[Swan-dev] interop-ikev2-strongswan-35-initiator-rekey not working

Paul Wouters paul at nohats.ca
Fri Feb 28 17:44:00 UTC 2020


On Fri, 28 Feb 2020, Antony Antony wrote:

>> As I said, I see no difference running 3.29, 3.30 or git master.

> I am pretty sure I saw the regression with 3.30. If you show your full test

I got something mixed up. I now see proper differences.

It looks like we might not be using in_struct() for reading traffic
selectors, or we are using one that doesn't handle v4 and v6 being
different. Ideally, this should fail at in_struct(), so we can
reject the entire packet witn INVALID_SYNTAX - which is what
strongswan correctly does.

Paul


More information about the Swan-dev mailing list