diff options
| author | Oleksandr Kuchmystyi <o.kuchmystyi@vyos.io> | 2026-09-15 12:10:16 +0300 |
|---|---|---|
| committer | Oleksandr Kuchmystyi <o.kuchmystyi@vyos.io> | 2026-09-16 11:22:40 +0300 |
| commit | d1cc3ed65eb1f00409d0b91fc8149431fb614e89 (patch) | |
| tree | 4e2f2fe9e22339d18ceb34bd949991bc24634c06 /interface-definitions/include/ldp-sync-protocol.xml.i | |
| parent | 28207a3068fd23d73c93cda806ed3757f9651a5f (diff) | |
| download | vyos-1x-d1cc3ed65eb1f00409d0b91fc8149431fb614e89.tar.gz vyos-1x-d1cc3ed65eb1f00409d0b91fc8149431fb614e89.zip | |
ipsec: T8952: Allow per-peer strongSwan `unique` override for site-to-site peers
VyOS does not expose the strongSwan `connections.<conn>.unique`
parameter for site-to-site peers. The swanctl default is
`unique = no`, which only replaces existing SAs
if the new one carries `INITIAL_CONTACT`. With `dpd_action = restart`,
charon initiates new IKE_SAs without `INITIAL_CONTACT`,
so duplicates accumulate on every DPD timeout.
Previously the strongSwan `unique` connection policy could only be
driven by the global "disable-uniqreqids" option, which set it to
"never" for every connection. Site-to-site peers had no way to opt
into stricter enforcement on their own.
Diffstat (limited to 'interface-definitions/include/ldp-sync-protocol.xml.i')
0 files changed, 0 insertions, 0 deletions
