-fix time assertion introduce in last patch
[oweals/gnunet.git] / src / transport / gnunet-service-transport_neighbours.c
index 21d40d9be48bf9fcb673d3abf7306121520aef9e..6c51d20d838ac530f1bd82bbeb877f73780610b5 100644 (file)
@@ -22,9 +22,6 @@
  * @file transport/gnunet-service-transport_neighbours.c
  * @brief neighbour management
  * @author Christian Grothoff
- *
- * TODO:
- * - TEST, TEST, TEST...
  */
 #include "platform.h"
 #include "gnunet_ats_service.h"
@@ -49,7 +46,7 @@
  * Time we give plugin to transmit DISCONNECT message before the
  * neighbour entry self-destructs.
  */
-#define DISCONNECT_SENT_TIMEOUT GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS, 100)
+#define DISCONNECT_SENT_TIMEOUT GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_MILLISECONDS, 500)
 
 /**
  * How often must a peer violate bandwidth quotas before we start
  */
 #define QUOTA_VIOLATION_DROP_THRESHOLD 10
 
-/**
- * How often do we send KEEPALIVE messages to each of our neighbours and measure
- * the latency with this neighbour?
- * (idle timeout is 5 minutes or 300 seconds, so with 100s interval we
- * send 3 keepalives in each interval, so 3 messages would need to be
- * lost in a row for a disconnect).
- */
-#define KEEPALIVE_FREQUENCY GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_SECONDS, 100)
-
 /**
  * How long are we willing to wait for a response from ATS before timing out?
  */
  */
 #define UTIL_TRANSMISSION_INTERVAL GNUNET_TIME_relative_multiply (GNUNET_TIME_UNIT_SECONDS, 1)
 
+/**
+ * State describing which kind a reply this neighbour should send
+ */
+enum GST_ACK_State
+{
+  /**
+   * We did not receive a CONNECT message for this neighbour
+   */
+  ACK_UNDEFINED = 0,
+
+  /* The neighbour received a CONNECT message and has to send a CONNECT_ACK
+   * as reply */
+  ACK_SEND_CONNECT_ACK = 1,
+
+  /* The neighbour sent a CONNECT_ACK message and has to send a SESSION_ACK
+   * as reply */
+  ACK_SEND_SESSION_ACK = 2
+};
+
+
 GNUNET_NETWORK_STRUCT_BEGIN
 
 /**
@@ -128,6 +136,28 @@ struct SessionConnectMessage
 };
 
 
+/**
+ * Message a peer sends to another when connected to indicate that a
+ * session is in use and the peer is still alive or to respond to a keep alive.
+ * A peer sends a message with type #GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE
+ * to request a message with #GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE_RESPONSE.
+ * When the keep alive response with type is received, transport service
+ * will call the respective plugin to update the session timeout
+ */
+struct SessionKeepAliveMessage
+{
+  /**
+   * Header of type #GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE or
+   * #GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE_RESPONSE.
+   */
+  struct GNUNET_MessageHeader header;
+
+  /**
+   * A nonce to identify the session the keep alive is used for
+   */
+  uint32_t nonce GNUNET_PACKED;
+};
+
 /**
  * Message we send to the other peer to notify him that we intentionally
  * are disconnecting (to reduce timeouts).  This is just a friendly
@@ -221,167 +251,6 @@ struct MessageQueue
 };
 
 
-/**
- * Possible state of a neighbour.  Initially, we are #S_NOT_CONNECTED.
- *
- * Then, there are two main paths. If we receive a CONNECT message, we
- * first run a check against the blacklist (#S_CONNECT_RECV_BLACKLIST_INBOUND).
- * If this check is successful, we give the inbound address to ATS.
- * After the check we ask ATS for a suggestion (S_CONNECT_RECV_ATS).
- * If ATS makes a suggestion, we ALSO give that suggestion to the blacklist
- * (#S_CONNECT_RECV_BLACKLIST).  Once the blacklist approves the
- * address we got from ATS, we send our CONNECT_ACK and go to
- * #S_CONNECT_RECV_ACK.  If we receive a SESSION_ACK, we go to
- * #S_CONNECTED (and notify everyone about the new connection).  If the
- * operation times out, we go to #S_DISCONNECT.
- *
- * The other case is where we transmit a CONNECT message first.  We
- * start with #S_INIT_ATS.  If we get an address, we enter
- * #S_INIT_BLACKLIST and check the blacklist.  If the blacklist is OK
- * with the connection, we actually send the CONNECT message and go to
- * state S_CONNECT_SENT.  Once we receive a CONNECT_ACK, we go to
- * #S_CONNECTED (and notify everyone about the new connection and send
- * back a SESSION_ACK).  If the operation times out, we go to
- * #S_DISCONNECT.
- *
- * If the session is in trouble (i.e. transport-level disconnect or
- * timeout), we go to #S_RECONNECT_ATS where we ask ATS for a new
- * address (we don't notify anyone about the disconnect yet).  Once we
- * have a new address, we go to #S_RECONNECT_BLACKLIST to check the new
- * address against the blacklist.  If the blacklist approves, we enter
- * #S_RECONNECT_SENT and send a CONNECT message.  If we receive a
- * #CONNECT_ACK, we go to #S_CONNECTED and nobody noticed that we had
- * trouble; we also send a SESSION_ACK at this time just in case.  If
- * the operation times out, we go to S_DISCONNECT (and notify everyone
- * about the lost connection).
- *
- * If ATS decides to switch addresses while we have a normal
- * connection, we go to #S_CONNECTED_SWITCHING_BLACKLIST to check the
- * new address against the blacklist.  If the blacklist approves, we
- * go to #S_CONNECTED_SWITCHING_CONNECT_SENT and send a
- * SESSION_CONNECT.  If we get a SESSION_ACK back, we switch the
- * primary connection to the suggested alternative from ATS, go back
- * to #S_CONNECTED and send a SESSION_ACK to the other peer just to be
- * sure.  If the operation times out (or the blacklist disapproves),
- * we go to #S_CONNECTED (and notify ATS that the given alternative
- * address is "invalid").
- *
- * Once a session is in #S_DISCONNECT, it is cleaned up and then goes
- * to (#S_DISCONNECT_FINISHED).  If we receive an explicit disconnect
- * request, we can go from any state to #S_DISCONNECT, possibly after
- * generating disconnect notifications.
- *
- * Note that it is quite possible that while we are in any of these
- * states, we could receive a 'CONNECT' request from the other peer.
- * We then enter a 'weird' state where we pursue our own primary state
- * machine (as described above), but with the 'send_connect_ack' flag
- * set to 1.  If our state machine allows us to send a 'CONNECT_ACK'
- * (because we have an acceptable address), we send the 'CONNECT_ACK'
- * and set the 'send_connect_ack' to 2.  If we then receive a
- * 'SESSION_ACK', we go to #S_CONNECTED (and reset 'send_connect_ack'
- * to 0).
- *
- */
-enum State
-{
-  /**
-   * fresh peer or completely disconnected
-   */
-  S_NOT_CONNECTED = 0,
-
-  /**
-   * Asked to initiate connection, trying to get address from ATS
-   */
-  S_INIT_ATS,
-
-  /**
-   * Asked to initiate connection, trying to get address approved
-   * by blacklist.
-   */
-  S_INIT_BLACKLIST,
-
-  /**
-   * Sent CONNECT message to other peer, waiting for CONNECT_ACK
-   */
-  S_CONNECT_SENT,
-
-  /**
-   * Received a CONNECT, do a blacklist check for inbound address
-   */
-  S_CONNECT_RECV_BLACKLIST_INBOUND,
-
-  /**
-   * Received a CONNECT, asking ATS about address suggestions.
-   */
-  S_CONNECT_RECV_ATS,
-
-  /**
-   * Received CONNECT from other peer, got an address, checking with blacklist.
-   */
-  S_CONNECT_RECV_BLACKLIST,
-
-  /**
-   * CONNECT request from other peer was SESSION_ACK'ed, waiting for
-   * SESSION_ACK.
-   */
-  S_CONNECT_RECV_ACK,
-
-  /**
-   * Got our CONNECT_ACK/SESSION_ACK, connection is up.
-   */
-  S_CONNECTED,
-
-  /**
-   * Connection got into trouble, rest of the system still believes
-   * it to be up, but we're getting a new address from ATS.
-   */
-  S_RECONNECT_ATS,
-
-  /**
-   * Connection got into trouble, rest of the system still believes
-   * it to be up; we are checking the new address against the blacklist.
-   */
-  S_RECONNECT_BLACKLIST,
-
-  /**
-   * Sent CONNECT over new address (either by ATS telling us to switch
-   * addresses or from RECONNECT_ATS); if this fails, we need to tell
-   * the rest of the system about a disconnect.
-   */
-  S_RECONNECT_SENT,
-
-  /**
-   * We have some primary connection, but ATS suggested we switch
-   * to some alternative; we're now checking the alternative against
-   * the blacklist.
-   */
-  S_CONNECTED_SWITCHING_BLACKLIST,
-
-  /**
-   * We have some primary connection, but ATS suggested we switch
-   * to some alternative; we now sent a CONNECT message for the
-   * alternative session to the other peer and waiting for a
-   * CONNECT_ACK to make this our primary connection.
-   */
-  S_CONNECTED_SWITCHING_CONNECT_SENT,
-
-  /**
-   * Disconnect in progress (we're sending the DISCONNECT message to the
-   * other peer; after that is finished, the state will be cleaned up).
-   */
-  S_DISCONNECT,
-
-  /**
-   * We're finished with the disconnect; and are cleaning up the state
-   * now!  We put the struct into this state when we are really in the
-   * task that calls 'free' on it and are about to remove the record
-   * from the map.  We should never find a 'struct NeighbourMapEntry'
-   * in this state in the map.  Accessing a 'struct NeighbourMapEntry'
-   * in this state virtually always means using memory that has been
-   * freed (the exception being the cleanup code in 'free_neighbour').
-   */
-  S_DISCONNECT_FINISHED
-};
 
 
 /**
@@ -422,9 +291,12 @@ struct NeighbourAddress
    */
   int ats_active;
 
+  /**
+   * The current nonce sent in the last keep alive messages
+   */
+  uint32_t keep_alive_nonce;
 };
 
-
 /**
  * Entry in neighbours.
  */
@@ -470,6 +342,11 @@ struct NeighbourMapEntry
    */
   GNUNET_SCHEDULER_TaskIdentifier task;
 
+  /**
+   * Task to disconnect neighbour after we received a DISCONNECT message
+   */
+  GNUNET_SCHEDULER_TaskIdentifier delayed_disconnect_task;
+
   /**
    * At what time should we sent the next keep-alive message?
    */
@@ -483,7 +360,7 @@ struct NeighbourMapEntry
 
   /**
    * Timestamp we should include in our next CONNECT_ACK message.
-   * (only valid if 'send_connect_ack' is GNUNET_YES).  Used to build
+   * (only valid if 'send_connect_ack' is #GNUNET_YES).  Used to build
    * our CONNECT_ACK message.
    */
   struct GNUNET_TIME_Absolute connect_ack_timestamp;
@@ -520,7 +397,7 @@ struct NeighbourMapEntry
   /**
    * The current state of the peer.
    */
-  enum State state;
+  enum GNUNET_TRANSPORT_PeerState state;
 
   /**
    * Did we sent an KEEP_ALIVE message and are we expecting a response?
@@ -528,13 +405,19 @@ struct NeighbourMapEntry
   int expect_latency_response;
 
   /**
+   * When a peer wants to connect we have to reply to the 1st CONNECT message
+   * with a CONNECT_ACK message. But sometime we cannot send this message
+   * immediately since we do not have an address and then we have to remember
+   * to send this message as soon as we have an address.
+   *
    * Flag to set if we still need to send a CONNECT_ACK message to the other peer
    * (once we have an address to use and the peer has been allowed by our
-   * blacklist).  Set to 1 if we need to send a CONNECT_ACK.  Set to 2 if we
-   * did send a CONNECT_ACK and should go to 'S_CONNECTED' upon receiving
-   * a 'SESSION_ACK' (regardless of what our own state machine might say).
+   * blacklist).  Initially set to #ACK_UNDEFINED. Set to #ACK_SEND_CONNECT_ACK
+   * if we need to send a CONNECT_ACK.  Set to #ACK_SEND_SESSION_ACK if we did
+   * send a CONNECT_ACK and should go to 'S_CONNECTED' upon receiving a
+   * 'SESSION_ACK' (regardless of what our own state machine might say).
    */
-  int send_connect_ack;
+  enum GST_ACK_State ack_state;
 
