requesting the same virtual IP on reauthentication
This commit is contained in:
+54
-49
@@ -1151,6 +1151,55 @@ static void set_other_id(private_ike_sa_t *this, identification_t *other)
|
|||||||
this->other_id = other;
|
this->other_id = other;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.set_virtual_ip
|
||||||
|
*/
|
||||||
|
static void set_virtual_ip(private_ike_sa_t *this, bool local, host_t *ip)
|
||||||
|
{
|
||||||
|
if (local)
|
||||||
|
{
|
||||||
|
DBG1(DBG_IKE, "installing new virtual IP %H", ip);
|
||||||
|
if (this->my_virtual_ip)
|
||||||
|
{
|
||||||
|
DBG1(DBG_IKE, "removing old virtual IP %H", this->my_virtual_ip);
|
||||||
|
charon->kernel_interface->del_ip(charon->kernel_interface,
|
||||||
|
this->my_virtual_ip,
|
||||||
|
this->my_host);
|
||||||
|
this->my_virtual_ip->destroy(this->my_virtual_ip);
|
||||||
|
}
|
||||||
|
if (charon->kernel_interface->add_ip(charon->kernel_interface, ip,
|
||||||
|
this->my_host) == SUCCESS)
|
||||||
|
{
|
||||||
|
this->my_virtual_ip = ip->clone(ip);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
DBG1(DBG_IKE, "installing virtual IP %H failed", ip);
|
||||||
|
this->my_virtual_ip = NULL;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
DESTROY_IF(this->other_virtual_ip);
|
||||||
|
this->other_virtual_ip = ip->clone(ip);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Implementation of ike_sa_t.get_virtual_ip
|
||||||
|
*/
|
||||||
|
static host_t* get_virtual_ip(private_ike_sa_t *this, bool local)
|
||||||
|
{
|
||||||
|
if (local)
|
||||||
|
{
|
||||||
|
return this->my_virtual_ip;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
return this->other_virtual_ip;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.derive_keys.
|
* Implementation of ike_sa_t.derive_keys.
|
||||||
*/
|
*/
|
||||||
@@ -1494,6 +1543,11 @@ static void reestablish(private_ike_sa_t *this)
|
|||||||
set_peer_cfg(other, this->peer_cfg);
|
set_peer_cfg(other, this->peer_cfg);
|
||||||
other->other_host->destroy(other->other_host);
|
other->other_host->destroy(other->other_host);
|
||||||
other->other_host = this->other_host->clone(this->other_host);
|
other->other_host = this->other_host->clone(this->other_host);
|
||||||
|
if (this->my_virtual_ip)
|
||||||
|
{
|
||||||
|
/* if we already have a virtual IP, we reuse it */
|
||||||
|
set_virtual_ip(other, TRUE, this->my_virtual_ip);
|
||||||
|
}
|
||||||
|
|
||||||
if (this->state == IKE_ESTABLISHED)
|
if (this->state == IKE_ESTABLISHED)
|
||||||
{
|
{
|
||||||
@@ -1619,55 +1673,6 @@ static void enable_natt(private_ike_sa_t *this, bool local)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.set_virtual_ip
|
|
||||||
*/
|
|
||||||
static void set_virtual_ip(private_ike_sa_t *this, bool local, host_t *ip)
|
|
||||||
{
|
|
||||||
if (local)
|
|
||||||
{
|
|
||||||
DBG1(DBG_IKE, "installing new virtual IP %H", ip);
|
|
||||||
if (this->my_virtual_ip)
|
|
||||||
{
|
|
||||||
DBG1(DBG_IKE, "removing old virtual IP %H", this->my_virtual_ip);
|
|
||||||
charon->kernel_interface->del_ip(charon->kernel_interface,
|
|
||||||
this->my_virtual_ip,
|
|
||||||
this->my_host);
|
|
||||||
this->my_virtual_ip->destroy(this->my_virtual_ip);
|
|
||||||
}
|
|
||||||
if (charon->kernel_interface->add_ip(charon->kernel_interface, ip,
|
|
||||||
this->my_host) == SUCCESS)
|
|
||||||
{
|
|
||||||
this->my_virtual_ip = ip->clone(ip);
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
DBG1(DBG_IKE, "installing virtual IP %H failed", ip);
|
|
||||||
this->my_virtual_ip = NULL;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
DESTROY_IF(this->other_virtual_ip);
|
|
||||||
this->other_virtual_ip = ip->clone(ip);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Implementation of ike_sa_t.get_virtual_ip
|
|
||||||
*/
|
|
||||||
static host_t* get_virtual_ip(private_ike_sa_t *this, bool local)
|
|
||||||
{
|
|
||||||
if (local)
|
|
||||||
{
|
|
||||||
return this->my_virtual_ip;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
return this->other_virtual_ip;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Implementation of ike_sa_t.remove_dns_server
|
* Implementation of ike_sa_t.remove_dns_server
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -261,8 +261,20 @@ static status_t build_i(private_ike_config_t *this, message_t *message)
|
|||||||
if (message->get_exchange_type(message) == IKE_AUTH &&
|
if (message->get_exchange_type(message) == IKE_AUTH &&
|
||||||
message->get_payload(message, ID_INITIATOR))
|
message->get_payload(message, ID_INITIATOR))
|
||||||
{
|
{
|
||||||
peer_cfg_t *config = this->ike_sa->get_peer_cfg(this->ike_sa);
|
peer_cfg_t *config;
|
||||||
this->virtual_ip = config->get_virtual_ip(config, NULL);
|
host_t *vip;
|
||||||
|
|
||||||
|
/* reuse virtual IP if we already have one */
|
||||||
|
vip = this->ike_sa->get_virtual_ip(this->ike_sa, TRUE);
|
||||||
|
if (vip)
|
||||||
|
{
|
||||||
|
this->virtual_ip = vip->clone(vip);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
config = this->ike_sa->get_peer_cfg(this->ike_sa);
|
||||||
|
this->virtual_ip = config->get_virtual_ip(config, NULL);
|
||||||
|
}
|
||||||
|
|
||||||
build_payloads(this, message, CFG_REQUEST);
|
build_payloads(this, message, CFG_REQUEST);
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user