[strongSwan] Why does charon delete all IKE_SA?

Martin Willi martin at strongswan.org
Wed Sep 8 10:06:00 CEST 2010


Hi,
> 
> generating CREATE_CHILD_SA request 2 [ SA No KE ]

> deleting IKE_SA airwalk[1] between aaa.bbb.cc.dd[aaa.bbb.cc.dd]...www.xx.yyy.zz[11.com]

> deleting IKE_SA airwalk[2] between aaa.bbb.cc.dd[aaa.bbb.cc.dd]...www.xx.yyy.zz[11.com]

I don't see why [1] gets deleted, your log does not show a reason. But
the delete for [2] follows a rekey, i.e. only the rekeyed SA should get
deleted; the replacement SA still stays up. The IKEv2 protocol uses a
DELETE messages to close rekeyed SAs.

Regards
Martin






More information about the Users mailing list