Hi Vpp Ipsec Experts,

I wanted to understand how child sa rekey ( lifetime) are handled in vpp.
i)   We are using strongswan + kernel-vpp plugin for our ikev2 exchange.
ii)  Now we are facing the issue child sa rekey, the problem child sa rekey
is not getting triggered. I understand, the strongswan needs to trigger
this. We triggered manually it works, but timeout of lifetime does not
work. Please also note there is no issue with IKE SA rekey timeout expiry.
iii) for ii) in the kernel world  while adding as these parameters such
lifetime are passed. And it is the kernel that triggers child sa rekey on
hard timer expiry.
iv) How do we pass these parameter lifetime cfg to the vpp, is it handled
or not handled.

Please note we are using the vpp 20.09 release version for the same.

Thank and regards
Venu
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19089): https://lists.fd.io/g/vpp-dev/message/19089
Mute This Topic: https://lists.fd.io/mt/81780992/21656
Group Owner: vpp-dev+ow...@lists.fd.io
Unsubscribe: https://lists.fd.io/g/vpp-dev/unsub [arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to