You can try. Or you can do a delete, then I think you can do straight to a start which will also do the add for you. If you do a down and the other end detects it, the other end may try to rekey before your wait is up. Have a play and see what works best for you

On 10/10/2018 16:08, Whit Blauvelt wrote:
On Wed, Oct 10, 2018 at 03:58:19PM +0100, Nick Howitt wrote:
Rather than restart ipsec which restarts all conns, can you do it on a per-conn
basis using the "ipsec auto delete/replace/add/start" commands?
Hi Nick,

Thanks for the suggestion. Do you happen to know the best use of those
options here? Considering the apparent need for a pause, should it be with
"--down" then after a wait "--up"?

Best,
Whit

_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan

Reply via email to