is configured with TELNETPARMS (port, security, timers) and BEGINVTAM sections (which LUs to use, default application, mapping rules).
- It usually runs in its own address space, so it can be restarted without touching the TCP/IP stack.
- LUs used by the server are defined to VTAM as application definitions, typically with names drawn from a pattern.
- Secure connections use TLS, configured either in the server or through AT-TLS policy. Port 992 is the usual secure port, but sites choose their own.
- The server can show a logon screen (often an Unformatted System Services table, which has nothing to do with Unix System Services) or send users straight to one application.
TELNETPARMS PORT 23 INACTIVE 3600 ENDTELNETPARMS BEGINVTAM PORT 23 DEFAULTLUS TCPM0001..TCPM0500 ENDDEFAULTLUS ALLOWAPPL * ENDVTAM
Exact statement names and options depend on release and site style, so read your own site's configuration before relying on any example.
Common mistakes
If that adapter fails, the service is unreachable even though the application is fine. Publish services on a VIPA.
It distributes new connections. Long-lived connections stay where they started, which matters when one system is restarted.
In VTAM, USS means Unformatted System Services (the logon screen and its table). In z/OS generally it usually means Unix System Services. Context decides.
What you will see at work
- When your emulator session will not connect, the TN3270 server, its port and its LU pool are early suspects.
- Application teams request DVIPAs and ports when deploying new TCP/IP services such as z/OS Connect APIs.
- During planned outages, DVIPA takeover lets one LPAR be shut down while clients keep working on the others.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.