Thread (18 messages) 18 messages, 4 authors, 2005-04-01

Re: PATCH: IPSEC acquire in presence of multiple managers

From: jamal <hidden>
Date: 2005-03-26 18:41:27

You could say i am obssesed by this aquire message - I dont know why;->

I noticed in the absence of a responsive KM, the acquires are sent
forever. Is it 30 seconds and may be degenerating to 60 seconds?
In the meantime my ping is sitting there not giving me back the prompt.
I suspect this is so as to make it reliable and maybe aggrevated by the
fact i can now passively monitor with ip xfrm mon.

Shouldnt there be a _configurable_ timer and number of retries?
all attempts of reliability at least put an upper limit.
Perhaps the km states could be extended a little? i.e instead of
just ACQUIRING maybe some intermidiate states are needed (sort of like
neighbor discovery or ARP). And when it looks hopeless you just stop.

Is there a standard maybe that defines such behavior?

cheers,
jamal
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help