|
|||||||||||
|
[Design] temporary wild-side problems cause long-term conn problems
From: John S. Denker <jsd(at)monmouth.com>
Date: Sat Mar 08 2003 - 11:27:01 EST I'm promoting this to the design list. Perhaps one of the designers could tell us, how is FreeS/WAN _supposed_ to respond to routing events "below" the tunnel layer, e.g. eth0 going down and back up, due to e.g. temporary dhcp failure or temporary removal of a pcmcia card? martin f krafft wrote: > It just happened again, > and I could see from the log that a DHCP failure preceeded this. Since > bringing the interface down without stopping FreeS/WAN first yield the > same result, I am thinking that this is what happened. > > However, don't you agree that this is a bug? Sure, it's a big ugly bug. Are you running dhcpcd or dhclient? I just did some playing on a box running dhcpcd and I observe a _different_ big ugly bug:
This is 100% reproducible for me. Hint: dhcpcd -k eth0 It seems to me that (a), (b), and (c) are each suboptimal separately, and even worse collectively. -- If we're going to unroute something, unroute ipsec0 (in the main routing table) so that it doesn't ask to receive packets that it can't possibly handle. -- If we unroute something, leave enough breadcrumbs in the forest so that we can restore the routes when the trouble is over. > I have a machine that does IPsec with two other static machines, and
Design mailing list Design@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/design Received on Sat Mar 8 12:26:21 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT |
||||||||||
|
|||||||||||