redesigned IKE_SA using a transaction mechanism:

removed old state machine
  reimplemented IKE_SA setup and delete
  implemented dead peer detection
  implemented keep-alives
  a lot of fixes
  no rekeying yet
This commit is contained in:
Martin Willi
2006-07-05 10:53:20 +00:00
parent b12af2ead6
commit 3dd3c5f39e
71 changed files with 4873 additions and 8187 deletions
+5 -8
View File
@@ -41,18 +41,15 @@ struct configuration_t {
/**
* @brief Returns the retransmit timeout.
*
* A return value of zero means the request should not retransmitted again.
* The timeout values are managed by the configuration, so
* another backoff algorithm may be implemented here.
*
* @param this calling object
* @param retransmit_count number of times a message was retransmitted so far
* @param[out] timeout the new retransmit timeout in milliseconds
*
* @return
* - FAILED, if the message should not be retransmitted
* - SUCCESS
* @return time in milliseconds, when to schedule next retransmit
*/
status_t (*get_retransmit_timeout) (configuration_t *this, u_int32_t retransmit_count, u_int32_t *timeout);
u_int32_t (*get_retransmit_timeout) (configuration_t *this, u_int32_t retransmit_count);
/**
* @brief Returns the timeout for an half open IKE_SA in ms.
@@ -76,7 +73,7 @@ struct configuration_t {
* NAT keepalive packet should be sent.
*
* @param this calling object
* @return interval in milliseconds (ms)
* @return interval in seconds
*/
u_int32_t (*get_keepalive_interval) (configuration_t *this);
@@ -87,7 +84,7 @@ struct configuration_t {
* DPD request packet should be sent.
*
* @param this calling object
* @return interval in milliseconds (ms)
* @return interval in seconds
*/
u_int32_t (*get_dpd_interval) (configuration_t *this);