[Openswan Users] Fwd: multiple ike sa getting created and multiple ike sa getting deleted for same endpoints

Samir Hussain shussain at xelerance.com
Tue May 7 08:28:42 EDT 2019


Rescued fro mthe spam bucket. Please be sure to join the OSW mailing
list before you post on it.


-------- Forwarded Message --------
Subject: 	multiple ike sa getting created and multiple ike sa getting
deleted for same endpoints
Date: 	Tue, 7 May 2019 16:22:57 +0530
From: 	Yogesh Purohit <yogeshpurohit2 at gmail.com>
To: 	users at lists.openswan.org



Hi Team,

In IKEv1 openswan implementation, I see IKE SA being deleted and
recreated whereas IPSec SA (Phase 2) is always up and running.

I have configured:

ikelifetime = 28800s
salifetime = 3600s

And I have multiple subnets configured behind two peer endpoints.

So multiple IPSec SA are using single IKE Sa.
but I see multiple ike sa getting created and multiple ike sa getting
deleted.
Why so when same ike sa is being used by all ipsec sa ?

-- 
Best Regards,

Yogesh Purohit


More information about the Users mailing list