Re: [Swan-dev] [Swan-commit] ikev2: allow Protocol ID IKE in Notify

2020-10-17 Thread Andrew Cagney
On Sat, 17 Oct 2020 at 05:51, Antony Antony wrote: > > I think fix f9fada7234b is worth a closer look. The source of the change is an IETF discussion around eid5247. I'm not sure if that is public. The upshot is that while these numbers all seem to be drawn from a common table, they're not. In

Re: [Swan-dev] [Swan-commit] ikev2: allow Protocol ID IKE in Notify

2020-10-17 Thread Paul Wouters
On Sat, 17 Oct 2020, Antony Antony wrote: I think fix f9fada7234b is worth a closer look. Yesterday, when Tuomo noticed this issue and when I fixed it, the issue appeared a simple bug. Thanks for finding and fixing it so quickly! On a closer look I think 14e07ddcf2f5 was very delibrate to b

Re: [Swan-dev] [Swan-commit] ikev2: allow Protocol ID IKE in Notify

2020-10-17 Thread Antony Antony
I think fix f9fada7234b is worth a closer look. Yesterday, when Tuomo noticed this issue and when I fixed it, the issue appeared a simple bug. On a closer look I think 14e07ddcf2f5 was very delibrate to block "Notify with Protocol ID IKE(1)" Now we know that out in the wild Cisco would send Pr