GET VPN - part eleven (multicast) - update
Update to GET VPN - part four (multicast) - http://myitmicroblog.svbtle.com/get-vpn-part-four
On one of my GMs I found a problem. It was registered but I didn’t see any ‘rekeys received’:
R3sh crypto gdoi gm rekey
Group GDOI-GROUP-GREEN
No rekey info available
Group GDOI-GROUP-RED (Multicast)
Number of Rekeys received (cumulative) : 0
Number of Rekeys received after registration : 0
Multicast destination address : 239.192.1.190
R3
I saw following messages:
R3
*Dec 20 06:06:04.404: %GDOI-4-GM_RE_REGISTER: The IPSec SA created for group GDOI-GROUP-RED may have expired/been cleared, or didn't go through. Re-register to KS.
R3
*Dec 20 06:06:04.412: %CRYPTO-5-GM_REGSTER: Start registration to KS 3.3.3.2 for group GDOI-GROUP-RED using address 7.7.7.2
*Dec 20 06:06:05.000: %GDOI-5-SA_KEK_UPDATED: SA KEK was updated
*Dec 20 06:06:05.008:
...