   /**
    * Tracking utilization of outbound bandwidth
@@ -564,7 +447,7 @@ struct NeighbourMapEntry
 
 
 /**
- * Context for blacklist checks and the 'handle_test_blacklist_cont'
+ * Context for blacklist checks and the #try_connect_bl_check_cont()
  * function.  Stores information about ongoing blacklist checks.
  */
 struct BlackListCheckContext
@@ -610,7 +493,17 @@ static struct BlackListCheckContext *bc_head;
 static struct BlackListCheckContext *bc_tail;
 
 /**
- * Closure for #connect_notify_cb, #disconnect_notify_cb and #address_change_cb
+ * List of pending blacklist checks: head
+ */
+static struct BlacklistCheckSwitchContext *pending_bc_head;
+
+/**
+ * List of pending blacklist checks: tail
+ */
+static struct BlacklistCheckSwitchContext *pending_bc_tail;
+
+/**
+ * Closure for #connect_notify_cb, #disconnect_notify_cb and #neighbour_change_cb
  */
 static void *callback_cls;
 
@@ -625,9 +518,9 @@ static NotifyConnect connect_notify_cb;
 static GNUNET_TRANSPORT_NotifyDisconnect disconnect_notify_cb;
 
 /**
- * Function to call when we changed an active address of a neighbour.
+ * Function to call when a neighbour changed address, state or bandwidth.
  */
-static GNUNET_TRANSPORT_PeerIterateCallback address_change_cb;
+static GNUNET_TRANSPORT_NeighbourChangeCallback neighbour_change_cb;
 
 /**
  * counter for connected neighbours
@@ -645,6 +538,24 @@ static unsigned long long bytes_in_send_queue;
 static GNUNET_SCHEDULER_TaskIdentifier util_transmission_tk;
 
 
+static struct GNUNET_CONTAINER_MultiPeerMap *registered_quota_notifications;
+
+static char *
+print_ack_state (enum GST_ACK_State s)
+{
+  switch (s) {
+    case ACK_UNDEFINED:
+      return "UNDEFINED";
+    case ACK_SEND_CONNECT_ACK:
+      return "SEND_CONNECT_ACK";
+    case ACK_SEND_SESSION_ACK:
+      return "SEND_SESSION_ACK";
+    default:
+      GNUNET_break (0);
+      return "N/A";
+  }
+}
+
 /**
  * Lookup a neighbour entry in the neighbours hash map.
  *
@@ -660,50 +571,6 @@ lookup_neighbour (const struct GNUNET_PeerIdentity *pid)
 }
 
 
-static const char *
-print_state (int state)
-{
-
-  switch (state)
-  {
-  case S_NOT_CONNECTED:
-    return "S_NOT_CONNECTED";
-  case S_INIT_ATS:
-    return "S_INIT_ATS";
-  case S_INIT_BLACKLIST:
-    return "S_INIT_BLACKLIST";
-  case S_CONNECT_SENT:
-    return "S_CONNECT_SENT";
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-    return "S_CONNECT_RECV_BLACKLIST_INBOUND";
-  case S_CONNECT_RECV_ATS:
-    return "S_CONNECT_RECV_ATS";
-  case S_CONNECT_RECV_BLACKLIST:
-    return "S_CONNECT_RECV_BLACKLIST";
-  case S_CONNECT_RECV_ACK:
-    return "S_CONNECT_RECV_ACK";
-  case S_CONNECTED:
-    return "S_CONNECTED";
-  case S_RECONNECT_ATS:
-    return "S_RECONNECT_ATS";
-  case S_RECONNECT_BLACKLIST:
-    return "S_RECONNECT_BLACKLIST";
-  case S_RECONNECT_SENT:
-    return "S_RECONNECT_SENT";
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    return "S_CONNECTED_SWITCHING_BLACKLIST";
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-    return "S_CONNECTED_SWITCHING_CONNECT_SENT";
-  case S_DISCONNECT:
-    return "S_DISCONNECT";
-  case S_DISCONNECT_FINISHED:
-    return "S_DISCONNECT_FINISHED";
-  default:
-    GNUNET_break (0);
-    return "UNDEFINED";
-  }
-}
-
 /**
  * Test if we're connected to the given peer.
  *
@@ -715,35 +582,7 @@ test_connected (struct NeighbourMapEntry *n)
 {
   if (NULL == n)
     return GNUNET_NO;
-  switch (n->state)
-  {
-  case S_NOT_CONNECTED:
-  case S_INIT_ATS:
-  case S_INIT_BLACKLIST:
-  case S_CONNECT_SENT:
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
-    return GNUNET_NO;
-  case S_CONNECTED:
-  case S_RECONNECT_ATS:
-  case S_RECONNECT_BLACKLIST:
-  case S_RECONNECT_SENT:
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-    return GNUNET_YES;
-  case S_DISCONNECT:
-  case S_DISCONNECT_FINISHED:
-    return GNUNET_NO;
-  default:
-    GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
-                "Unhandled state `%s' \n",
-                print_state (n->state));
-    GNUNET_break (0);
-    break;
-  }
-  return GNUNET_SYSERR;
+  return GNUNET_TRANSPORT_is_connected (n->state);
 }
 
 /**
@@ -774,19 +613,21 @@ send_outbound_quota (const struct GNUNET_PeerIdentity *target,
  * Release its resources and give appropriate notifications
  * to ATS and other subsystems.
  *
- * @param na address we are done with; 'na' itself must NOT be 'free'd, only the contents!
+ * @param na address we are done with; @a na itself must NOT be 'free'd, only the contents!
  */
 static void
 free_address (struct NeighbourAddress *na)
 {
   if (GNUNET_YES == na->ats_active)
   {
-    GST_validation_set_address_use (na->address, na->session, GNUNET_NO, __LINE__);
+    GST_validation_set_address_use (na->address, na->session, GNUNET_NO);
     GNUNET_ATS_address_in_use (GST_ats, na->address, na->session, GNUNET_NO);
-    address_change_cb (callback_cls, &na->address->peer, NULL);
   }
 
+  na->bandwidth_in = GNUNET_BANDWIDTH_value_init (0);
+  na->bandwidth_out = GNUNET_BANDWIDTH_value_init (0);
   na->ats_active = GNUNET_NO;
+  na->keep_alive_nonce = 0;
   if (NULL != na->address)
   {
     GNUNET_HELLO_address_free (na->address);
@@ -797,9 +638,136 @@ free_address (struct NeighbourAddress *na)
 
 
 /**
- * Initialize the 'struct NeighbourAddress'.
+ * Set net state for this neighbour and notify monitoring
+ *
+ * @param n the respective neighbour
+ * @param s the new state
+ */
+static void
+set_state (struct NeighbourMapEntry *n, enum GNUNET_TRANSPORT_PeerState s)
+{
+  n->state = s;
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO, "Neighbour `%s' changed state to %s\n",
+      GNUNET_i2s (&n->id),
+      GNUNET_TRANSPORT_ps2s(s));
+  neighbour_change_cb (callback_cls,
+      &n->id,
+      n->primary_address.address,
+      n->state, n->timeout,
+      n->primary_address.bandwidth_in,
+      n->primary_address.bandwidth_out);
+}
+
+
+/**
+ * Set net state and state timeout for this neighbour and notify monitoring
+ *
+ * @param n the respective neighbour
+ * @param s the new state
+ * @param timeout the new timeout
+ */
+static void
+set_state_and_timeout (struct NeighbourMapEntry *n,
+    enum GNUNET_TRANSPORT_PeerState s,
+    struct GNUNET_TIME_Absolute timeout)
+{
+  n->state = s;
+  n->timeout = timeout;
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO, "Neighbour `%s' changed state to %s with timeout %s\n",
+      GNUNET_i2s (&n->id),
+      GNUNET_TRANSPORT_ps2s(s),
+      GNUNET_STRINGS_absolute_time_to_string (timeout));
+  neighbour_change_cb (callback_cls,
+      &n->id,
+      n->primary_address.address,
+      n->state, n->timeout,
+      n->primary_address.bandwidth_in,
+      n->primary_address.bandwidth_out);
+}
+
+
+/**
+ * Set new state timeout for this neighbour and notify monitoring
+ *
+ * @param n the respective neighbour
+ * @param timeout the new timeout
+ */
+static void
+set_timeout (struct NeighbourMapEntry *n,
+    struct GNUNET_TIME_Absolute timeout)
+{
+  n->timeout = timeout;
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Neighbour `%s' changed timeout %s\n",
+      GNUNET_i2s (&n->id),
+      GNUNET_STRINGS_absolute_time_to_string (timeout));
+  neighbour_change_cb (callback_cls,
+      &n->id,
+      n->primary_address.address,
+      n->state, n->timeout,
+      n->primary_address.bandwidth_in,
+      n->primary_address.bandwidth_out);
+}
+
+
+/**
+ * Initialize the alternative address of a neighbour
+ *
+ * @param n the neighbour
+ * @param address address of the other peer, NULL if other peer
+ *                       connected to us
+ * @param session session to use (or NULL, in which case an
+ *        address must be setup)
+ * @param bandwidth_in inbound quota to be used when connection is up
+ * @param bandwidth_out outbound quota to be used when connection is up
+ */
+static void
+set_alternative_address (struct NeighbourMapEntry *n,
+             const struct GNUNET_HELLO_Address *address,
+             struct Session *session,
+             struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in,
+             struct GNUNET_BANDWIDTH_Value32NBO bandwidth_out)
+{
+  struct GNUNET_TRANSPORT_PluginFunctions *papi;
+  if (NULL == (papi = GST_plugins_find (address->transport_name)))
+  {
+    GNUNET_break (0);
+    return;
+  }
+  if (session == n->alternative_address.session)
+  {
+    n->alternative_address.bandwidth_in = bandwidth_in;
+    n->alternative_address.bandwidth_out = bandwidth_out;
+    return;
+  }
+  free_address (&n->alternative_address);
+  if (NULL == session)
+    session = papi->get_session (papi->cls, address);
+  if (NULL == session)
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                "Failed to obtain new session for peer `%s' and  address '%s'\n",
+                GNUNET_i2s (&address->peer), GST_plugins_a2s (address));
+    GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+    return;
+  }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO, "Neighbour `%s' configured alternative address %s\n",
+      GNUNET_i2s (&n->id),
+      GST_plugins_a2s(address));
+
+  n->alternative_address.address = GNUNET_HELLO_address_copy (address);
+  n->alternative_address.bandwidth_in = bandwidth_in;
+  n->alternative_address.bandwidth_out = bandwidth_out;
+  n->alternative_address.session = session;
+  n->alternative_address.ats_active = GNUNET_NO;
+  n->alternative_address.keep_alive_nonce = 0;
+}
+
+
+/**
+ * Initialize the primary address of a neighbour
  *
- * @param na neighbour address to initialize
+ * @param n the neighbour
  * @param address address of the other peer, NULL if other peer
  *                       connected to us
  * @param session session to use (or NULL, in which case an
@@ -809,7 +777,7 @@ free_address (struct NeighbourAddress *na)
  * @param is_active #GNUNET_YES to mark this as the active address with ATS
  */
 static void
-set_address (struct NeighbourAddress *na,
+set_primary_address (struct NeighbourMapEntry *n,
             const struct GNUNET_HELLO_Address *address,
             struct Session *session,
             struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in,
@@ -817,32 +785,30 @@ set_address (struct NeighbourAddress *na,
             int is_active)
 {
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
+
   if (NULL == (papi = GST_plugins_find (address->transport_name)))
   {
     GNUNET_break (0);
     return;
   }
-  if (session == na->session)
+  if (session == n->primary_address.session)
   {
-    na->bandwidth_in = bandwidth_in;
-    na->bandwidth_out = bandwidth_out;
-    if (is_active != na->ats_active)
+    n->primary_address.bandwidth_in = bandwidth_in;
+    n->primary_address.bandwidth_out = bandwidth_out;
+    if (is_active != n->primary_address.ats_active)
     {
-      na->ats_active = is_active;
-      GNUNET_ATS_address_in_use (GST_ats, na->address, na->session, is_active);
-      GST_validation_set_address_use (na->address, na->session, is_active,  __LINE__);
-      if (is_active)
-        address_change_cb (callback_cls, &address->peer, address);
+      n->primary_address.ats_active = is_active;
+      GNUNET_ATS_address_in_use (GST_ats, n->primary_address.address, n->primary_address.session, is_active);
+      GST_validation_set_address_use (n->primary_address.address, n->primary_address.session, is_active);
     }
     if (GNUNET_YES == is_active)
     {
-      /* FIXME: is this the right place to set quotas? */
       GST_neighbours_set_incoming_quota (&address->peer, bandwidth_in);
       send_outbound_quota (&address->peer, bandwidth_out);
     }
     return;
   }
-  free_address (na);
+  free_address (&n->primary_address);
   if (NULL == session)
     session = papi->get_session (papi->cls, address);
   if (NULL == session)
@@ -853,38 +819,86 @@ set_address (struct NeighbourAddress *na,
     GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
     return;
   }
-  na->address = GNUNET_HELLO_address_copy (address);
-  na->bandwidth_in = bandwidth_in;
-  na->bandwidth_out = bandwidth_out;
-  na->session = session;
-  na->ats_active = is_active;
+
+  n->primary_address.address = GNUNET_HELLO_address_copy (address);
+  n->primary_address.bandwidth_in = bandwidth_in;
+  n->primary_address.bandwidth_out = bandwidth_out;
+  n->primary_address.session = session;
+  n->primary_address.ats_active = is_active;
+  n->primary_address.keep_alive_nonce = 0;
   if (GNUNET_YES == is_active)
   {
     /* Telling ATS about new session */
-    GNUNET_ATS_address_in_use (GST_ats, na->address, na->session, GNUNET_YES);
-    GST_validation_set_address_use (na->address, na->session, GNUNET_YES,  __LINE__);
-    address_change_cb (callback_cls, &address->peer, address);
-    /* FIXME: is this the right place to set quotas? */
+    GNUNET_ATS_address_in_use (GST_ats, n->primary_address.address, n->primary_address.session, GNUNET_YES);
+    GST_validation_set_address_use (n->primary_address.address, n->primary_address.session, GNUNET_YES);
     GST_neighbours_set_incoming_quota (&address->peer, bandwidth_in);
     send_outbound_quota (&address->peer, bandwidth_out);
   }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO, "Neighbour `%s' switched to address `%s'\n",
+      GNUNET_i2s (&n->id),
+      GST_plugins_a2s(address));
+
+  neighbour_change_cb (callback_cls,
+      &n->id,
+      n->primary_address.address,
+      n->state, n->timeout,
+      n->primary_address.bandwidth_in,
+      n->primary_address.bandwidth_out);
+}
+
+/**
+ * Clear the primary address of a neighbour since this address is not
+ * valid anymore and notify monitoring about it
+ *
+ * @param n the neighbour
+ */
+static void
+unset_primary_address (struct NeighbourMapEntry *n)
+{
+  /* Unset primary address */
+  free_address (&n->primary_address);
+
+  /* Notify monitoring about it */
+  neighbour_change_cb (callback_cls,
+      &n->id,
+      NULL,
+      n->state, n->timeout,
+      n->primary_address.bandwidth_in,
+      n->primary_address.bandwidth_out);
 }
 
