ping behaviour when ipsec peer is not available
When a connection is configured for ipsec in my case using strongswan and the peer of the connection is not responding (say it is unreachable) I see the ping behavior as below
root@ffd-ipsec-189 sanjay]# ping 10.204.74.188
basically ping is stuck or blocked. This behaviour also manifests in any program that tries to open a socket to the same peer and gets blocked.
Now if I do not have a connection configured in the /etc/ipsec.conf I see that the ping responds like this
root@ffd-ipsec-189 sanjay]# ping 10.204.74.188
PING 10.204.74.188 (10.204.74.188) 56(84) bytes of data.
From 10.204.74.189 icmp_seq=2 Destination Host Unreachable
From 10.204.74.189 icmp_seq=3 Destination Host Unreachable
From 10.204.74.189 icmp_seq=5 Destination Host Unreachable
What settings can be done for a timeout to occurs to that a program that is trying to reach an ip may not be blocked forever if ipsec SA cannot be established ?
|