From: Martin Willi Date: Thu, 7 Nov 2013 08:21:02 +0000 (+0100) Subject: ike: Restart inactivity counter after doing a CHILD_SA rekey X-Git-Tag: 5.1.2rc1~38 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=d048a319df412ee7966a898caed2ac93f0eae1b1;p=thirdparty%2Fstrongswan.git ike: Restart inactivity counter after doing a CHILD_SA rekey When doing a rekey for a CHILD_SA, the use counters get reset. An inactivity job is queued for a time unrelated to the rekey time, so it might happen that the inactivity job gets executed just after rekeying. If this happens, inactivity is detected even if we had traffic on the rekeyed CHILD_SA just before rekeying. This change implies that inactivity checks can't handle inactivity timeouts for rekeyed CHILD_SAs, and therefore requires that inactivity timeout is shorter than the rekey time to have any effect. --- diff --git a/man/ipsec.conf.5.in b/man/ipsec.conf.5.in index 92be670000..a0be75536e 100644 --- a/man/ipsec.conf.5.in +++ b/man/ipsec.conf.5.in @@ -386,7 +386,9 @@ retransmission timeout applies, as every exchange is used to detect dead peers. .TP .BR inactivity " =