+/**
+ * Clear the alternative address of a neighbour since this address is not
+ * valid anymore
+ *
+ * @param n the neighbour
+ */
+static void
+unset_alternative_address (struct NeighbourMapEntry *n)
+{
+  /* Unset primary address */
+  free_address (&n->alternative_address);
+}
 
 /**
  * Free a neighbour map entry.
  *
  * @param n entry to free
- * @param keep_sessions GNUNET_NO to tell plugin to terminate sessions,
- *                      GNUNET_YES to keep all sessions
+ * @param keep_sessions #GNUNET_NO to tell plugin to terminate sessions,
+ *                      #GNUNET_YES to keep all sessions
  */
 static void
-free_neighbour (struct NeighbourMapEntry *n, int keep_sessions)
+free_neighbour (struct NeighbourMapEntry *n,
+                int keep_sessions)
 {
   struct MessageQueue *mq;
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
   struct GNUNET_HELLO_Address *backup_primary;
 
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+              "Freeing neighbour state of peer `%s'\n",
+              GNUNET_i2s (&n->id));
   n->is_active = NULL; /* always free'd by its own continuation! */
 
   /* fail messages currently in the queue */
@@ -905,51 +919,46 @@ free_neighbour (struct NeighbourMapEntry *n, int keep_sessions)
                           GNUNET_NO);
     disconnect_notify_cb (callback_cls, &n->id);
   }
-  n->state = S_DISCONNECT_FINISHED;
+
+  /* Mark peer as disconnected */
+  set_state (n, GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED);
 
   if (NULL != n->primary_address.address)
-  {
-    backup_primary = GNUNET_HELLO_address_copy(n->primary_address.address);
-  }
+    backup_primary = GNUNET_HELLO_address_copy (n->primary_address.address);
   else
     backup_primary = NULL;
 
   /* free addresses and mark as unused */
-  free_address (&n->primary_address);
+  unset_primary_address (n);
   free_address (&n->alternative_address);
 
-  /* FIXME-PLUGIN-API: This does not seem to guarantee that all
-     transport sessions eventually get killed due to inactivity; they
-     MUST have their own timeout logic (but at least TCP doesn't have
-     one yet).  Are we sure that EVERY 'session' of a plugin is
-     actually cleaned up this way!?  Note that if we are switching
-     between two TCP sessions to the same peer, the existing plugin
-     API gives us not even the means to selectively kill only one of
-     them! Killing all sessions like this seems to be very, very
-     wrong. */
-
-  /* cut transport-level connection */
+  /* cut all transport-level connection for this peer */
   if ((GNUNET_NO == keep_sessions) &&
       (NULL != backup_primary) &&
       (NULL != (papi = GST_plugins_find (backup_primary->transport_name))))
-    papi->disconnect (papi->cls, &n->id);
-
-  GNUNET_free_non_null (backup_primary);
+    papi->disconnect_peer (papi->cls, &n->id);
 
+  if (NULL != backup_primary)
+    GNUNET_HELLO_address_free (backup_primary);
   GNUNET_assert (GNUNET_YES ==
                  GNUNET_CONTAINER_multipeermap_remove (neighbours,
                                                        &n->id, n));
 
-  // FIXME-ATS-API: we might want to be more specific about
-  // which states we do this from in the future (ATS should
-  // have given us a 'suggest_address' handle, and if we have
-  // such a handle, we should cancel the operation here!
+  /* Cancel address requests for this peer */
   if (NULL != n->suggest_handle)
   {
     GNUNET_ATS_suggest_address_cancel (GST_ats, &n->id);
     n->suggest_handle = NULL;
   }
 
+  /* Cancel the disconnect task */
+  if (GNUNET_SCHEDULER_NO_TASK != n->delayed_disconnect_task)
+  {
+    GNUNET_SCHEDULER_cancel (n->delayed_disconnect_task);
+    n->delayed_disconnect_task = GNUNET_SCHEDULER_NO_TASK;
+  }
+
+  /* Cancel the master task */
   if (GNUNET_SCHEDULER_NO_TASK != n->task)
   {
     GNUNET_SCHEDULER_cancel (n->task);
@@ -959,27 +968,34 @@ free_neighbour (struct NeighbourMapEntry *n, int keep_sessions)
   GNUNET_free (n);
 }
 
+
 /**
  * Transmit a message using the current session of the given
  * neighbour.
  *
  * @param n entry for the recipient
  * @param msgbuf buffer to transmit
- * @param msgbuf_size number of bytes in buffer
+ * @param msgbuf_size number of bytes in @a msgbuf buffer
  * @param priority transmission priority
  * @param timeout transmission timeout
+ * @param use_keepalive_timeout #GNUNET_YES to use plugin-specific keep-alive
+ *        timeout (@a timeout is ignored in that case), #GNUNET_NO otherwise
  * @param cont continuation to call when finished (can be NULL)
- * @param cont_cls closure for cont
+ * @param cont_cls closure for @a cont
+ * @return timeout (copy of @a timeout or a calculated one if
+ *         @a use_keepalive_timeout is #GNUNET_YES.
  */
-static void
+static struct GNUNET_TIME_Relative
 send_with_session (struct NeighbourMapEntry *n,
                    const char *msgbuf, size_t msgbuf_size,
                    uint32_t priority,
                    struct GNUNET_TIME_Relative timeout,
+                  unsigned int use_keepalive_timeout,
                    GNUNET_TRANSPORT_TransmitContinuation cont,
                   void *cont_cls)
 {
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
+  struct GNUNET_TIME_Relative result = GNUNET_TIME_UNIT_FOREVER_REL;
 
   GNUNET_assert (n->primary_address.session != NULL);
   if ( ((NULL == (papi = GST_plugins_find (n->primary_address.address->transport_name)) ||
@@ -987,13 +1003,16 @@ send_with_session (struct NeighbourMapEntry *n,
                            n->primary_address.session,
                            msgbuf, msgbuf_size,
                            priority,
-                           timeout,
+                           (result = (GNUNET_NO == use_keepalive_timeout) ? timeout :
+                               GNUNET_TIME_relative_divide (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT,
+                                                            papi->query_keepalive_factor (papi->cls))),
                            cont, cont_cls)))) &&
        (NULL != cont))
     cont (cont_cls, &n->id, GNUNET_SYSERR, msgbuf_size, 0);
   GST_neighbours_notify_data_sent (&n->id,
       n->primary_address.address, n->primary_address.session, msgbuf_size);
   GNUNET_break (NULL != papi);
+  return result;
 }
 
 
@@ -1002,7 +1021,7 @@ send_with_session (struct NeighbourMapEntry *n,
  * activities (keep alive, send next message, disconnect if idle, finish
  * clean up after disconnect).
  *
- * @param cls the 'struct NeighbourMapEntry' for which we are running
+ * @param cls the `struct NeighbourMapEntry` for which we are running
  * @param tc scheduler context (unused)
  */
 static void
@@ -1029,7 +1048,7 @@ send_disconnect_cont (void *cls, const struct GNUNET_PeerIdentity *target,
   n = lookup_neighbour (target);
   if (NULL == n)
     return; /* already gone */
-  if (S_DISCONNECT != n->state)
+  if (GNUNET_TRANSPORT_PS_DISCONNECT != n->state)
     return; /* have created a fresh entry since */
   if (GNUNET_SCHEDULER_NO_TASK != n->task)
     GNUNET_SCHEDULER_cancel (n->task);
@@ -1047,7 +1066,7 @@ send_disconnect (struct NeighbourMapEntry *n)
 {
   struct SessionDisconnectMessage disconnect_msg;
 
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
               "Sending DISCONNECT message to peer `%4s'\n",
               GNUNET_i2s (&n->id));
   disconnect_msg.header.size = htons (sizeof (struct SessionDisconnectMessage));
@@ -1068,10 +1087,9 @@ send_disconnect (struct NeighbourMapEntry *n)
                                          &disconnect_msg.purpose,
                                          &disconnect_msg.signature));
 
