Re: [strongSwan] [strongswan] ipsec SA rekeying

2009-12-28 Thread Andreas Steffen
Hello Ashish, The old rekeying model up to and include version 4.3.4 was delta(x) = (1 + x/100) * rekeymargin with x being a random value in the range 0 <= x <= rekeyfuzz, the defaultof rekeyfuzz being 100%. rekeyfuzz=0% disables the randomization of the rekeying time. The rekeying interv

[strongSwan] [strongswan] ipsec SA rekeying

2009-12-28 Thread ashish mahalka
Hello Andreas, I have been trying to setup rekeying of both IKE SA annd IPSEC SA. But there is some confusion as to what is really the correct behaviour. I understand that there some attributes which need to be set : ikelifetime lifetime rekeymargin rekeyfuzz rekey reauth We have a requirement t