ikev2: fix non-matching SPIs during rekey 01/25501/1
authorFilip Tehlar <ftehlar@cisco.com>
Thu, 27 Feb 2020 13:14:52 +0000 (13:14 +0000)
committerFilip Tehlar <ftehlar@cisco.com>
Thu, 27 Feb 2020 13:14:52 +0000 (13:14 +0000)
Type:fix

Change-Id: I01ac57f6186b20d8ab4070b7259a82a150f0ae9a
Signed-off-by: Filip Tehlar <ftehlar@cisco.com>
src/plugins/ikev2/ikev2.c

index 55c9aa3..b0ed4f2 100644 (file)
@@ -1541,6 +1541,8 @@ ikev2_add_tunnel_from_main (ikev2_add_ipsec_tunnel_args_t * a)
   vec_add1 (sas_in, a->remote_sa_id);
   if (a->is_rekey)
     {
+      ipsec_tun_protect_del (sw_if_index, NULL);
+
       /* replace local SA immediately */
       ipsec_sa_unlock_id (a->local_sa_id);