<div>hi all,</div>
<div> Is it right that the duplicate IKE tunnel is not deleted because the older tunnel is running DPD detecting.</div>
<div> I am running strongswan-4.5.2 and using IKEv2 with DPD in the following scenario:</div>
<div> <a href="http://www.strongswan.org/uml-testresults.html">http://www.strongswan.org/uml-testresults.html</a></div>
<div> </div>
<div> I follow these steps:</div>
<div> 1. Carol establishes a ipsec tunnel with moon.</div>
<div> 2. Carol shutdown the eth0 with the command ifdown </div>
<div> 3. Carol run 'ipsec resstart'</div>
<div> 4. Carol establishes a ipsec tunnel with moon again. </div>
<div> Then I can see two IKE tunnel in the 'ipsec statusall', and the older one is running DPD detecting. I can see "deleting duplicate tunnel....." in /var/log/messages but the older tunnel is not deleted immediately.</div>
<div> </div>
<div> Is it right or am I missing so meting in the strongwan configure file?</div>
<div> And it is a way to delete the older tunnel immediately with DPD ?</div>
<div> </div>
<div>best regards,</div>
<div>nanajian5</div>