made ikev2/reauth-late scenario more robust
authorAndreas Steffen <andreas.steffen@strongswan.org>
Wed, 21 Dec 2011 05:00:13 +0000 (06:00 +0100)
committerAndreas Steffen <andreas.steffen@strongswan.org>
Wed, 21 Dec 2011 05:00:13 +0000 (06:00 +0100)
testing/tests/ikev2/reauth-late/evaltest.dat
testing/tests/ikev2/reauth-late/hosts/moon/etc/ipsec.conf

index 7f083a0..c0893df 100644 (file)
@@ -1,7 +1,7 @@
 moon::ipsec statusall::rw\[2\].*ESTABLISHED::YES
 carol::ipsec statusall::home\[2\].*ESTABLISHED::YES
 carol::cat /var/log/daemon.log::scheduling reauthentication in 2[0-5]s::YES
-carol::cat /var/log/daemon.log::received AUTH_LIFETIME of 3600s, reauthentication already scheduled in 2[0-5]s::YES
+carol::cat /var/log/daemon.log::received AUTH_LIFETIME of 360[01]s, reauthentication already scheduled in 2[0-5]s::YES
 carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
 moon::tcpdump::IP carol.strongswan.org > moon.strongswan.org: ESP::YES
 moon::tcpdump::IP moon.strongswan.org > carol.strongswan.org: ESP::YES
index bdd186a..cb5e86a 100755 (executable)
@@ -6,8 +6,8 @@ config setup
        plutostart=no
 
 conn %default
-       ikelifetime=60m
-       keylife=20m
+       ikelifetime=3601
+       keylife=1200
        rekeymargin=0s
        keyingtries=1