Force port update as responder when initiator switches to 4500 in IKE_AUTH

This commit is contained in:
Martin Willi
2011-01-12 14:37:15 +01:00
parent 8ba805f4db
commit 2082417df3
4 changed files with 7 additions and 6 deletions
@@ -71,7 +71,7 @@ static void execute(private_update_sa_job_t *this)
if (ike_sa->has_condition(ike_sa, COND_NAT_THERE) && if (ike_sa->has_condition(ike_sa, COND_NAT_THERE) &&
!ike_sa->has_condition(ike_sa, COND_NAT_HERE)) !ike_sa->has_condition(ike_sa, COND_NAT_HERE))
{ {
ike_sa->update_hosts(ike_sa, NULL, this->new); ike_sa->update_hosts(ike_sa, NULL, this->new, FALSE);
} }
charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa); charon->ike_sa_manager->checkin(charon->ike_sa_manager, ike_sa);
} }
+2 -2
View File
@@ -825,7 +825,7 @@ METHOD(ike_sa_t, float_ports, void,
} }
METHOD(ike_sa_t, update_hosts, void, METHOD(ike_sa_t, update_hosts, void,
private_ike_sa_t *this, host_t *me, host_t *other) private_ike_sa_t *this, host_t *me, host_t *other, bool force)
{ {
bool update = FALSE; bool update = FALSE;
@@ -858,7 +858,7 @@ METHOD(ike_sa_t, update_hosts, void,
if (!other->equals(other, this->other_host)) if (!other->equals(other, this->other_host))
{ {
/* update others adress if we are NOT NATed */ /* update others adress if we are NOT NATed */
if (!has_condition(this, COND_NAT_HERE)) if (force || !has_condition(this, COND_NAT_HERE))
{ {
set_other_host(this, other->clone(other)); set_other_host(this, other->clone(other));
update = TRUE; update = TRUE;
+2 -1
View File
@@ -343,8 +343,9 @@ struct ike_sa_t {
* *
* @param me new local host address, or NULL * @param me new local host address, or NULL
* @param other new remote host address, or NULL * @param other new remote host address, or NULL
* @param force force update
*/ */
void (*update_hosts)(ike_sa_t *this, host_t *me, host_t *other); void (*update_hosts)(ike_sa_t *this, host_t *me, host_t *other, bool force);
/** /**
* Get the own identification. * Get the own identification.
+2 -2
View File
@@ -897,7 +897,7 @@ METHOD(task_manager_t, process_message, status_t,
{ /* only do host updates based on verified messages */ { /* only do host updates based on verified messages */
if (!this->ike_sa->supports_extension(this->ike_sa, EXT_MOBIKE)) if (!this->ike_sa->supports_extension(this->ike_sa, EXT_MOBIKE))
{ /* with MOBIKE, we do no implicit updates */ { /* with MOBIKE, we do no implicit updates */
this->ike_sa->update_hosts(this->ike_sa, me, other); this->ike_sa->update_hosts(this->ike_sa, me, other, mid == 1);
} }
} }
charon->bus->message(charon->bus, msg, TRUE); charon->bus->message(charon->bus, msg, TRUE);
@@ -942,7 +942,7 @@ METHOD(task_manager_t, process_message, status_t,
{ /* only do host updates based on verified messages */ { /* only do host updates based on verified messages */
if (!this->ike_sa->supports_extension(this->ike_sa, EXT_MOBIKE)) if (!this->ike_sa->supports_extension(this->ike_sa, EXT_MOBIKE))
{ /* with MOBIKE, we do no implicit updates */ { /* with MOBIKE, we do no implicit updates */
this->ike_sa->update_hosts(this->ike_sa, me, other); this->ike_sa->update_hosts(this->ike_sa, me, other, FALSE);
} }
} }
charon->bus->message(charon->bus, msg, TRUE); charon->bus->message(charon->bus, msg, TRUE);