added close_action as a seperate config option to dpd_action
This commit is contained in:
+23
-6
@@ -1880,6 +1880,7 @@ static status_t reestablish(private_ike_sa_t *this)
|
||||
{
|
||||
ike_sa_t *new;
|
||||
host_t *host;
|
||||
action_t action;
|
||||
iterator_t *iterator;
|
||||
child_sa_t *child_sa;
|
||||
child_cfg_t *child_cfg;
|
||||
@@ -1891,7 +1892,15 @@ static status_t reestablish(private_ike_sa_t *this)
|
||||
while (iterator->iterate(iterator, (void**)&child_sa))
|
||||
{
|
||||
child_cfg = child_sa->get_config(child_sa);
|
||||
switch (child_cfg->get_action(child_cfg))
|
||||
if (this->state == IKE_DELETING)
|
||||
{
|
||||
action = child_cfg->get_close_action(child_cfg);
|
||||
}
|
||||
else
|
||||
{
|
||||
action = child_cfg->get_dpd_action(child_cfg);
|
||||
}
|
||||
switch (action)
|
||||
{
|
||||
case ACTION_RESTART:
|
||||
case ACTION_ROUTE:
|
||||
@@ -1951,7 +1960,15 @@ static status_t reestablish(private_ike_sa_t *this)
|
||||
while (iterator->iterate(iterator, (void**)&child_sa))
|
||||
{
|
||||
child_cfg = child_sa->get_config(child_sa);
|
||||
switch (child_cfg->get_action(child_cfg))
|
||||
if (this->state == IKE_DELETING)
|
||||
{
|
||||
action = child_cfg->get_close_action(child_cfg);
|
||||
}
|
||||
else
|
||||
{
|
||||
action = child_cfg->get_dpd_action(child_cfg);
|
||||
}
|
||||
switch (action)
|
||||
{
|
||||
case ACTION_RESTART:
|
||||
DBG1(DBG_IKE, "restarting CHILD_SA %s",
|
||||
@@ -2011,16 +2028,16 @@ static status_t retransmit(private_ike_sa_t *this, u_int32_t message_id)
|
||||
SIG(IKE_UP_FAILED, "establishing IKE_SA failed, peer not responding");
|
||||
break;
|
||||
}
|
||||
case IKE_REKEYING:
|
||||
SIG(IKE_REKEY_FAILED, "rekeying IKE_SA failed, peer not responding");
|
||||
break;
|
||||
case IKE_DELETING:
|
||||
SIG(IKE_DOWN_FAILED, "proper IKE_SA delete failed, peer not responding");
|
||||
break;
|
||||
case IKE_REKEYING:
|
||||
SIG(IKE_REKEY_FAILED, "rekeying IKE_SA failed, peer not responding");
|
||||
/* FALL */
|
||||
default:
|
||||
reestablish(this);
|
||||
break;
|
||||
}
|
||||
reestablish(this);
|
||||
return DESTROY_ME;
|
||||
}
|
||||
return SUCCESS;
|
||||
|
||||
@@ -173,7 +173,7 @@ static status_t destroy_and_reestablish(private_child_delete_t *this)
|
||||
this->ike_sa->destroy_child_sa(this->ike_sa, protocol, spi);
|
||||
if (!this->initiator)
|
||||
{ /* enforce child_cfg policy if deleted passively */
|
||||
switch (child_cfg->get_action(child_cfg))
|
||||
switch (child_cfg->get_close_action(child_cfg))
|
||||
{
|
||||
case ACTION_RESTART:
|
||||
child_cfg->get_ref(child_cfg);
|
||||
|
||||
@@ -82,19 +82,18 @@ static status_t process_r(private_ike_delete_t *this, message_t *message)
|
||||
* come so far without being correct */
|
||||
switch (this->ike_sa->get_state(this->ike_sa))
|
||||
{
|
||||
case IKE_DELETING:
|
||||
this->simultaneous = TRUE;
|
||||
break;
|
||||
case IKE_ESTABLISHED:
|
||||
DBG1(DBG_IKE, "deleting IKE_SA on request");
|
||||
this->ike_sa->set_state(this->ike_sa, IKE_DELETING);
|
||||
this->ike_sa->reestablish(this->ike_sa);
|
||||
break;
|
||||
case IKE_REKEYING:
|
||||
break;
|
||||
case IKE_DELETING:
|
||||
this->simultaneous = TRUE;
|
||||
/* FALL */
|
||||
default:
|
||||
this->ike_sa->set_state(this->ike_sa, IKE_DELETING);
|
||||
break;
|
||||
}
|
||||
this->ike_sa->set_state(this->ike_sa, IKE_DELETING);
|
||||
return NEED_MORE;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user