On Wed, 25 Jul 2001, Sean Chittenden wrote:
> > day or two suffice? I'm not concerned about rekeying breaking a few
> > connections given that it will only happen occasionally.
>
> While I agree that rekeying isn't something that should be
> removed, I am concerned with your last sentence. Breaking TCP sessions
> strikes me as an indicator that there needs to be some way of
> configuring this. Is there any chance you could make this a tunable
> variable through sysctl such as the number of seconds between rekeying?
By "breaking a few connections", I was referring to delaying the
establishment of a few connections when TIME_WAIT wraparound occurs, not
the termination of active connections. I apologize for the confusion.
Mike "Silby" Silbersack
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-net" in the body of the message