[strongSwan] Alternative ways of controlling DPD

Kristian.Lippert at tieto.com Kristian.Lippert at tieto.com
Mon Jul 30 12:25:48 CEST 2012

Thanks for the reply.
Is it possible to get callbacks when Strongswan identifies that no traffic happens (the first step in the DPD), and then when traffic happens again?
In this way we can implement our own custom DPD!
Best Regards,

-----Original Message-----
From: Martin Willi [mailto:martin at strongswan.org] 
Sent: 6. juli 2012 16:56
To: Lippert Kristian
Cc: users at lists.strongswan.org
Subject: Re: [strongSwan] Alternative ways of controlling DPD

Hi Kristian,

> Is it possible to somehow write a plugin or modify the code so it is
> possible to make the behavior for DPD independent of the settings that
> are used in other situations?

Retransmission timeouts are currently global options.

Making these settings per-connection is not that trivial: We'd have to
introduce new ipsec.conf keywords, pass them via starter and stroke and
finally store them on the peer_cfg [1]. Then we could read these values
in the task manager [2]. No rocket-science, but needs some work.

While implementing IKEv1 DPD, we have added a connection specific DPD
timeout option to the peer_cfg. It is currently used for IKEv1 only, and
overrides the cumulative timeout to detect a dead peer. It does not
affect retransmission, but only the timeout. Maybe we should use a
similar behavior for IKEv2. This would be at least somewhat more
congruent, and brings connection specific DPD timeout.



More information about the Users mailing list