The IP Security feature in AIX is separately installable and loadable. The file sets that need to be installed are:
The bos.crypto* file sets are located on the ExpansionPacks. For IKE digital signature support, also install the gskit.rte fileset (AIX Version 4) or gskkm.rte (AIX 5.1) from the Expansion Pack.
Once installed, IP Security can be separately loaded for IP Version 4 and IP Version 6, either by using the recommended procedure given in Loading IP Security or by using the mkdev command.
Attention: Loading IP Security enables the filtering function. Before loading, it is important to ensure the correct filter rules are created, or all outside communication might be blocked.
Use SMIT or Web-based System Manager, to automatically load the IP security modules when IP Security is started. Also, SMIT and Web-based System Manager ensure that the kernel extensions and IKE daemons are loaded in the correct order.
If the loading completes successfully, the lsdev command shows the IP Security devices as Available.
lsdev -C -c ipsec ipsec_v4 Available IP Version 4 Security Extension ipsec_v6 Available IP Version 6 Security Extension
Once the IP Security kernel extension has been loaded, tunnels and filters are ready to be configured.