Język

IkeSessionOption Enum

Definition

public enum IkeSessionOption
type IkeSessionOption = 
Inheritance
IkeSessionOption

Fields

Name Value Description
AcceptAnyRemoteId 0

If set, the IKE library will accept any remote (server) identity, even if it does not match the configured remote identity

See Builder.setRemoteIdentification(IkeIdentification)

Android reference for android.net.ipsec.ike.IkeSessionParams.IKE_OPTION_ACCEPT_ANY_REMOTE_ID.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

EapOnlyAuth 1

If set, and EAP has been configured as the authentication method, the IKE library will request that the remote (also) use an EAP-only authentication flow.

@see Builder.setAuthEap(X509Certificate,EapSessionConfig)

Android reference for android.net.ipsec.ike.IkeSessionParams.IKE_OPTION_EAP_ONLY_AUTH.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

Mobike 2

If set, the IKE Session will attempt to handle IP address changes using RFC4555 MOBIKE.

Upon IP address changes (including Network changes), the IKE session will initiate an RFC 4555 MOBIKE procedure, migrating both this IKE Session and associated IPsec Transforms to the new local and remote address pair.

Checking whether or not MOBIKE is supported by both the IKE library and the server in an IKE Session is done via IkeSessionConfiguration.isIkeExtensionEnabled(int).

It is recommended that IKE_OPTION_MOBIKE be enabled unless precluded for compatibility reasons.

If this option is set for an IKE Session, Transport-mode SAs will not be allowed in that Session.

Callers that need to perform migration of IPsec transforms and tunnels MUST implement migration specific methods in IkeSessionCallback and ChildSessionCallback.

Android reference for android.net.ipsec.ike.IkeSessionParams.IKE_OPTION_MOBIKE.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

ForcePort4500 3

Configures the IKE session to always send to port 4500.

If set, the IKE Session will be initiated and maintained exclusively using destination port 4500, regardless of the presence of NAT. Otherwise, the IKE Session will be initiated on destination port 500; then, if either a NAT is detected or both MOBIKE and NAT-T are supported by the peer, it will proceed on port 4500.

Android reference for android.net.ipsec.ike.IkeSessionParams.IKE_OPTION_FORCE_PORT_4500.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

InitialContact 4

If set, the IKE library will send INITIAL_CONTACT notification to the peers.

If this option is set, the INITIAL_CONTACT notification payload is sent in IKE_AUTH. The client can use this option to assert to the peer that this IKE SA is the only IKE SA currently active between the authenticated identities.

@see "https://tools.ietf.org/html/rfc7296#section-2.4" RFC 7296, Internet Key Exchange Protocol Version 2 (IKEv2)

@see Builder.addIkeOption(int)

Android reference for android.net.ipsec.ike.IkeSessionParams.IKE_OPTION_INITIAL_CONTACT.

Portions of this page are modifications based on work created and shared by the Android Open Source Project and used according to terms described in the Creative Commons 2.5 Attribution License.

Applies to