[Users] why doesn't `ipsec auto --down <connection>` work?

From: martin f krafft (madduck_at_madduck.net)
Date: Thu Nov 28 2002 - 00:08:47 CET


two machines, both are auto=add. i now start the connection by typing

  ipsec auto --up <connection>

on one, and the SA is established. why does

  ipsec auto --down <connection>

not take the SA down? sure, it terminates the SA:

  terminating SAs using connection
  deleting state (STATE_QUICK_I2)
  deleting state (STATE_MAIN_I4)

but the next packet to cross the line causes the SA to be
reestablished. this isn't too bad, but i am wondering how one can
reset the relationship between two VPN hosts to before --up was issued
(i.e. before phase 1 happened, right?), short of restarting pluto...
--delete doesn't really do what i want ;^>.

thanks,

-- 
martin;              (greetings from the heart of the sun.)
  \____ echo mailto: !#^."<*>"|tr "<*> mailto:" net_at_madduck
 
NOTE: The public PGP keyservers are broken!
Get my key here: http://people.debian.org/~madduck/gpg/330c4a75.asc
 
consciousness: that annoying time between naps.

_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users




This archive was generated by hypermail 2.1.5 : Thu Nov 28 2002 - 05:20:53 CET