[strongSwan] Multiple CHILD_SA's after reauth timer expires

Tobias Brunner tobias at strongswan.org
Tue Aug 18 17:46:50 CEST 2020


Hi Makarand,

> Any opinions on how to avoid the multiple CHILD_SAs after reauth?

Don't use reauth (use rekeying) or use make-before-break reauth, see [1]
for details (where this issue with trap policies is also mentioned).

Regards,
Tobias

[1] https://wiki.strongswan.org/projects/strongswan/wiki/ExpiryRekey#IKE


More information about the Users mailing list