testing: Adapt tests to retransmission settings and reduce DPD delay/timeout
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
The roadwarrior <b>carol</b> sets up an IPsec tunnel connection to the gateway <b>moon</b>
|
||||
which in turn activates <b>Dead Peer Detection</b> (DPD) with a polling interval of 10 s.
|
||||
When the network connectivity between <b>carol</b> and <b>moon</b> is forcefully disrupted,
|
||||
<b>moon</b> clears the connection after 4 unsuccessful retransmits.
|
||||
<b>moon</b> clears the connection after a number of unsuccessful retransmits.
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
carol::ipsec status 2> /dev/null::home.*INSTALLED, TUNNEL::YES
|
||||
moon:: ipsec status 2> /dev/null::rw.*INSTALLED, TUNNEL::YES
|
||||
carol::iptables -A INPUT -i eth0 -s PH_IP_MOON -j DROP::no output expected::NO
|
||||
moon:: sleep 60::no output expected::NO
|
||||
moon:: sleep 16::no output expected::NO
|
||||
moon:: cat /var/log/daemon.log::sending DPD request::YES
|
||||
moon::cat /var/log/daemon.log::DPD check timed out, enforcing DPD action::YES
|
||||
moon:: cat /var/log/daemon.log::DPD check timed out, enforcing DPD action::YES
|
||||
moon:: ipsec status 2> /dev/null::rw.*INSTALLED::NO
|
||||
|
||||
@@ -9,8 +9,8 @@ conn %default
|
||||
keyingtries=1
|
||||
keyexchange=ikev1
|
||||
dpdaction=clear
|
||||
dpddelay=10
|
||||
dpdtimeout=45
|
||||
dpddelay=5
|
||||
dpdtimeout=15
|
||||
|
||||
conn rw
|
||||
left=PH_IP_MOON
|
||||
|
||||
Reference in New Issue
Block a user