Page MenuHomeVyOS Platform

Lower IPSec DPD timeout lower limit from 10s -> 2s
Closed, ResolvedPublicFEATURE REQUEST

Description

Right now the lower limit of the Dead-Peer-Detection timeout is 10 seconds. This could be lowered down to 2 for faster reaction of DPD.

vyatta-cfg-vpn: /opt/vyatta/share/vyatta-cfg/templates/vpn/ipsec/ike-group/node.tag/dead-peer-detection/timeout/node.def

I manually changed this for testing and the tunnels are up and running.

Details

Difficulty level
Easy (less than an hour)
Version
1.2.3
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Unspecified (possibly destroys the router)

Event Timeline

c-po changed the task status from Open to In progress.Dec 8 2019, 11:58 AM
c-po claimed this task.
c-po triaged this task as Low priority.
c-po created this task.
c-po changed Version from - to 1.2.3.
c-po changed the task status from In progress to Backport pending.Dec 8 2019, 12:04 PM
c-po raised the priority of this task from Low to Normal.
c-po changed Difficulty level from Unknown (require assessment) to Easy (less than an hour).
c-po moved this task from Need Triage to Finished on the VyOS 1.3 Equuleus board.
c-po moved this task from Needs Triage to Backlog on the VyOS 1.2 Crux (VyOS 1.2.4) board.
c-po moved this task from VyOS 1.2.4 to VyOS 1.2.5 on the VyOS 1.2 Crux board.
c-po moved this task from Needs Triage to Finished on the VyOS 1.2 Crux (VyOS 1.2.5) board.