[strongSwan] stroke down-nb blocks during retransmits?

Brad Johnson bjohnson at ecessa.com
Mon Jun 16 20:52:40 CEST 2014

Running strongSwan 5.1.2 and using stroke up-nb and down-nb. After a 
road-warrior connection is established, attempting to stop the 
connection on the server side using down-nb can hang for nearly 3 
minutes (5 retransmits) if any network problems are preventing the 
IKE_SA Delete packets from reaching the client. This can happen for a 
variety of reasons, including connectivity issues or the firewall on the 
client. In any case I'm wondering why it is not non-blocking as advertised?

Brad Johnson

