ikev1: Fix handling of UNITY_LOAD_BALANCE
The re-authentication is now handled within the original IKE_SA if it has not yet been established, so we don't want to destroy it.
This commit is contained in:
@@ -112,16 +112,16 @@ METHOD(task_t, process_r, status_t,
|
|||||||
IKEV2_UDP_PORT);
|
IKEV2_UDP_PORT);
|
||||||
if (redirect)
|
if (redirect)
|
||||||
{ /* treat the redirect as reauthentication */
|
{ /* treat the redirect as reauthentication */
|
||||||
DBG1(DBG_IKE, "received %N notify. redirected to %H",
|
DBG1(DBG_IKE, "received %N notify, redirected to %H",
|
||||||
notify_type_names, type, redirect);
|
notify_type_names, type, redirect);
|
||||||
/* Cisco boxes reject the first message from 4500 */
|
/* Cisco boxes reject the first message from 4500 */
|
||||||
me = this->ike_sa->get_my_host(this->ike_sa);
|
me = this->ike_sa->get_my_host(this->ike_sa);
|
||||||
me->set_port(me, charon->socket->get_port(
|
me->set_port(me, charon->socket->get_port(
|
||||||
charon->socket, FALSE));
|
charon->socket, FALSE));
|
||||||
this->ike_sa->set_other_host(this->ike_sa, redirect);
|
this->ike_sa->set_other_host(this->ike_sa, redirect);
|
||||||
this->ike_sa->reauth(this->ike_sa);
|
status = this->ike_sa->reauth(this->ike_sa);
|
||||||
enumerator->destroy(enumerator);
|
enumerator->destroy(enumerator);
|
||||||
return DESTROY_ME;
|
return status;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user