[strongSwan] charon: how to determine minimum number of threads

2009-11-03 Thread Dimitrios Siganos
Hi, Scanning through the mailing list I can see that the recomended minimum number of threads is 8-10 depending on the plugins used. Is there a way to determine the absolute minimum number of threads for a given plugin configuration? For example, are the threads allocated statically at

Re: [strongSwan] Specifying ikelifetime or keylife but not both

2009-11-03 Thread Andreas Steffen
Hi Graham, make sure to disable reauthentication (reauth=no) since reauthentication takes down the IKE_SA and all dependent CHILD_SAs and starts renegotiation from scratch. Unfortunately rekey=no disables both IKE_SA and CHILD_SA rekeying so the only workaround is to set ikelifetime and lifetime

[strongSwan] Specifying ikelifetime or keylife but not both

2009-11-03 Thread Graham Hudspith
Hi. Is it possible to specify a value for ikelifetime (e.g. 10m) but leave lifetime turned off (e.g. 0) ? And vice versa ? During testing we want to be able to checking child-rekeying without worrying about ike-rekeying, and vice versa. I realise that we could set the unwanted one to

[strongSwan] Looking for ideas

2009-11-03 Thread Brandon Rock
Hello, I am looking for some better ideas on how to handle an issue I am experiencing, please. I am using Ubuntu 9.10 Server with StrongSwan 4.3.5. The issue I am having is that, even with Dead Peer Detection turned on, once a remote ISA Server is rebooted, my StrongSwan configuration cannot