ike: Disable NAT keepalives in state PASSIVE
Signed-off-by: Thomas Egerer <[email protected]>
This commit is contained in:
committed by
Tobias Brunner
parent
008a9ad12c
commit
edaba56ec7
@@ -487,8 +487,9 @@ METHOD(ike_sa_t, send_keepalive, void,
|
|||||||
send_keepalive_job_t *job;
|
send_keepalive_job_t *job;
|
||||||
time_t last_out, now, diff;
|
time_t last_out, now, diff;
|
||||||
|
|
||||||
if (!(this->conditions & COND_NAT_HERE) || this->keepalive_interval == 0)
|
if (!(this->conditions & COND_NAT_HERE) || this->keepalive_interval == 0 ||
|
||||||
{ /* disable keep alives if we are not NATed anymore */
|
this->state == IKE_PASSIVE)
|
||||||
|
{ /* disable keep alives if we are not NATed anymore, or we are passive */
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -651,7 +652,7 @@ METHOD(ike_sa_t, get_state, ike_sa_state_t,
|
|||||||
METHOD(ike_sa_t, set_state, void,
|
METHOD(ike_sa_t, set_state, void,
|
||||||
private_ike_sa_t *this, ike_sa_state_t state)
|
private_ike_sa_t *this, ike_sa_state_t state)
|
||||||
{
|
{
|
||||||
bool trigger_dpd = FALSE;
|
bool trigger_dpd = FALSE, keepalives = FALSE;
|
||||||
|
|
||||||
DBG2(DBG_IKE, "IKE_SA %s[%d] state change: %N => %N",
|
DBG2(DBG_IKE, "IKE_SA %s[%d] state change: %N => %N",
|
||||||
get_name(this), this->unique_id,
|
get_name(this), this->unique_id,
|
||||||
@@ -722,6 +723,10 @@ METHOD(ike_sa_t, set_state, void,
|
|||||||
* so yet, so prevent that. */
|
* so yet, so prevent that. */
|
||||||
this->stats[STAT_INBOUND] = this->stats[STAT_ESTABLISHED];
|
this->stats[STAT_INBOUND] = this->stats[STAT_ESTABLISHED];
|
||||||
}
|
}
|
||||||
|
if (this->state == IKE_PASSIVE)
|
||||||
|
{
|
||||||
|
keepalives = TRUE;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
@@ -742,6 +747,10 @@ METHOD(ike_sa_t, set_state, void,
|
|||||||
DBG1(DBG_IKE, "DPD not supported by peer, disabled");
|
DBG1(DBG_IKE, "DPD not supported by peer, disabled");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (keepalives)
|
||||||
|
{
|
||||||
|
send_keepalive(this);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(ike_sa_t, reset, void,
|
METHOD(ike_sa_t, reset, void,
|
||||||
|
|||||||
Reference in New Issue
Block a user