-  send_with_session (n,
-                    (const char *) &disconnect_msg, sizeof (disconnect_msg),
-                    UINT32_MAX, GNUNET_TIME_UNIT_FOREVER_REL,
-                    &send_disconnect_cont, NULL);
+  (void) send_with_session (n, (const char *) &disconnect_msg,
+      sizeof (disconnect_msg), UINT32_MAX, GNUNET_TIME_UNIT_FOREVER_REL,
+      GNUNET_NO, &send_disconnect_cont, NULL );
   GNUNET_STATISTICS_update (GST_stats,
                             gettext_noop
                             ("# DISCONNECT messages sent"), 1,
@@ -1087,38 +1105,35 @@ send_disconnect (struct NeighbourMapEntry *n)
 static void
 disconnect_neighbour (struct NeighbourMapEntry *n)
 {
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Disconnecting from peer %s in state %s\n",
+              GNUNET_i2s (&n->id),
+              GNUNET_TRANSPORT_ps2s (n->state));
   /* depending on state, notify neighbour and/or upper layers of this peer
      about disconnect */
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
-  case S_INIT_ATS:
-  case S_INIT_BLACKLIST:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
     /* other peer is completely unaware of us, no need to send DISCONNECT */
-    n->state = S_DISCONNECT_FINISHED;
     free_neighbour (n, GNUNET_NO);
     return;
-  case S_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
     send_disconnect (n);
-    n->state = S_DISCONNECT;
+    set_state (n, GNUNET_TRANSPORT_PS_DISCONNECT);
     break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
     /* we never ACK'ed the other peer's request, no need to send DISCONNECT */
-    n->state = S_DISCONNECT_FINISHED;
     free_neighbour (n, GNUNET_NO);
     return;
-  case S_CONNECT_RECV_ACK:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
     /* we DID ACK the other peer's request, must send DISCONNECT */
     send_disconnect (n);
-    n->state = S_DISCONNECT;
+    set_state (n, GNUNET_TRANSPORT_PS_DISCONNECT);
     break;
-  case S_CONNECTED:
-  case S_RECONNECT_BLACKLIST:
-  case S_RECONNECT_SENT:
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECTED:
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
     /* we are currently connected, need to send disconnect and do
        internal notifications and update statistics */
     send_disconnect (n);
@@ -1127,28 +1142,24 @@ disconnect_neighbour (struct NeighbourMapEntry *n)
                           --neighbours_connected,
                           GNUNET_NO);
     disconnect_notify_cb (callback_cls, &n->id);
-    n->state = S_DISCONNECT;
-    break;
-  case S_RECONNECT_ATS:
-    /* ATS address request timeout, disconnect without sending disconnect message */
-    GNUNET_STATISTICS_set (GST_stats,
-                           gettext_noop ("# peers connected"),
-                           --neighbours_connected,
-                           GNUNET_NO);
-    disconnect_notify_cb (callback_cls, &n->id);
-    n->state = S_DISCONNECT;
+    set_state (n, GNUNET_TRANSPORT_PS_DISCONNECT);
     break;
-  case S_DISCONNECT:
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
+    /* Disconnecting while waiting for an ATS address to reconnect,
+     * cannot send DISCONNECT */
+    free_neighbour (n, GNUNET_NO);
+    return;
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
     /* already disconnected, ignore */
     break;
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     /* already cleaned up, how did we get here!? */
     GNUNET_assert (0);
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
     break;
   }
@@ -1163,7 +1174,7 @@ disconnect_neighbour (struct NeighbourMapEntry *n)
 /**
  * We're done with our transmission attempt, continue processing.
  *
- * @param cls the 'struct MessageQueue' of the message
+ * @param cls the `struct MessageQueue` of the message
  * @param receiver intended receiver
  * @param success whether it worked or not
  * @param size_payload bytes payload sent
@@ -1193,12 +1204,12 @@ transmit_send_continuation (void *cls,
   }
   if (bytes_in_send_queue < mq->message_buf_size)
   {
-      GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
-                  "Bytes_in_send_queue `%u', Message_size %u, result: %s, payload %u, on wire %u\n",
-                  bytes_in_send_queue, mq->message_buf_size,
-                  (GNUNET_OK == success) ? "OK" : "FAIL",
-                         size_payload, physical);
-      GNUNET_break (0);
+    GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
+                "Bytes_in_send_queue `%u', Message_size %u, result: %s, payload %u, on wire %u\n",
+                bytes_in_send_queue, mq->message_buf_size,
+                (GNUNET_OK == success) ? "OK" : "FAIL",
+                size_payload, physical);
+    GNUNET_break (0);
   }
 
 
@@ -1219,9 +1230,10 @@ transmit_send_continuation (void *cls,
                              ("# transmission failures for messages to other peers"),
                              1, GNUNET_NO);
   GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-             "Sending message to `%s' of type %u was a %s\n",
+             "Sending message to `%s' of type %u with %u bytes was a %s\n",
              GNUNET_i2s (receiver),
               ntohs (((struct GNUNET_MessageHeader *) mq->message_buf)->type),
+              mq->message_buf_size,
               (success == GNUNET_OK) ? "success" : "FAILURE");
   if (NULL != mq->cont)
     mq->cont (mq->cont_cls, success, size_payload, physical);
@@ -1277,16 +1289,23 @@ try_transmission_to_peer (struct NeighbourMapEntry *n)
                              1, GNUNET_NO);
     GNUNET_CONTAINER_DLL_remove (n->messages_head, n->messages_tail, mq);
     n->is_active = mq;
-    transmit_send_continuation (mq, &n->id, GNUNET_SYSERR, mq->message_buf_size, 0);     /* timeout */
+    transmit_send_continuation (mq, &n->id,
+                                GNUNET_SYSERR,
+                                mq->message_buf_size, 0);     /* timeout */
   }
   if (NULL == mq)
     return;                     /* no more messages */
   GNUNET_CONTAINER_DLL_remove (n->messages_head, n->messages_tail, mq);
   n->is_active = mq;
-  send_with_session (n,
-                    mq->message_buf, mq->message_buf_size,
-                    0 /* priority */, timeout,
-                    &transmit_send_continuation, mq);
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "Giving message with %u bytes to plugin session %p\n",
+      mq->message_buf_size, n->primary_address.session);
+
+  (void) send_with_session (n,
+                           mq->message_buf, mq->message_buf_size,
+                           0 /* priority */, timeout, GNUNET_NO,
+                           &transmit_send_continuation, mq);
 }
 
 
@@ -1301,25 +1320,39 @@ try_transmission_to_peer (struct NeighbourMapEntry *n)
 static void
 send_keepalive (struct NeighbourMapEntry *n)
 {
-  struct GNUNET_MessageHeader m;
+  struct SessionKeepAliveMessage m;
+  struct GNUNET_TIME_Relative timeout;
+  uint32_t nonce;
 
-  GNUNET_assert ((S_CONNECTED == n->state) ||
-                 (S_CONNECTED_SWITCHING_BLACKLIST == n->state) ||
-                 (S_CONNECTED_SWITCHING_CONNECT_SENT));
+  GNUNET_assert ((GNUNET_TRANSPORT_PS_CONNECTED == n->state) ||
+                 (GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT));
   if (GNUNET_TIME_absolute_get_remaining (n->keep_alive_time).rel_value_us > 0)
     return; /* no keepalive needed at this time */
-  m.size = htons (sizeof (struct GNUNET_MessageHeader));
-  m.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE);
-  send_with_session (n,
-                    (const void *) &m, sizeof (m),
-                    UINT32_MAX /* priority */,
-                    KEEPALIVE_FREQUENCY,
-                    NULL, NULL);
+
+  nonce = 0; /* 0 indicates 'not set' */
+  while (0 == nonce)
+    nonce = GNUNET_CRYPTO_random_u32 (GNUNET_CRYPTO_QUALITY_NONCE, UINT32_MAX);
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "Sending keep alive to peer `%s' with nonce %u\n",
+      GNUNET_i2s (&n->id), nonce);
+
+  m.header.size = htons (sizeof (struct SessionKeepAliveMessage));
+  m.header.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE);
+  m.nonce = htonl (nonce);
+
+  timeout = send_with_session (n,
+                              (const void *) &m, sizeof (m),
+                              UINT32_MAX /* priority */,
+                              GNUNET_TIME_UNIT_FOREVER_REL, GNUNET_YES,
+                              NULL, NULL);
   GNUNET_STATISTICS_update (GST_stats, gettext_noop ("# keepalives sent"), 1,
                            GNUNET_NO);
+  n->primary_address.keep_alive_nonce = nonce;
   n->expect_latency_response = GNUNET_YES;
   n->last_keep_alive_time = GNUNET_TIME_absolute_get ();
-  n->keep_alive_time = GNUNET_TIME_relative_to_absolute (KEEPALIVE_FREQUENCY);
+  n->keep_alive_time = GNUNET_TIME_relative_to_absolute (timeout);
+
 }
 
 
@@ -1328,13 +1361,20 @@ send_keepalive (struct NeighbourMapEntry *n)
  * we received a KEEPALIVE (or equivalent); send a response.
  *
  * @param neighbour neighbour to keep alive (by sending keep alive response)
+ * @param m the keep alive message containing the nonce to respond to
  */
 void
-GST_neighbours_keepalive (const struct GNUNET_PeerIdentity *neighbour)
+GST_neighbours_keepalive (const struct GNUNET_PeerIdentity *neighbour,
+    const struct GNUNET_MessageHeader *m)
 {
   struct NeighbourMapEntry *n;
-  struct GNUNET_MessageHeader m;
+  const struct SessionKeepAliveMessage *msg_in;
+  struct SessionKeepAliveMessage msg;
+
+  if (sizeof (struct SessionKeepAliveMessage) != ntohs (m->size))
+    return;
 
+  msg_in = (struct SessionKeepAliveMessage *) m;
   if (NULL == (n = lookup_neighbour (neighbour)))
   {
     GNUNET_STATISTICS_update (GST_stats,
@@ -1351,14 +1391,20 @@ GST_neighbours_keepalive (const struct GNUNET_PeerIdentity *neighbour)
                               1, GNUNET_NO);
     return;
   }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "Received keep alive request from peer `%s' with nonce %u\n",
+      GNUNET_i2s (&n->id), ntohl (msg_in->nonce));
+
   /* send reply to allow neighbour to measure latency */
-  m.size = htons (sizeof (struct GNUNET_MessageHeader));
-  m.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE_RESPONSE);
-  send_with_session(n,
-                   (const void *) &m, sizeof (m),
-                   UINT32_MAX /* priority */,
-                   KEEPALIVE_FREQUENCY,
-                   NULL, NULL);
+  msg.header.size = htons (sizeof (struct SessionKeepAliveMessage));
+  msg.header.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_KEEPALIVE_RESPONSE);
+  msg.nonce = msg_in->nonce;
+  (void) send_with_session(n,
+                          (const void *) &msg, sizeof (struct SessionKeepAliveMessage),
+                          UINT32_MAX /* priority */,
+                          GNUNET_TIME_UNIT_FOREVER_REL, GNUNET_YES,
+                          NULL, NULL);
 }
 
 
@@ -1368,14 +1414,22 @@ GST_neighbours_keepalive (const struct GNUNET_PeerIdentity *neighbour)
  * plus calculated latency) to ATS.
  *
  * @param neighbour neighbour to keep alive
+ * @param m the message containing the keep alive response
  */
 void
-GST_neighbours_keepalive_response (const struct GNUNET_PeerIdentity *neighbour)
+GST_neighbours_keepalive_response (const struct GNUNET_PeerIdentity *neighbour,
+    const struct GNUNET_MessageHeader *m)
 {
   struct NeighbourMapEntry *n;
+  const struct SessionKeepAliveMessage *msg;
+  struct GNUNET_TRANSPORT_PluginFunctions *papi;
   uint32_t latency;
   struct GNUNET_ATS_Information ats;
 
+  if (sizeof (struct SessionKeepAliveMessage) != ntohs (m->size))
+    return;
+
+  msg = (const struct SessionKeepAliveMessage *) m;
   if (NULL == (n = lookup_neighbour (neighbour)))
   {
     GNUNET_STATISTICS_update (GST_stats,
@@ -1384,7 +1438,7 @@ GST_neighbours_keepalive_response (const struct GNUNET_PeerIdentity *neighbour)
                               1, GNUNET_NO);
     return;
   }
-  if ( (S_CONNECTED != n->state) ||
+  if ( (GNUNET_TRANSPORT_PS_CONNECTED != n->state) ||
        (GNUNET_YES != n->expect_latency_response) )
   {
     GNUNET_STATISTICS_update (GST_stats,
@@ -1393,27 +1447,64 @@ GST_neighbours_keepalive_response (const struct GNUNET_PeerIdentity *neighbour)
                               1, GNUNET_NO);
     return;
   }
-  n->expect_latency_response = GNUNET_NO;
-  n->latency = GNUNET_TIME_absolute_get_duration (n->last_keep_alive_time);
-  n->timeout = GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT);
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-             "Latency for peer `%s' is %s\n",
-              GNUNET_i2s (&n->id),
-             GNUNET_STRINGS_relative_time_to_string (n->latency,
-                                                     GNUNET_YES));
-  /* append latency */
-  ats.type = htonl (GNUNET_ATS_QUALITY_NET_DELAY);
-  if (n->latency.rel_value_us > UINT32_MAX)
-    latency = UINT32_MAX;
-  else
-    latency = n->latency.rel_value_us;
-  ats.value = htonl (latency);
-  GST_ats_update_metrics (&n->id,
-                                                                                         n->primary_address.address,
-                                                                                       n->primary_address.session,
-                                                                                       &ats, 1);
-}
-
+  if (NULL == n->primary_address.address)
+  {
+    GNUNET_STATISTICS_update (GST_stats,
+                              gettext_noop
+                              ("# KEEPALIVE_RESPONSE messages discarded (address changed)"),
+                              1, GNUNET_NO);
+    return;
+  }
+  if (n->primary_address.keep_alive_nonce != ntohl (msg->nonce))
+  {
+    GNUNET_STATISTICS_update (GST_stats,
+                              gettext_noop
+                              ("# KEEPALIVE_RESPONSE messages discarded (wrong nonce)"),
+                              1, GNUNET_NO);
+    return;
+  }
+  else
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+        "Received keep alive response from peer `%s' for session %p\n",
+        GNUNET_i2s (&n->id), n->primary_address.session);
+
+  }
+
+  /* Update session timeout here */
+  if (NULL != (papi = GST_plugins_find (n->primary_address.address->transport_name)))
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+        "Updating session for peer `%s' for session %p\n",
+        GNUNET_i2s (&n->id), n->primary_address.session);
+    papi->update_session_timeout (papi->cls, &n->id, n->primary_address.session);
+  }
+  else
+  {
+    GNUNET_break (0);
+  }
+
+  n->primary_address.keep_alive_nonce = 0;
+  n->expect_latency_response = GNUNET_NO;
+  n->latency = GNUNET_TIME_absolute_get_duration (n->last_keep_alive_time);
+  set_timeout (n, GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT));
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+             "Latency for peer `%s' is %s\n",
+              GNUNET_i2s (&n->id),
+             GNUNET_STRINGS_relative_time_to_string (n->latency,
+                                                     GNUNET_YES));
+  /* append latency */
+  ats.type = htonl (GNUNET_ATS_QUALITY_NET_DELAY);
+  if (n->latency.rel_value_us > UINT32_MAX)
+    latency = UINT32_MAX;
+  else
+    latency = n->latency.rel_value_us;
+  ats.value = htonl (latency);
+  GST_ats_update_metrics (&n->id, n->primary_address.address,
+      n->primary_address.session, &ats, 1);
+}
+
 
