[strongSwan] Total connection time with rekeying

Dmitry Korzhevin dmitry.korzhevin at stidia.com
Thu Oct 11 15:51:21 CEST 2012


Hello,

I have vpn server on debian 6.0.5 with strongSwan 5.0.0

I can see users connection status with command 'ipsec status' or 'ipsec
statusall'. I can see connection time 'ESTABLISHED x minutes ago' but i
want to see or be able to calculate total time of connection.

For example i have user:

ios[13967]: ESTABLISHED 44 minutes ago,
SERVER_IP[SERVER_IP]...CLIENT_IP[192.168.0.102]
         ios[13967]: Remote XAuth identity: PASSWORD
         ios[13967]: IKEv1 SPIs: b5a09665f457ed48_i 9c44c5ec6c4e07a1_r*,
pre-shared key reauthentication in 2 hours
         ios[13967]: IKE proposal:
AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024
         ios[13967]: Tasks active: QUICK_MODE
         ios{10783}:  REKEYING, TUNNEL, expires in 15 minutes
         ios{10783}:   0.0.0.0/0 === 10.2.0.219/32

What i see is string 'REKEYING, TUNNEL, expires in 15 minutes', so
connection will be lost and client will be disconnected?

How can i trac total connection time with all disconnections, rekeying,
etc...  ?



Best Regards,
Dmitry

---
Dmitry KORZHEVIN
System Administrator
STIDIA S.A. - Luxembourg

e: dmitry.korzhevin at stidia.com
m: +38 093 874 5453
w: http://www.stidia.com

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4488 bytes
Desc: ���������������������������������� �������������� S/MIME
URL: <http://lists.strongswan.org/pipermail/users/attachments/20121011/ac93b5f1/attachment.bin>


More information about the Users mailing list