[strongSwan] Strongswan MOBIKE support
itsamitkatyal at gmail.com
Wed Sep 28 13:00:06 CEST 2016
I'm testing MOBIKE feature with CISCO GW and strongswan client. Please find
below the test set-up details.
I've configured two interfaces on the client side in the 85 VLAN and
testing the MOBIKE feature by bringing down the interface over which tunnel
has been established.
1. Bring up IKEV2 tunnel between Strongswan and CISCO GW (188.8.131.52 -
2. Confirmed from logs that client is sending MOBIKE_SUPPORTED notification
in the IKE_AUTH message and also receiving the MOBIKE_SUPPORTED capability
in the IKE_AUTH response.
3. Bring down the interface having 184.108.40.206 ip address.
4. Confirmed from the logs, client receives notification from the lower
layer about interface getting down. Client looks for new path and
identifies the new path 220.127.116.11 to reach the GW.
Here I expect client to send UPDATE_SA_ADDRESS notification for new IP
address 18.104.22.168 before actually start using this new IP address.
However, client start sending DPD messages using new IP
to which CISCO GW is not responding (As GW is not aware of new IP address)
and after maximum number of retries client is bringing down the current
tunnel and initiating the new tunnel.
Please help me in validating UDPATE_SA_ADDRESS request message.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Users