 /**
  * We have received a message from the given sender.  How long should
@@ -1422,9 +1513,9 @@ GST_neighbours_keepalive_response (const struct GNUNET_PeerIdentity *neighbour)
  *
  * @param sender sender of the message
  * @param size size of the message
- * @param do_forward set to GNUNET_YES if the message should be forwarded to clients
- *                   GNUNET_NO if the neighbour is not connected or violates the quota,
- *                   GNUNET_SYSERR if the connection is not fully up yet
+ * @param do_forward set to #GNUNET_YES if the message should be forwarded to clients
+ *                   #GNUNET_NO if the neighbour is not connected or violates the quota,
+ *                   #GNUNET_SYSERR if the connection is not fully up yet
  * @return how long to wait before reading more from this sender
  */
 struct GNUNET_TIME_Relative
@@ -1550,15 +1641,88 @@ GST_neighbours_send (const struct GNUNET_PeerIdentity *target, const void *msg,
   mq->message_buf = (const char *) &mq[1];
   mq->message_buf_size = msg_size;
   mq->timeout = GNUNET_TIME_relative_to_absolute (timeout);
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Enqueueing %u bytes to send to peer %s\n",
+      msg_size, GNUNET_i2s (target));
+
   GNUNET_CONTAINER_DLL_insert_tail (n->messages_head, n->messages_tail, mq);
-  if ( (NULL != n->is_active) ||
-       ( (NULL == n->primary_address.session) && (NULL == n->primary_address.address)) )
-    return;
   if (GNUNET_SCHEDULER_NO_TASK != n->task)
     GNUNET_SCHEDULER_cancel (n->task);
   n->task = GNUNET_SCHEDULER_add_now (&master_task, n);
 }
 
+static void
+send_session_connect_cont (void *cls,
+                      const struct GNUNET_PeerIdentity *target,
+                      int result,
+                      size_t size_payload,
+                      size_t size_on_wire)
+{
+  struct NeighbourMapEntry *n;
+
+  n = lookup_neighbour (target);
+  if (NULL == n)
+  {
+    /* CONNECT continuation was called after neighbor was freed,
+     * for example due to a time out for the state or the session
+     * used was already terminated: nothing to do here... */
+    return;
+  }
+
+  if ( (GNUNET_TRANSPORT_PS_CONNECT_SENT != n->state) &&
+       (GNUNET_TRANSPORT_PS_RECONNECT_SENT != n->state) &&
+       (GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT != n->state))
+  {
+    /* CONNECT continuation was called after neighbor changed state,
+     * for example due to a time out for the state or the session
+     * used was already terminated: nothing to do here... */
+    return;
+  }
+  if (GNUNET_OK == result)
+    return;
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+            _("Failed to send CONNECT message to peer `%s' using address `%s' session %p\n"),
+            GNUNET_i2s (target),
+            GST_plugins_a2s (n->primary_address.address),
+            n->primary_address.session);
+
+  switch (n->state) {
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+    /* Remove address and request and additional one */
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address,
+        n->primary_address.session);
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL );
+    unset_primary_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_INIT_ATS,
+        GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT));
+    break;
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    /* Remove address and request and additional one */
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address,
+        n->primary_address.session);
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL );
+    unset_primary_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+    /* Remove address and request and go back to primary address */
+    GNUNET_STATISTICS_update (GST_stats, gettext_noop
+        ("# Failed attempts to switch addresses (failed to send CONNECT CONT)"), 1, GNUNET_NO);
+    GNUNET_ATS_address_destroyed (GST_ats, n->alternative_address.address,
+        n->alternative_address.session);
+    GNUNET_ATS_address_destroyed (GST_ats, n->alternative_address.address,
+        NULL );
+    unset_alternative_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+    break;
+  default:
+    disconnect_neighbour (n);
+    break;
+  }
+}
 
 /**
  * Send a SESSION_CONNECT message via the given address.
@@ -1570,6 +1734,11 @@ send_session_connect (struct NeighbourAddress *na)
 {
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
   struct SessionConnectMessage connect_msg;
+  struct NeighbourMapEntry *n;
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Sending SESSION_CONNECT message to peer `%s'\n",
+              GNUNET_i2s (&na->address->peer));
 
   if (NULL == (papi = GST_plugins_find (na->address->transport_name)))
   {
@@ -1583,37 +1752,140 @@ send_session_connect (struct NeighbourAddress *na)
     GNUNET_break (0);
     return;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# SESSION_CONNECT messages sent"),
+                            1, GNUNET_NO);
   na->connect_timestamp = GNUNET_TIME_absolute_get ();
   connect_msg.header.size = htons (sizeof (struct SessionConnectMessage));
   connect_msg.header.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_CONNECT);
   connect_msg.reserved = htonl (0);
   connect_msg.timestamp = GNUNET_TIME_absolute_hton (na->connect_timestamp);
-  (void) papi->send (papi->cls,
-                    na->session,
-                    (const char *) &connect_msg, sizeof (struct SessionConnectMessage),
-                    UINT_MAX,
-                    GNUNET_TIME_UNIT_FOREVER_REL,
-                    NULL, NULL);
+  if (-1 ==
+      papi->send (papi->cls,
+                  na->session,
+                  (const char *) &connect_msg, sizeof (struct SessionConnectMessage),
+                  UINT_MAX,
+                  SETUP_CONNECTION_TIMEOUT,
+                  send_session_connect_cont, NULL))
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_WARNING,
+                _("Failed to transmit CONNECT message via plugin to %s\n"),
+                GST_plugins_a2s (na->address));
+
+    n = lookup_neighbour (&na->address->peer);
+    if (NULL == n)
+    {
+      GNUNET_break (0);
+      return;
+    }
+
+    switch (n->state) {
+      case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+        /* Remove address and request and additional one */
+        unset_primary_address (n);
+        set_state_and_timeout (n, GNUNET_TRANSPORT_PS_INIT_ATS,
+          GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT));
+        /* Hard failure to send the CONNECT message with this address:
+           Destroy address and session */
+        break;
+      case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+        /* Remove address and request and additional one */
+        unset_primary_address (n);
+        set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_ATS,
+          GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+        break;
+      case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+        GNUNET_STATISTICS_update (GST_stats, gettext_noop
+            ("# Failed attempts to switch addresses (failed to send CONNECT)"), 1, GNUNET_NO);
+        /* Remove address and request and additional one */
+        unset_alternative_address (n);
+        set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+          GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+        break;
+      default:
+        disconnect_neighbour (n);
+        break;
+    }
+    GNUNET_ATS_address_destroyed (GST_ats, na->address, na->session);
+    GNUNET_ATS_address_destroyed (GST_ats, na->address, NULL);
+  }
   GST_neighbours_notify_data_sent (&na->address->peer,
-      na->address, na->session, sizeof (struct SessionConnectMessage));
+                                   na->address,
+                                   na->session,
+                                   sizeof (struct SessionConnectMessage));
+}
+
+
+static void
+send_session_connect_ack_cont (void *cls,
+                      const struct GNUNET_PeerIdentity *target,
+                      int result,
+                      size_t size_payload,
+                      size_t size_on_wire)
+{
+  struct NeighbourMapEntry *n;
+
+  n = lookup_neighbour (target);
+  if (NULL == n)
+  {
+    /* CONNECT_ACK continuation was called after neighbor was freed,
+     * for example due to a time out for the state or the session
+     * used was already terminated: nothing to do here... */
+    return;
+  }
 
+  if (GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK != n->state)
+  {
+    /* CONNECT_ACK continuation was called after neighbor changed state,
+     * for example due to a time out for the state or the session
+     * used was already terminated: nothing to do here... */
+    return;
+  }
+  if (GNUNET_OK == result)
+    return;
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+            _("Failed to send CONNECT_ACK message to peer `%s' using address `%s' session %p\n"),
+            GNUNET_i2s (target),
+            GST_plugins_a2s (n->primary_address.address),
+            n->primary_address.session);
+
+  /* Failed to send CONNECT_ACK message with this address */
+  GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address,
+      n->primary_address.session);
+  GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address,
+      NULL);
+
+  /* Remove address and request and additional one */
+  unset_primary_address (n);
+  n->ack_state = ACK_SEND_CONNECT_ACK;
+  set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS,
+      GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+  return;
 }
 
 
 /**
- * Send a SESSION_CONNECT_ACK message via the given address.
+ * Send a CONNECT_ACK message via the given address.
  *
  * @param address address to use
  * @param session session to use
  * @param timestamp timestamp to use for the ACK message
+ * @return GNUNET_SYSERR if sending immediately failed, GNUNET_OK otherwise
  */
 static void
-send_session_connect_ack_message (const struct GNUNET_HELLO_Address *address,
+send_connect_ack_message (const struct GNUNET_HELLO_Address *address,
                                  struct Session *session,
                                  struct GNUNET_TIME_Absolute timestamp)
 {
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
   struct SessionConnectMessage connect_msg;
+  struct NeighbourMapEntry *n;
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Sending CONNECT_ACK to peer `%s'\n",
+              GNUNET_i2s (&address->peer));
 
