ike: Disable NAT keepalives in state PASSIVE

Signed-off-by: Thomas Egerer <[email protected]>
This commit is contained in:
Thomas Egerer
2015-08-04 11:16:13 +02:00
committed by Tobias Brunner
parent 008a9ad12c
commit edaba56ec7
+12 -3
View File
@@ -487,8 +487,9 @@ METHOD(ike_sa_t, send_keepalive, void,
send_keepalive_job_t *job; send_keepalive_job_t *job;
time_t last_out, now, diff; time_t last_out, now, diff;
if (!(this->conditions & COND_NAT_HERE) || this->keepalive_interval == 0) if (!(this->conditions & COND_NAT_HERE) || this->keepalive_interval == 0 ||
{ /* disable keep alives if we are not NATed anymore */ this->state == IKE_PASSIVE)
{ /* disable keep alives if we are not NATed anymore, or we are passive */
return; return;
} }
@@ -651,7 +652,7 @@ METHOD(ike_sa_t, get_state, ike_sa_state_t,
METHOD(ike_sa_t, set_state, void, METHOD(ike_sa_t, set_state, void,
private_ike_sa_t *this, ike_sa_state_t state) private_ike_sa_t *this, ike_sa_state_t state)
{ {
bool trigger_dpd = FALSE; bool trigger_dpd = FALSE, keepalives = FALSE;
DBG2(DBG_IKE, "IKE_SA %s[%d] state change: %N => %N", DBG2(DBG_IKE, "IKE_SA %s[%d] state change: %N => %N",
get_name(this), this->unique_id, get_name(this), this->unique_id,
@@ -722,6 +723,10 @@ METHOD(ike_sa_t, set_state, void,
* so yet, so prevent that. */ * so yet, so prevent that. */
this->stats[STAT_INBOUND] = this->stats[STAT_ESTABLISHED]; this->stats[STAT_INBOUND] = this->stats[STAT_ESTABLISHED];
} }
if (this->state == IKE_PASSIVE)
{
keepalives = TRUE;
}
} }
break; break;
} }
@@ -742,6 +747,10 @@ METHOD(ike_sa_t, set_state, void,
DBG1(DBG_IKE, "DPD not supported by peer, disabled"); DBG1(DBG_IKE, "DPD not supported by peer, disabled");
} }
} }
if (keepalives)
{
send_keepalive(this);
}
} }
METHOD(ike_sa_t, reset, void, METHOD(ike_sa_t, reset, void,