On 30/10/2024 15:50, Ilya Maximets wrote:
> These should be considered active, because pluto is waiting for the
> other side to react. We should not remove them or try to repair.
> Such connections have an extra text between the SA number and the
> name of the connection.
>
> Ideally, we would like not to parse the output of ipsec status, since
> it's very error prone, but there is, unfortunately, no other interface.
>
> Signed-off-by: Ilya Maximets <[email protected]>
> ---
> ipsec/ovs-monitor-ipsec.in | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/ipsec/ovs-monitor-ipsec.in b/ipsec/ovs-monitor-ipsec.in
> index 4885e048f..14004f924 100755
> --- a/ipsec/ovs-monitor-ipsec.in
> +++ b/ipsec/ovs-monitor-ipsec.in
> @@ -729,7 +729,7 @@ conn prevent_unencrypted_vxlan
> return conns
>
> for line in pout.splitlines():
> - m = re.search(r"#\d+: \"(.*)\".*", line)
> + m = re.search(r"#\d+: .*\"(.*)\".*", line)
> if not m:
> continue
>
Acked-by: Roi Dayan <[email protected]>
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev