ikev2: add hint to the log when IDs do not match
Type: improvement
Ticket: VPP-1908
Change-Id: I1d86ea18fcb6174b86c449d5d9403fd0e5715318
Signed-off-by: Filip Tehlar <ftehlar@cisco.com>
diff --git a/src/plugins/ikev2/ikev2.c b/src/plugins/ikev2/ikev2.c
index 8bb3277..0236764 100644
--- a/src/plugins/ikev2/ikev2.c
+++ b/src/plugins/ikev2/ikev2.c
@@ -1666,7 +1666,11 @@
sel_p = p;
break;
}
-
+ else
+ {
+ ikev2_elog_uint (IKEV2_LOG_ERROR, "shared key mismatch! ispi %lx",
+ sa->ispi);
+ }
}
else if (sa_auth->method == IKEV2_AUTH_METHOD_RSA_SIG)
{
@@ -1679,6 +1683,11 @@
sel_p = p;
break;
}
+ else
+ {
+ ikev2_elog_uint (IKEV2_LOG_ERROR,
+ "cert verification failed! ispi %lx", sa->ispi);
+ }
}
vec_free(auth);