Issue #973
IKEv2 dpd + auto=route + tunnel downtime cause additional CHILD_SAs
Status:
New
Priority:
Normal
Assignee:
-
Category:
-
Affected version:
5.3.0
Resolution:
Description
Hello,
I encountered the following bug:
When an IKEv2 tunnel withdpdaction=restart and auto=route is down
and traffic reaches the host with a matching policy for that tunnel,
additional CHILD_Sas will be spawned the next time the tunnel is established again.
Also, reauthentication events are acted upon. See the attachements "gw1.log" and "gw2.log"
for details. ipsec.conf of the two sides is in the corresponding _ipsec.conf files.
Kind regards,
Noel
Related issues
History
#1 Updated by Noel Kuntze over 8 years ago
- Related to Issue #2260: Number of CHILD_SA for a single connection grows over time added