Page MenuHomeFreeBSD

Correct IPSec SA statistic keeping
ClosedPublic

Authored by eri on Jul 29 2015, 8:48 PM.
Referenced Files
Unknown Object (File)
Sat, Apr 20, 2:48 PM
Unknown Object (File)
Thu, Apr 11, 4:41 PM
Unknown Object (File)
Mon, Apr 8, 1:11 PM
Unknown Object (File)
Mon, Apr 8, 12:31 PM
Unknown Object (File)
Jan 31 2024, 9:56 AM
Unknown Object (File)
Dec 20 2023, 12:03 AM
Unknown Object (File)
Dec 12 2023, 4:33 PM
Unknown Object (File)
Oct 11 2023, 10:27 AM
Subscribers

Details

Summary

The IPsec SA statistic keeping is used even for decision making on expiry/rekeying SAs.
When there are multiple transformations being done the statistic keeping might be wrong.

This mostly impacts multiple encapsulations on IPsec since the usual scenario it is not noticed due to the code path not taken.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

eri retitled this revision from to Correct IPSec SA statistic keeping.
eri updated this object.
eri edited the test plan for this revision. (Show Details)
eri added reviewers: ae, gnn.
eri set the repository for this revision to rS FreeBSD src repository - subversion.
eri added a project: network.
eri added a subscriber: network.
ae edited edge metadata.
This revision is now accepted and ready to land.Jul 30 2015, 7:29 AM
gnn edited edge metadata.

Approved

This revision was automatically updated to reflect the committed changes.