Project

General

Profile

Issue #702

ipsec route mode, Strongswan as responder may result collsion in INIT exchange. and ike

Added by Eric song about 6 years ago. Updated about 6 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
-
Affected version:
5.2.0
Resolution:

Description

stongswan receive an IKE_INIT request when negotiation IKEv2 as responder, strongswan always initiate a new request as responder(when centos power on).
so the first Initiator will found a collsion happened but stongswan have received an initial-contact at the same time, it will delete the ike sa negotiated as initiator.
so strongswan will be only remain 1 ike sa that as responder, but the peer have 2 ike sa, and detected collision, that may delete the ike sa negotiated as initiator,
and send delete to stongswan. so no ike sa will be remain.

History

#2 Updated by Eric song about 6 years ago

complete for tittle :ipsec route mode, Strongswan as responder may result collsion in INIT exchange. and no ike sa maybe be remain.

Also available in: Atom PDF