   if (NULL == (papi = GST_plugins_find (address->transport_name)))
   {
@@ -1627,17 +1899,208 @@ send_session_connect_ack_message (const struct GNUNET_HELLO_Address *address,
     GNUNET_break (0);
     return;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# CONNECT_ACK messages sent"),
+                            1, GNUNET_NO);
   connect_msg.header.size = htons (sizeof (struct SessionConnectMessage));
   connect_msg.header.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_CONNECT_ACK);
   connect_msg.reserved = htonl (0);
   connect_msg.timestamp = GNUNET_TIME_absolute_hton (timestamp);
-  (void) papi->send (papi->cls,
+
+  if (GNUNET_SYSERR == papi->send (papi->cls,
                     session,
                     (const char *) &connect_msg, sizeof (struct SessionConnectMessage),
                     UINT_MAX,
                     GNUNET_TIME_UNIT_FOREVER_REL,
-                    NULL, NULL);
+                    send_session_connect_ack_cont, NULL))
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_WARNING,
+                _("Failed to transmit CONNECT_ACK message via plugin to %s\n"),
+                GST_plugins_a2s (address));
+
+    n = lookup_neighbour (&address->peer);
+    if (NULL == n)
+    {
+      GNUNET_break (0);
+      return;
+    }
+    /* Hard failure to send the CONNECT_ACK message with this address:
+       Destroy session (and address)  */
+    if (GNUNET_YES == GNUNET_HELLO_address_check_option(address,
+        GNUNET_HELLO_ADDRESS_INFO_INBOUND))
+    {
+      GNUNET_ATS_address_destroyed (GST_ats, address, session);
+      GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+    }
+    else
+      GNUNET_ATS_address_destroyed (GST_ats, address, session);
+
+    /* Remove address and request and additional one */
+    unset_primary_address (n);
+    n->ack_state = ACK_SEND_CONNECT_ACK;
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+    return;
+  }
+
+}
+
+struct QuotaNotificationRequest
+{
+  struct GNUNET_PeerIdentity peer;
+  struct Session *session;
+  char *plugin;
+};
+
+struct QNR_LookContext
+{
+  struct GNUNET_PeerIdentity peer;
+  struct Session *session;
+  const char *plugin;
+
+  struct QuotaNotificationRequest *res;
+};
+
+static int
+find_notification_request (void *cls, const struct GNUNET_PeerIdentity *key, void *value)
+{
+  struct QNR_LookContext *qnr_ctx = cls;
+  struct QuotaNotificationRequest *qnr = value;
+
+  if ((qnr->session == qnr_ctx->session) &&
+      (0 == memcmp (&qnr->peer, &qnr_ctx->peer, sizeof (struct GNUNET_PeerIdentity))) &&
+      (0 == strcmp(qnr_ctx->plugin, qnr->plugin)))
+  {
+    qnr_ctx->res = value;
+    return GNUNET_NO;
+  }
+  return GNUNET_YES;
+}
+
+void
+GST_neighbours_register_quota_notification(void *cls,
+    const struct GNUNET_PeerIdentity *peer, const char *plugin,
+    struct Session *session)
+{
+  struct QuotaNotificationRequest *qnr;
+  struct QNR_LookContext qnr_ctx;
+
+  if (NULL == registered_quota_notifications)
+  {
+    return; /* init or shutdown */
+  }
+
+  qnr_ctx.peer = (*peer);
+  qnr_ctx.plugin = plugin;
+  qnr_ctx.session = session;
+  qnr_ctx.res = NULL;
+
+  GNUNET_CONTAINER_multipeermap_get_multiple (registered_quota_notifications,
+      peer, &find_notification_request, &qnr_ctx);
+  if (NULL != qnr_ctx.res)
+  {
+    GNUNET_break(0);
+    return;
+  }
+
+  qnr = GNUNET_new (struct QuotaNotificationRequest);
+  qnr->peer =  (*peer);
+  qnr->plugin = GNUNET_strdup (plugin);
+  qnr->session = session;
 
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "Adding notification for peer `%s' plugin `%s' session %p \n",
+      GNUNET_i2s (peer), plugin, session);
+
+  GNUNET_CONTAINER_multipeermap_put (registered_quota_notifications, peer,
+      qnr, GNUNET_CONTAINER_MULTIHASHMAPOPTION_MULTIPLE);
+}
+
+
+void
+GST_neighbours_unregister_quota_notification(void *cls,
+    const struct GNUNET_PeerIdentity *peer, const char *plugin, struct Session *session)
+{
+  struct QNR_LookContext qnr_ctx;
+
+  if (NULL == registered_quota_notifications)
+  {
+    return; /* init or shutdown */
+  }
+
+  qnr_ctx.peer = (*peer);
+  qnr_ctx.plugin = plugin;
+  qnr_ctx.session = session;
+  qnr_ctx.res = NULL;
+
+  GNUNET_CONTAINER_multipeermap_iterate (registered_quota_notifications,
+      &find_notification_request, &qnr_ctx);
+  if (NULL == qnr_ctx.res)
+  {
+    GNUNET_break(0);
+    return;
+  }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "Removing notification for peer `%s' plugin `%s' session %p \n",
+      GNUNET_i2s (peer), plugin, session);
+
+  GNUNET_CONTAINER_multipeermap_remove (registered_quota_notifications, peer,
+      qnr_ctx.res);
+  GNUNET_free (qnr_ctx.res->plugin);
+  GNUNET_free (qnr_ctx.res);
+}
+
+static int
+notification_cb(void *cls, const struct GNUNET_PeerIdentity *key, void *value)
+{
+  /* struct NeighbourMapEntry *n = cls; */
+  struct QuotaNotificationRequest *qnr = value;
+  struct GNUNET_TRANSPORT_PluginFunctions *papi;
+  struct GNUNET_TIME_Relative delay;
+  int do_forward;
+
+  papi = GST_plugins_find(qnr->plugin);
+  if (NULL == papi)
+  {
+    GNUNET_break (0);
+    return GNUNET_OK;
+  }
+
+  delay = GST_neighbours_calculate_receive_delay (key, 0, &do_forward);
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      "New inbound delay for peer `%s' is %llu ms\n", GNUNET_i2s (key),
+      delay.rel_value_us / 1000);
+
+  if (NULL != papi->update_inbound_delay)
+    papi->update_inbound_delay (papi->cls, key, qnr->session, delay);
+  return GNUNET_OK;
+}
+
+static int
+free_notification_cb(void *cls, const struct GNUNET_PeerIdentity *key,
+    void *value)
+{
+  /* struct NeighbourMapEntry *n = cls; */
+  struct QuotaNotificationRequest *qnr = value;
+
+  GNUNET_break (GNUNET_OK == GNUNET_CONTAINER_multipeermap_remove (registered_quota_notifications, key,
+      qnr));
+  GNUNET_free(qnr->plugin);
+  GNUNET_free(qnr);
+
+  return GNUNET_OK;
+}
+
+static void
+inbound_bw_tracker_update(void *cls)
+{
+  struct NeighbourMapEntry *n = cls;
+
+  /* Quota was updated, tell plugins to update the time to receive next */
+  GNUNET_CONTAINER_multipeermap_get_multiple (registered_quota_notifications,
+      &n->id, &notification_cb, n);
 }
 
 
@@ -1657,17 +2120,18 @@ setup_neighbour (const struct GNUNET_PeerIdentity *peer)
              GNUNET_i2s (peer));
   n = GNUNET_new (struct NeighbourMapEntry);
   n->id = *peer;
-  n->state = S_NOT_CONNECTED;
+  n->ack_state = ACK_UNDEFINED;
   n->latency = GNUNET_TIME_UNIT_FOREVER_REL;
   n->last_util_transmission = GNUNET_TIME_absolute_get();
   n->util_payload_bytes_recv = 0;
   n->util_payload_bytes_sent = 0;
   n->util_total_bytes_recv = 0;
   n->util_total_bytes_sent = 0;
-  GNUNET_BANDWIDTH_tracker_init (&n->in_tracker,
+  GNUNET_BANDWIDTH_tracker_init (&n->in_tracker, &inbound_bw_tracker_update, n,
                                  GNUNET_CONSTANTS_DEFAULT_BW_IN_OUT,
                                  MAX_BANDWIDTH_CARRY_S);
   n->task = GNUNET_SCHEDULER_add_now (&master_task, n);
+  set_state_and_timeout (n, GNUNET_TRANSPORT_PS_NOT_CONNECTED, GNUNET_TIME_UNIT_FOREVER_ABS);
   GNUNET_assert (GNUNET_OK ==
                  GNUNET_CONTAINER_multipeermap_put (neighbours,
                                                     &n->id, n,
@@ -1675,33 +2139,78 @@ setup_neighbour (const struct GNUNET_PeerIdentity *peer)
   return n;
 }
 
+/* We received a address suggestion after requesting an address in
+ * try_connect or after receiving a connect, switch to address
+ */
+static void
+address_suggest_cont (void *cls,
+    const struct GNUNET_PeerIdentity *peer,
+    const struct GNUNET_HELLO_Address *address, struct Session *session,
+    struct GNUNET_BANDWIDTH_Value32NBO bandwidth_out,
+    struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in,
+    const struct GNUNET_ATS_Information *ats, uint32_t ats_count)
+{
+  GST_neighbours_switch_to_address(peer, address, session, ats, ats_count,
+      bandwidth_in, bandwidth_out);
+}
+
+
+struct BlacklistCheckSwitchContext
+{
+  struct BlacklistCheckSwitchContext *prev;
+  struct BlacklistCheckSwitchContext *next;
+
+
+  struct GST_BlacklistCheck *blc;
+
+  struct GNUNET_HELLO_Address *address;
+  struct Session *session;
+  struct GNUNET_ATS_Information *ats;
+  uint32_t ats_count;
+
+  struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in;
+  struct GNUNET_BANDWIDTH_Value32NBO bandwidth_out;
+};
 
 /**
- * Check if the two given addresses are the same.
- * Actually only checks if the sessions are non-NULL
- * (which they should be) and then if they are identical;
- * the actual addresses don't matter if the session
- * pointers match anyway, and we must have session pointers
- * at this time.
+ * Black list check result for try_connect call
+ * If connection to the peer is allowed request adddress and
  *
- * @param a1 first address to compare
- * @param a2 other address to compare
- * @return GNUNET_NO if the addresses do not match, GNUNET_YES if they do match
+ * @param cls blc_ctx bl context
+ * @param peer the peer
+ * @param result the result
  */
-static int
-address_matches (const struct NeighbourAddress *a1,
-                const struct NeighbourAddress *a2)
+static void
+try_connect_bl_check_cont (void *cls,
+    const struct GNUNET_PeerIdentity *peer, int result)
 {
-  if ( (NULL == a1->session) ||
-       (NULL == a2->session) )
+  struct BlacklistCheckSwitchContext *blc_ctx = cls;
+  struct NeighbourMapEntry *n;
+
+  GNUNET_CONTAINER_DLL_remove (pending_bc_head, pending_bc_tail, blc_ctx);
+  GNUNET_free (blc_ctx);
+
+  if (GNUNET_OK != result)
   {
-    GNUNET_break (0);
-    return 0;
+    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+        _("Blacklisting disapproved to connect to peer `%s'\n"),
+        GNUNET_i2s (peer));
+    return;
   }
-  return (a1->session == a2->session) ? GNUNET_YES : GNUNET_NO;
+
+  /* Setup a new neighbour */
+  n = setup_neighbour (peer);
+
+  /* Request address suggestions for this peer */
+  set_state_and_timeout (n, GNUNET_TRANSPORT_PS_INIT_ATS,
+      GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+  GNUNET_ATS_reset_backoff (GST_ats, peer);
+  n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, peer,
+      &address_suggest_cont, n);
 }
 
 
+
 /**
  * Try to create a connection to the given target (eventually).
  *
@@ -1711,335 +2220,73 @@ void
 GST_neighbours_try_connect (const struct GNUNET_PeerIdentity *target)
 {
   struct NeighbourMapEntry *n;
+  struct GST_BlacklistCheck *blc;
+  struct BlacklistCheckSwitchContext *blc_ctx;
 
   if (NULL == neighbours)
   {
-         GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                     "Asked to connect to peer `%s' during shutdown\n",
-                     GNUNET_i2s (target));
-               return; /* during shutdown, do nothing */
-  }
-  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
-             "Asked to connect to peer `%s'\n",
-              GNUNET_i2s (target));
-  if (0 == memcmp (target, &GST_my_identity, sizeof (struct GNUNET_PeerIdentity)))
-  {
-    /* refuse to connect to myself */
-    /* FIXME: can this happen? Is this not an API violation? */
-    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
-               "Refusing to try to connect to myself.\n");
-    return;
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                "Asked to connect to peer `%s' during shutdown\n",
+                GNUNET_i2s (target));
+    return; /* during shutdown, do nothing */
   }
   n = lookup_neighbour (target);
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+             "Asked to connect to peer `%s' (state: %s)\n",
+              GNUNET_i2s (target),
+              (NULL != n) ? GNUNET_TRANSPORT_ps2s(n->state) : "NEW PEER");
   if (NULL != n)
   {
     switch (n->state)
     {
-    case S_NOT_CONNECTED:
+    case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
       /* this should not be possible */
       GNUNET_break (0);
       free_neighbour (n, GNUNET_NO);
       break;
-    case S_INIT_ATS:
-    case S_INIT_BLACKLIST:
-    case S_CONNECT_SENT:
-    case S_CONNECT_RECV_BLACKLIST_INBOUND:
-    case S_CONNECT_RECV_ATS:
-    case S_CONNECT_RECV_BLACKLIST:
-    case S_CONNECT_RECV_ACK:
+    case GNUNET_TRANSPORT_PS_INIT_ATS:
+    case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+    case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+    case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
       GNUNET_log (GNUNET_ERROR_TYPE_INFO,
-               "Ignoring request to try to connect to `%s', already trying!\n",
+                  "Ignoring request to try to connect to `%s', already trying!\n",
                  GNUNET_i2s (target));
       return; /* already trying */
-    case S_CONNECTED:
-    case S_RECONNECT_ATS:
-    case S_RECONNECT_BLACKLIST:
-    case S_RECONNECT_SENT:
-    case S_CONNECTED_SWITCHING_BLACKLIST:
-    case S_CONNECTED_SWITCHING_CONNECT_SENT:
+    case GNUNET_TRANSPORT_PS_CONNECTED:
+    case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
+    case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
       GNUNET_log (GNUNET_ERROR_TYPE_INFO,
-               "Ignoring request to try to connect, already connected to `%s'!\n",
+                  "Ignoring request to try to connect, already connected to `%s'!\n",
                  GNUNET_i2s (target));
       return; /* already connected */
-    case S_DISCONNECT:
+    case GNUNET_TRANSPORT_PS_DISCONNECT:
       /* get rid of remains, ready to re-try immediately */
       free_neighbour (n, GNUNET_NO);
       break;
-    case S_DISCONNECT_FINISHED:
+    case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
       /* should not be possible */
       GNUNET_assert (0);
+      return;
     default:
       GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                   "Unhandled state `%s'\n",
-                  print_state (n->state));
+                  GNUNET_TRANSPORT_ps2s (n->state));
       GNUNET_break (0);
       free_neighbour (n, GNUNET_NO);
       break;
     }
   }
-  n = setup_neighbour (target);
-  n->state = S_INIT_ATS;
-  n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-
-  GNUNET_ATS_reset_backoff (GST_ats, target);
-  n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, target);
-}
-
 
