ikev1: Ignore roam events for IKEv1
We don't have MOBIKE and the fallback to reauthentication does also not make much sense as that doesn't affect the CHILD_SAs for IKEv1. So instead of complicating the code we just ignore roam events for IKEv1 for now. Closes strongswan/strongswan#100.
This commit is contained in:
@@ -2582,10 +2582,15 @@ METHOD(ike_sa_t, roam, status_t,
|
|||||||
* without config assigned */
|
* without config assigned */
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
if (this->version == IKEV1)
|
||||||
|
{ /* ignore roam events for IKEv1 where we don't have MOBIKE and would
|
||||||
|
* have to reestablish from scratch (reauth is not enough) */
|
||||||
|
return SUCCESS;
|
||||||
|
}
|
||||||
|
|
||||||
/* ignore roam events if MOBIKE is not supported/enabled and the local
|
/* ignore roam events if MOBIKE is not supported/enabled and the local
|
||||||
* address is statically configured */
|
* address is statically configured */
|
||||||
if (this->version == IKEV2 && !supports_extension(this, EXT_MOBIKE) &&
|
if (!supports_extension(this, EXT_MOBIKE) &&
|
||||||
ike_cfg_has_address(this->ike_cfg, this->my_host, TRUE))
|
ike_cfg_has_address(this->ike_cfg, this->my_host, TRUE))
|
||||||
{
|
{
|
||||||
DBG2(DBG_IKE, "keeping statically configured path %H - %H",
|
DBG2(DBG_IKE, "keeping statically configured path %H - %H",
|
||||||
|
|||||||
Reference in New Issue
Block a user