diff options
author | Martin Willi <martin@revosec.ch> | 2013-02-25 11:42:50 +0100 |
---|---|---|
committer | Martin Willi <martin@revosec.ch> | 2013-02-25 12:12:19 +0100 |
commit | cdf75a39e3c6eb5e7e59d831d8b2441d8af08516 (patch) | |
tree | 61ec8b3e37ea89b03965becdeead971937b49bbb /src/libcharon/sa/ikev2 | |
parent | 9eaed7a5bb11726e8a2bca5e82fde78f25803237 (diff) | |
download | strongswan-cdf75a39e3c6eb5e7e59d831d8b2441d8af08516.tar.bz2 strongswan-cdf75a39e3c6eb5e7e59d831d8b2441d8af08516.tar.xz |
Move initial message dropping to task manager
When the last request message of the initial tunnel setup is retransmitted,
we must retransmit the response instead of ignoring the request.
Fixes #295.
Diffstat (limited to 'src/libcharon/sa/ikev2')
-rw-r--r-- | src/libcharon/sa/ikev2/task_manager_v2.c | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/src/libcharon/sa/ikev2/task_manager_v2.c b/src/libcharon/sa/ikev2/task_manager_v2.c index ea0117c54..29d8d830e 100644 --- a/src/libcharon/sa/ikev2/task_manager_v2.c +++ b/src/libcharon/sa/ikev2/task_manager_v2.c @@ -1123,6 +1123,18 @@ METHOD(task_manager_t, process_message, status_t, { if (mid == this->responding.mid) { + /* reject initial messages once established */ + if (msg->get_exchange_type(msg) == IKE_SA_INIT || + msg->get_exchange_type(msg) == IKE_AUTH) + { + if (this->ike_sa->get_state(this->ike_sa) != IKE_CREATED && + this->ike_sa->get_state(this->ike_sa) != IKE_CONNECTING) + { + DBG1(DBG_IKE, "ignoring %N in established IKE_SA state", + exchange_type_names, msg->get_exchange_type(msg)); + return FAILED; + } + } if (this->ike_sa->get_state(this->ike_sa) == IKE_CREATED || this->ike_sa->get_state(this->ike_sa) == IKE_CONNECTING || msg->get_exchange_type(msg) != IKE_SA_INIT) |