charon-nm: Use a DPD to check the current path
If the client's network goes down for a while but the same IP address is assigned later, it won't be aware if the server killed the IKE_SA while it wasn't reachable. This way, a DPD is triggered and the client can reestablish the SA if necessary. When roaming to a different IP, a MOBIKE update is triggered with the same effect. References strongswan/strongswan#2696
This commit is contained in:
@@ -217,6 +217,10 @@ int main(int argc, char *argv[])
|
|||||||
lib->settings->set_default_str(lib->settings,
|
lib->settings->set_default_str(lib->settings,
|
||||||
"charon-nm.plugins.kernel-netlink.fwmark", "!210");
|
"charon-nm.plugins.kernel-netlink.fwmark", "!210");
|
||||||
|
|
||||||
|
/* trigger a DPD to verify the current path is working */
|
||||||
|
lib->settings->set_default_str(lib->settings,
|
||||||
|
"charon-nm.check_current_path", "yes");
|
||||||
|
|
||||||
DBG1(DBG_DMN, "Starting charon NetworkManager backend (strongSwan "VERSION")");
|
DBG1(DBG_DMN, "Starting charon NetworkManager backend (strongSwan "VERSION")");
|
||||||
if (lib->integrity)
|
if (lib->integrity)
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user