ike-sa: Avoid reusing established IKE_SAs that got redirected
These will get terminated by the peer after a while. So we don't want to reuse them.
This commit is contained in:
@@ -2341,6 +2341,9 @@ static bool redirect_established(private_ike_sa_t *this, identification_t *to)
|
|||||||
{
|
{
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
|
/* mark the SA so it won't get reused even though it's established */
|
||||||
|
set_condition(this, COND_REDIRECTED, TRUE);
|
||||||
|
|
||||||
new_priv = (private_ike_sa_t*)new;
|
new_priv = (private_ike_sa_t*)new;
|
||||||
new->set_peer_cfg(new, this->peer_cfg);
|
new->set_peer_cfg(new, this->peer_cfg);
|
||||||
new_priv->redirected_from = this->other_host->clone(this->other_host);
|
new_priv->redirected_from = this->other_host->clone(this->other_host);
|
||||||
|
|||||||
@@ -1563,6 +1563,7 @@ METHOD(ike_sa_manager_t, checkout_by_config, ike_sa_t*,
|
|||||||
}
|
}
|
||||||
if (entry->ike_sa->get_state(entry->ike_sa) == IKE_DELETING ||
|
if (entry->ike_sa->get_state(entry->ike_sa) == IKE_DELETING ||
|
||||||
entry->ike_sa->get_state(entry->ike_sa) == IKE_REKEYED ||
|
entry->ike_sa->get_state(entry->ike_sa) == IKE_REKEYED ||
|
||||||
|
entry->ike_sa->has_condition(entry->ike_sa, COND_REDIRECTED) ||
|
||||||
ike_sa_is_delete_queued(entry->ike_sa))
|
ike_sa_is_delete_queued(entry->ike_sa))
|
||||||
{ /* skip IKE_SAs which are not usable, wake other waiting threads */
|
{ /* skip IKE_SAs which are not usable, wake other waiting threads */
|
||||||
entry->condvar->signal(entry->condvar);
|
entry->condvar->signal(entry->condvar);
|
||||||
|
|||||||
Reference in New Issue
Block a user