Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
IKEv2: OE connection timing out could accidentally overwrite tunnel p…
…olicy The failure scenario: west OE initiates conn private #1 to east but east is not running pluto. west keeps trying (keyingtries=%forver) east is started, and triggers its own OE initiatialize to west west creates a new IKE state #2 and an IPsec tunnel is installed. west state #1 finds out it is no longer newest IKE SA and deletes itself west will try to install an OE bare shunt on deleting, overwriting the IPsec tunnel out policy. This commit ensures west skips creating bare shunts when it is no longer c->newest_isakmp_sa
- Loading branch information