跳转到主内容

CONTAP-183882:IKE SA 重新协商可能在接管/交还事件期间失败

Views:
6
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
core
Last Updated:

问题描述

  • 作为接管/回转事件的一部分,所有 IKE 和 IPsec SA 必须在短时间内重新协商。
  • 这可能会使系统不堪重负,并导致 SA 协商超时。
  • 为解决某些 SA 协商边缘情况而引入的快速重试逻辑,可能会加剧这种情况。

启用快速重试逻辑后,charon 日志将包含与以下条目类似的日志条目:
  • [[MGR] checkout_by_message() IKE_SA 未找到 SPIs *****_i *****_r.]
  • [[NET]process_message_job.c: 快速恢复逻辑,寻找匹配 **** 到 **** 的任何身份的对等配置。]
  • [[MGR]ike_sa_manager.c:create_new() IKEv2 SA 带有 SPIs *****.]
  • [[NET]process_message_job.c: 将快速恢复逻辑应用于新的 IKE SA。]
  • [[IKE] 启动 IKE_SA ***** 到 ******.]

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.