Re: [strongSwan] Issue regarding rekeying and updation of an IKE SA

2010-03-03 Thread Stephen Pisano
Hi Martin, I have some additional questions on this topic: Reinitiating the IKE_SA from scratch is also not possible on asymmetric connections. Can you elaborate on this point? What is an asymmetric connection? And why is reinitiating an IKE_SA not possible in this case? As recreating an

Re: [strongSwan] Issue regarding rekeying and updation of an IKE SA

2010-03-03 Thread Martin Willi
Hi Stephen, Reinitiating the IKE_SA from scratch is also not possible on asymmetric connections. Can you elaborate on this point? What is an asymmetric connection? And why is reinitiating an IKE_SA not possible in this case? Under asymmetric I meant an IKE_SA that can be initiated by

[strongSwan] Issue regarding rekeying and updation of an IKE SA

2009-08-06 Thread vivek bairathi
Hi, Thanks for your reply. With your help now I am able to create IKE SA and CHILD SA but there is a problem with updation rekeying of IKE SA:- 1. I am trying to change a/all parameter (for e.g:- rekeytime, encryption algo, integrity algo, DH group parameter) in ipsec.conf so that when I do