-/**
- * Function called with the result of a blacklist check.
- *
- * @param cls closure with the 'struct BlackListCheckContext'
- * @param peer peer this check affects
- * @param result GNUNET_OK if the address is allowed
- */
-static void
-handle_test_blacklist_cont (void *cls,
-                           const struct GNUNET_PeerIdentity *peer,
-                           int result)
-{
-  struct BlackListCheckContext *bcc = cls;
-  struct NeighbourMapEntry *n;
+  /* Do blacklist check if connecting to this peer is allowed */
+  blc_ctx = GNUNET_new (struct BlacklistCheckSwitchContext);
+  GNUNET_CONTAINER_DLL_insert (pending_bc_head, pending_bc_tail, blc_ctx);
 
-  bcc->bc = NULL;
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-              "Connection to new address of peer `%s' based on blacklist is `%s'\n",
-              GNUNET_i2s (peer),
-              (GNUNET_OK == result) ? "allowed" : "FORBIDDEN");
-  if (NULL == (n = lookup_neighbour (peer)))
-    goto cleanup; /* nobody left to care about new address */
-  switch (n->state)
+  if (NULL != (blc = GST_blacklist_test_allowed (target, NULL,
+        &try_connect_bl_check_cont, blc_ctx)))
   {
-  case S_NOT_CONNECTED:
-    /* this should not be possible */
-    GNUNET_break (0);
-    free_neighbour (n, GNUNET_NO);
-    break;
-  case S_INIT_ATS:
-    /* still waiting on ATS suggestion */
-    break;
-  case S_INIT_BLACKLIST:
-    /* check if the address the blacklist was fine with matches
-       ATS suggestion, if so, we can move on! */
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (bcc->na.address,
-                                       bcc->na.session,
-                                       n->connect_ack_timestamp);
-    }
-    if (GNUNET_YES != address_matches (&bcc->na, &n->primary_address))
-      break; /* result for an address we currently don't care about */
-    if (GNUNET_OK == result)
-    {
-      n->timeout = GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT);
-      n->state = S_CONNECT_SENT;
-      send_session_connect (&n->primary_address);
-    }
-    else
-    {
-      // FIXME: should also possibly destroy session with plugin!?
-      GNUNET_ATS_address_destroyed (GST_ats,
-                                   bcc->na.address,
-                                   NULL);
-      free_address (&n->primary_address);
-      n->state = S_INIT_ATS;
-      n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-      // FIXME: do we need to ask ATS again for suggestions?
-      n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
-    }
-    break;
-  case S_CONNECT_SENT:
-    /* waiting on CONNECT_ACK, send ACK if one is pending */
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (n->primary_address.address,
-                                       n->primary_address.session,
-                                       n->connect_ack_timestamp);
-    }
-    break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-    if (GNUNET_OK == result)
-       GST_ats_add_address (bcc->na.address, bcc->na.session);
-
-    n->state = S_CONNECT_RECV_ATS;
-    n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-    GNUNET_ATS_reset_backoff (GST_ats, peer);
-    n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, peer);
-    break;
-  case S_CONNECT_RECV_ATS:
-    /* still waiting on ATS suggestion, don't care about blacklist */
-    break;
-  case S_CONNECT_RECV_BLACKLIST:
-    if (GNUNET_YES != address_matches (&bcc->na, &n->primary_address))
-      break; /* result for an address we currently don't care about */
-    if (GNUNET_OK == result)
-    {
-      n->timeout = GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT);
-      n->state = S_CONNECT_RECV_ACK;
-      send_session_connect_ack_message (bcc->na.address,
-                                       bcc->na.session,
-                                       n->connect_ack_timestamp);
-      if (1 == n->send_connect_ack)
-       n->send_connect_ack = 2;
-    }
-    else
-    {
-      // FIXME: should also possibly destroy session with plugin!?
-      GNUNET_ATS_address_destroyed (GST_ats,
-                                   bcc->na.address,
-                                   NULL);
-      free_address (&n->primary_address);
-      n->state = S_INIT_ATS;
-      n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-      // FIXME: do we need to ask ATS again for suggestions?
-      GNUNET_ATS_reset_backoff (GST_ats, peer);
-      n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
-    }
-    break;
-  case S_CONNECT_RECV_ACK:
-    /* waiting on SESSION_ACK, send ACK if one is pending */
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (n->primary_address.address,
-                                       n->primary_address.session,
-                                       n->connect_ack_timestamp);
-    }
-    break;
-  case S_CONNECTED:
-    /* already connected, don't care about blacklist */
-    break;
-  case S_RECONNECT_ATS:
-    /* still waiting on ATS suggestion, don't care about blacklist */
-    break;
-  case S_RECONNECT_BLACKLIST:
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (bcc->na.address,
-                                       bcc->na.session,
-                                       n->connect_ack_timestamp);
-    }
-    if (GNUNET_YES != address_matches (&bcc->na, &n->primary_address))
-      break; /* result for an address we currently don't care about */
-    if (GNUNET_OK == result)
-    {
-      send_session_connect (&n->primary_address);
-      n->timeout = GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT);
-      n->state = S_RECONNECT_SENT;
-    }
-    else
-    {
-      GNUNET_ATS_address_destroyed (GST_ats,
-                                   bcc->na.address,
-                                   NULL);
-      n->state = S_RECONNECT_ATS;
-      n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-      // FIXME: do we need to ask ATS again for suggestions?
-      n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
-    }
-    break;
-  case S_RECONNECT_SENT:
-    /* waiting on CONNECT_ACK, don't care about blacklist */
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (n->primary_address.address,
-                                       n->primary_address.session,
-                                       n->connect_ack_timestamp);
-    }
-    break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    if (GNUNET_YES != address_matches (&bcc->na, &n->alternative_address))
-      break; /* result for an address we currently don't care about */
-    if (GNUNET_OK == result)
-    {
-      send_session_connect (&n->alternative_address);
-      n->state = S_CONNECTED_SWITCHING_CONNECT_SENT;
-    }
-    else
-    {
-      GNUNET_ATS_address_destroyed (GST_ats,
-                                   bcc->na.address,
-                                   NULL);
-      free_address (&n->alternative_address);
-      n->state = S_CONNECTED;
-    }
-    break;
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-    /* waiting on CONNECT_ACK, don't care about blacklist */
-    if ( (GNUNET_OK == result) &&
-        (1 == n->send_connect_ack) )
-    {
-      n->send_connect_ack = 2;
-      send_session_connect_ack_message (n->primary_address.address,
-                                       n->primary_address.session,
-                                       n->connect_ack_timestamp);
-    }
-    break;
-  case S_DISCONNECT:
-    /* Nothing to do here, ATS will already do what can be done */
-    break;
-  case S_DISCONNECT_FINISHED:
-    /* should not be possible */
-    GNUNET_assert (0);
-    break;
-  default:
-    GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
-                "Unhandled state `%s'\n",
-                print_state (n->state));
-    GNUNET_break (0);
-    free_neighbour (n, GNUNET_NO);
-    break;
+    blc_ctx->blc = blc;
   }
- cleanup:
-  GNUNET_HELLO_address_free (bcc->na.address);
-  GNUNET_CONTAINER_DLL_remove (bc_head,
-                              bc_tail,
-                              bcc);
-  GNUNET_free (bcc);
-}
-
-
-/**
- * We want to know if connecting to a particular peer via
- * a particular address is allowed.  Check it!
- *
- * @param peer identity of the peer to switch the address for
- * @param ts time at which the check was initiated
- * @param address address of the other peer, NULL if other peer
- *                       connected to us
- * @param session session to use (or NULL)
- */
-static void
-check_blacklist (const struct GNUNET_PeerIdentity *peer,
-                struct GNUNET_TIME_Absolute ts,
-                const struct GNUNET_HELLO_Address *address,
-                struct Session *session)
-{
-  struct BlackListCheckContext *bcc;
-  struct GST_BlacklistCheck *bc;
-
-  bcc = GNUNET_malloc (sizeof (struct BlackListCheckContext));
-  bcc->na.address = GNUNET_HELLO_address_copy (address);
-  bcc->na.session = session;
-  bcc->na.connect_timestamp = ts;
-  GNUNET_CONTAINER_DLL_insert (bc_head,
-                              bc_tail,
-                              bcc);
-  if (NULL != (bc = GST_blacklist_test_allowed (peer,
-                                               address->transport_name,
-                                               &handle_test_blacklist_cont, bcc)))
-    bcc->bc = bc;
-  /* if NULL == bc, 'cont' was already called and 'bcc' already free'd, so
-     we must only store 'bc' if 'bc' is non-NULL... */
 }
 
 
@@ -2049,340 +2296,462 @@ check_blacklist (const struct GNUNET_PeerIdentity *peer,
  *
  * @param message possibly a 'struct SessionConnectMessage' (check format)
  * @param peer identity of the peer to switch the address for
- * @param address address of the other peer, NULL if other peer
- *                       connected to us
- * @param session session to use (or NULL)
+ * @return #GNUNET_OK if the message was fine, #GNUNET_SYSERR on serious error
  */
-void
+int
 GST_neighbours_handle_connect (const struct GNUNET_MessageHeader *message,
-                               const struct GNUNET_PeerIdentity *peer,
-                               const struct GNUNET_HELLO_Address *address,
-                               struct Session *session)
+                               const struct GNUNET_PeerIdentity *peer)
 {
   const struct SessionConnectMessage *scm;
   struct NeighbourMapEntry *n;
   struct GNUNET_TIME_Absolute ts;
 
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-              "Received CONNECT message from peer `%s'\n",
-             GNUNET_i2s (peer));
-
   if (ntohs (message->size) != sizeof (struct SessionConnectMessage))
   {
     GNUNET_break_op (0);
-    return;
+    return GNUNET_SYSERR;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# CONNECT messages received"),
+                            1, GNUNET_NO);
   if (NULL == neighbours)
-    return; /* we're shutting down */
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+                _("CONNECT request from peer `%s' ignored due impending shutdown\n"),
+                GNUNET_i2s (peer));
+    return GNUNET_OK; /* we're shutting down */
+  }
   scm = (const struct SessionConnectMessage *) message;
   GNUNET_break_op (0 == ntohl (scm->reserved));
   ts = GNUNET_TIME_absolute_ntoh (scm->timestamp);
   n = lookup_neighbour (peer);
   if (NULL == n)
+  {
+    /* This is a new neighbour and set to not connected */
     n = setup_neighbour (peer);
-  n->send_connect_ack = 1;
+  }
+
+  /* Remember this CONNECT message in neighbour */
+  n->ack_state = ACK_SEND_CONNECT_ACK;
   n->connect_ack_timestamp = ts;
 
