← Back to team overview

yahoo-eng-team team mailing list archive

[Bug 1726422] [NEW] ike version V2 incompatible with ike_phase1_mode

 

Public bug reported:

Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel.
Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode.
Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main","aggressive",null].
add aggressive mode to solve bug/1701413

** Affects: neutron
     Importance: Undecided
         Status: New

** Description changed:

- Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. 
- Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. 
- Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main",null].
+ Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel.
+ Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode.
+ Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main","aggressive",null].
+ add aggressive mode to solve bug/1701413

-- 
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1726422

Title:
  ike version V2  incompatible with ike_phase1_mode

Status in neutron:
  New

Bug description:
  Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel.
  Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode.
  Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main","aggressive",null].
  add aggressive mode to solve bug/1701413

To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1726422/+subscriptions