File: description.txt

package info (click to toggle)
libreswan 5.2-2.2
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 81,632 kB
  • sloc: ansic: 129,988; sh: 32,018; xml: 20,646; python: 10,303; makefile: 3,022; javascript: 1,506; sed: 574; yacc: 511; perl: 264; awk: 52
file content (19 lines) | stat: -rw-r--r-- 674 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
This tests the RFC3706 DPD implementation, with dpdaction=clear on east,
and dpdaction=restart on west.

This means east will clear the SA after the tunnel times out, while west
will put the route into %trap, awaiting a new packet to trigger reestablishment
of the tunnel.

Order of Operations:

1) East sets up for tunnel
2) West initiates tunnel to east
3) We idle for 20 seconds, to prove that DPD R_U_THERE/R_U_THERE_ACKs work.
4) West blocks traffic on eth0
5) Both sides trigger a DPD Timeout:
	East clears the eroute & SA
	West puts the eroute into %trap
6) West removes the traffic block
7) West sends icmp packets to east, triggering a renegotiation of the tunnel