Re: [strongSwan] Duplicate IKE_SA?

2020-06-01 Thread Noel Kuntze
Hello Michael, It might be that both sides use auto=route or auto=start and initiated in parallel and uniqueids=no is set, so duplicate SAs are not deleted. That is pure speculation though. ;) Kind regards Noel Am 31.05.20 um 09:44 schrieb Michael Schwartzkopff: > Hi, > > > we have a centra

Re: [strongSwan] Duplicate IKE_SA?

2020-06-01 Thread Michael Schwartzkopff
On 01.06.20 19:23, Noel Kuntze wrote: > Hello Michael, > > It might be that both sides use auto=route or auto=start and initiated in > parallel and uniqueids=no is set, so duplicate SAs are not deleted. > > That is pure speculation though. ;) > > Kind regards > > Noel side A has auto=start and re

[strongSwan] Duplicate IKE_SA?

2020-05-31 Thread Michael Schwartzkopff
Hi, we have a central gateway and several remote gateways. The setup should be very simple, all fixed IP Addresses, PSK authentication. When I look to the status of the connections, I see that EVERY IKE_SA exists duplicate. The expiry times are far from being close to the timeout. Sample outpu