 maxusa Premium join:2004-05-05 USA
| reply to adiinfo Re: VPN reconnect
The reason for not dropping a dynamic tunnel appears to be that there is no way of knowing apriori that this is the same or different node/user calling. Suppose several users in the same remote site are trying to IPsec pass-through. During the initial IPsec negotiation, it is very difficult/risky to make a determination to drop something else. Besides this and obvious complexity, there might be other reasons.
In theory, the 2 timers, nailed-up/keepAlive, and chk_peer shall provide the solution. As we know, however, technology not always works as expected.  |