A method to prevent dpd detection failure from causing ipsec tunnel flapping
A technology for tunnel flapping and packet detection, applied in the field of computer networks
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0025] The following is a detailed description of the method for preventing ipsec tunnel oscillation caused by dpd detection failure proposed by the present invention with reference to the accompanying drawings and embodiments.
[0026] In the prior art, when the ipsec peer sends a dpd message to the opposite ipsec peer, if the opposite ipsec peer cannot find the ikesa with the same cookie in the dpd message, then It means that the dpd packet cannot be processed, so it is directly discarded. When the ipsec peer sends 5 dpd packets in a row and still does not respond to the dpd packet, it means that the link is abnormal and the ikesa corresponding to the local dpd will be deleted. At the same time, delete the ipsecsa whose original address and destination address are the same as this ikesa, which will cause the ipsec tunnel to oscillate.
[0027] Such as figure 1 As shown, the present invention provides a method for preventing ipsec tunnel oscillation caused by dpd detection failur...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 