[strongSwan] IPsec SAs closed unexpectedly

Mihai Maties mihai at xcyb.org
Tue Nov 5 17:33:22 CET 2013


On Thu, Oct 24, 2013 at 4:43 PM, Mihai Maties <mihai at xcyb.org> wrote:

> One issue that I noticed so far, is that while on Juniper the tunnels seem
> stable (i.e. rekeying occurs only when the SAs are about to expire), on
> strongSwan some tunnels go down after a short while. According to the logs,
> the other peer is actually triggering the deletion of SAs.


After disabling dead peer detection on the remote peer the tunnels seem
stable. Are there any known issues with DPD between strongSwan and Juniper
devices? Their end is running JunOS 10.4S5.2.


Best regards,
Mihai
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20131105/2f027b72/attachment.html>


More information about the Users mailing list