address inertia

"John S. Denker" <[email protected]>
Newsgroups gmane.network.freeswan.devel,gmane.network.freeswan.user
Message-ID <[email protected]>
Executive summary:

Suppose you have IPsec gateways at one or two base
locations (which we expect to be more-or-less stationary),
plus a large number of road warriors, i.e. folks who initiate
IPsec connections to the base from strange places.
Typically the wild-side IP address of each road warrior is
assigned by DHCP.

Now suppose you need to restart one of the base stations.
This is bad. All its IPsec connections will go down, and in
the prior art there is no good way to re-establish the
connections. The road warriors will not know that the base
has restarted. They will continue using the old connections
until they time out, which could take hours. Only then will
they commence the rekeying procedure which will lead to
the establishment of new connections.

We now describe mk_conf, which solves this problem.
The key concept is something we call address inertia. That
is, the base station remembers the last known wild-side
address of each road warrior, and uses that to attempt to
re-contact them after a restart.

For details, see:
http://www.monmouth.com/~jsd/vpn/ipsec+routing/mk_conf.htm
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.