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Received CONNECT for peer `%s' in state %s/%s\n",
+              GNUNET_i2s (peer),
+              GNUNET_TRANSPORT_ps2s (n->state),
+              print_ack_state (n->ack_state));
+
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
-    n->state = S_CONNECT_RECV_BLACKLIST_INBOUND;
-    /* Do a blacklist check for the new address */
-    check_blacklist (peer, ts, address, session);
-    break;
-  case S_INIT_ATS:
-    /* CONNECT message takes priority over us asking ATS for address */
-    n->state = S_CONNECT_RECV_BLACKLIST_INBOUND;
-    /* fallthrough */
-  case S_INIT_BLACKLIST:
-  case S_CONNECT_SENT:
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
-    /* It can never hurt to have an alternative address in the above cases,
-       see if it is allowed */
-    check_blacklist (peer, ts, address, session);
-    break;
-  case S_CONNECTED:
-    /* we are already connected and can thus send the ACK immediately;
-       still, it can never hurt to have an alternative address, so also
-       tell ATS  about it */
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
+    /* Request an address from ATS to send CONNECT_ACK to this peer */
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+    if (NULL == n->suggest_handle)
+      GNUNET_ATS_suggest_address (GST_ats, peer, address_suggest_cont, n);
+    break;
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
+    /* CONNECT message takes priority over us asking ATS for address:
+     * Wait for ATS to suggest an address and send CONNECT_ACK */
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+    /* We already wait for an address to send an CONNECT_ACK */
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
+    /* Send ACK immediately */
+    n->ack_state = ACK_SEND_SESSION_ACK;
+    send_connect_ack_message (n->primary_address.address,
+                              n->primary_address.session, ts);
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECTED:
+    /* we are already connected and can thus send the ACK immediately */
     GNUNET_assert (NULL != n->primary_address.address);
     GNUNET_assert (NULL != n->primary_address.session);
-    n->send_connect_ack = 0;
-    send_session_connect_ack_message (n->primary_address.address,
-                                     n->primary_address.session, ts);
-    check_blacklist (peer, ts, address, session);
-    break;
-  case S_RECONNECT_ATS:
-  case S_RECONNECT_BLACKLIST:
-  case S_RECONNECT_SENT:
-    /* It can never hurt to have an alternative address in the above cases,
-       see if it is allowed */
-    check_blacklist (peer, ts, address, session);
-    break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-    /* we are already connected and can thus send the ACK immediately;
+    n->ack_state = ACK_SEND_SESSION_ACK;
+    send_connect_ack_message (n->primary_address.address,
+                              n->primary_address.session, ts);
+    break;
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
+    /* We wait for ATS address suggestion */
+    break;
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    /* We received a CONNECT message while waiting for a CONNECT_ACK in fast
+     * reconnect. Send CONNECT_ACK immediately */
+    n->ack_state = ACK_SEND_SESSION_ACK;
+    send_connect_ack_message (n->primary_address.address,
+        n->primary_address.session, n->connect_ack_timestamp);
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+    /* We are already connected and can thus send the ACK immediately;
        still, it can never hurt to have an alternative address, so also
        tell ATS  about it */
     GNUNET_assert (NULL != n->primary_address.address);
     GNUNET_assert (NULL != n->primary_address.session);
-    n->send_connect_ack = 0;
-    send_session_connect_ack_message (n->primary_address.address,
-                                     n->primary_address.session, ts);
-    check_blacklist (peer, ts, address, session);
+    n->ack_state = ACK_SEND_SESSION_ACK;
+    send_connect_ack_message (n->primary_address.address,
+        n->primary_address.session, ts);
     break;
-  case S_DISCONNECT:
-    /* get rid of remains without terminating sessions, ready to re-try */
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
+    /* Get rid of remains without terminating sessions, ready to re-try */
     free_neighbour (n, GNUNET_YES);
     n = setup_neighbour (peer);
-    n->state = S_CONNECT_RECV_ATS;
+    /* Remember the CONNECT time stamp for ACK message */
+    n->ack_state = ACK_SEND_CONNECT_ACK;
+    n->connect_ack_timestamp = ts;
+    /* Request an address for the peer */
+    GNUNET_ATS_suggest_address (GST_ats, peer, address_suggest_cont, n);
     GNUNET_ATS_reset_backoff (GST_ats, peer);
-    n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, peer);
+    set_state (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS);
     break;
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     /* should not be possible */
     GNUNET_assert (0);
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
-    free_neighbour (n, GNUNET_NO);
-    break;
+    return GNUNET_SYSERR;
   }
+  return GNUNET_OK;
 }
 
-
-/**
- * For an existing neighbour record, set the active connection to
- * use the given address.
- *
- * @param peer identity of the peer to switch the address for
- * @param address address of the other peer, NULL if other peer
- *                       connected to us
- * @param session session to use (or NULL)
- * @param ats performance data
- * @param ats_count number of entries in ats
- * @param bandwidth_in inbound quota to be used when connection is up,
- *     0 to disconnect from peer
- * @param bandwidth_out outbound quota to be used when connection is up,
- *     0 to disconnect from peer
- */
-void
-GST_neighbours_switch_to_address (const struct GNUNET_PeerIdentity *peer,
-                                 const struct GNUNET_HELLO_Address *address,
-                                 struct Session *session,
-                                 const struct GNUNET_ATS_Information *ats,
-                                 uint32_t ats_count,
-                                 struct GNUNET_BANDWIDTH_Value32NBO
-                                 bandwidth_in,
-                                 struct GNUNET_BANDWIDTH_Value32NBO
-                                 bandwidth_out)
+static void
+switch_address_bl_check_cont (void *cls,
+    const struct GNUNET_PeerIdentity *peer, int result)
 {
-  struct NeighbourMapEntry *n;
+  struct BlacklistCheckSwitchContext *blc_ctx = cls;
   struct GNUNET_TRANSPORT_PluginFunctions *papi;
+  struct NeighbourMapEntry *n;
 
-  GNUNET_assert (address->transport_name != NULL);
-  if (NULL == (n = lookup_neighbour (peer)))
-    return;
+  papi = GST_plugins_find (blc_ctx->address->transport_name);
 
-  /* Obtain an session for this address from plugin */
-  if (NULL == (papi = GST_plugins_find (address->transport_name)))
+  if ( (NULL == (n = lookup_neighbour (peer))) || (result == GNUNET_NO) ||
+       (NULL == (papi)) )
   {
-    /* we don't have the plugin for this address */
-    GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
-    return;
-  }
-  if ((NULL == session) && (0 == address->address_length))
-  {
-    GNUNET_break (0);
-    if (strlen (address->transport_name) > 0)
-      GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+    if (NULL == n)
+    {
+      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                  "Peer %s is unknown, suggestion ignored\n",
+                  GNUNET_i2s (peer));
+    }
+    if (result == GNUNET_NO)
+    {
+      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+          "Blacklist denied to switch to suggested address `%s' session %p for peer `%s'\n",
+          GST_plugins_a2s (blc_ctx->address),
+          blc_ctx->session,
+          GNUNET_i2s (&blc_ctx->address->peer));
+    }
+    if (NULL == papi)
+    {
+      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+          "Plugin `%s' for suggested address `%s' session %p for peer `%s' is not available\n",
+          blc_ctx->address->transport_name,
+          GST_plugins_a2s (blc_ctx->address),
+          blc_ctx->session,
+          GNUNET_i2s (&blc_ctx->address->peer));
+    }
+
+    /* This address is blacklisted, delete address and session (if existing) in ATS */
+    GNUNET_ATS_address_destroyed (GST_ats, blc_ctx->address, blc_ctx->session);
+
+    if ( (GNUNET_YES == (GNUNET_HELLO_address_check_option (blc_ctx->address,
+          GNUNET_HELLO_ADDRESS_INFO_INBOUND))) && (NULL != blc_ctx->session))
+    {
+      /* This is an inbound address, destroy full  address */
+      GNUNET_ATS_address_destroyed (GST_ats, blc_ctx->address, NULL );
+    }
+
+    /* Remove blacklist check and clean up */
+    GNUNET_CONTAINER_DLL_remove (pending_bc_head, pending_bc_tail, blc_ctx);
+    GNUNET_HELLO_address_free (blc_ctx->address);
+    GNUNET_free_non_null (blc_ctx->ats);
+    GNUNET_free (blc_ctx);
     return;
   }
 
   GNUNET_log (GNUNET_ERROR_TYPE_INFO,
-              "ATS tells us to switch to address '%s' session %p for "
-              "peer `%s' in state %s (quota in/out %u %u )\n",
-              (address->address_length != 0) ? GST_plugins_a2s (address): "<inbound>",
-              session,
-              GNUNET_i2s (peer),
-              print_state (n->state),
-              ntohl (bandwidth_in.value__),
-              ntohl (bandwidth_out.value__));
+      "Blacklist accepted address `%s' session %p for peer `%s'\n",
+      GST_plugins_a2s (blc_ctx->address),
+      blc_ctx->session,
+      GNUNET_i2s (&blc_ctx->address->peer));
 
-  if (NULL == session)
+  if (NULL == blc_ctx->session)
   {
-    session = papi->get_session (papi->cls, address);
+    blc_ctx->session = papi->get_session (papi->cls, blc_ctx->address);
     GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
                 "Obtained new session for peer `%s' and  address '%s': %p\n",
-                GNUNET_i2s (&address->peer), GST_plugins_a2s (address), session);
+                GNUNET_i2s (&blc_ctx->address->peer), GST_plugins_a2s (blc_ctx->address), blc_ctx->session);
   }
-  if (NULL == session)
+  if (NULL == blc_ctx->session)
   {
+    /* No session could be obtained, remove blacklist check and clean up */
     GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-               "Failed to obtain new session for peer `%s' and  address '%s'\n",
-               GNUNET_i2s (&address->peer), GST_plugins_a2s (address));
-    GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+                "Failed to obtain new session for peer `%s' and  address '%s'\n",
+                GNUNET_i2s (&blc_ctx->address->peer),
+                GST_plugins_a2s (blc_ctx->address));
+    /* Delete address in ATS */
+    GNUNET_ATS_address_destroyed (GST_ats, blc_ctx->address, NULL);
+
+    GNUNET_CONTAINER_DLL_remove (pending_bc_head, pending_bc_tail, blc_ctx);
+    GNUNET_HELLO_address_free (blc_ctx->address);
+    GNUNET_free_non_null (blc_ctx->ats);
+    GNUNET_free (blc_ctx);
     return;
   }
+
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
     GNUNET_break (0);
     free_neighbour (n, GNUNET_NO);
-    return;
-  case S_INIT_ATS:
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_INIT_BLACKLIST;
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_INIT_BLACKLIST:
-    /* ATS suggests a different address, switch again */
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
+    return;
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
+    /* We requested an address and ATS suggests one:
+     * set primary address and send CONNECT message*/
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    if ( (ACK_SEND_CONNECT_ACK == n->ack_state) )
+    {
+      /* Send pending CONNECT_ACK message */
+      n->ack_state = ACK_SEND_SESSION_ACK;
+      send_connect_ack_message (n->primary_address.address,
+          n->primary_address.session, n->connect_ack_timestamp);
+    }
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
+    send_session_connect (&n->primary_address);
     break;
-  case S_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+    /* ATS suggested a new address while waiting for an CONNECT_ACK:
+     * Switch and send new CONNECT */
     /* ATS suggests a different address, switch again */
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_INIT_BLACKLIST;
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_CONNECT_RECV_ATS:
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_CONNECT_RECV_BLACKLIST;
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                     n->connect_ack_timestamp,
-                     address, session);
-    break;
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    if (ACK_SEND_CONNECT_ACK == n->ack_state)
+    {
+      /* Send pending CONNECT_ACK message */
+      n->ack_state = ACK_SEND_SESSION_ACK;
+      send_connect_ack_message (n->primary_address.address,
+          n->primary_address.session, n->connect_ack_timestamp);
+    }
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
+    send_session_connect (&n->primary_address);
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+    /* We requested an address and ATS suggests one:
+     * set primary address and send CONNECT_ACK message*/
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    /* Send an ACK message as a response to the CONNECT msg */
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
+    send_connect_ack_message (n->primary_address.address,
+                              n->primary_address.session,
+                              n->connect_ack_timestamp);
+    if ( (ACK_SEND_CONNECT_ACK == n->ack_state) ||
+         (ACK_UNDEFINED == n->ack_state) )
+      n->ack_state = ACK_SEND_SESSION_ACK;
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
     /* ATS asks us to switch while we were trying to connect; switch to new
        address and check blacklist again */
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
+    if ( (ACK_SEND_CONNECT_ACK == n->ack_state) )
+    {
+      n->ack_state = ACK_SEND_SESSION_ACK;
+      send_connect_ack_message (n->primary_address.address,
+          n->primary_address.session, n->connect_ack_timestamp);
+    }
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
     break;
-  case S_CONNECTED:
+  case GNUNET_TRANSPORT_PS_CONNECTED:
     GNUNET_assert (NULL != n->primary_address.address);
     GNUNET_assert (NULL != n->primary_address.session);
-    if (n->primary_address.session == session)
+    if (n->primary_address.session == blc_ctx->session)
     {
       /* not an address change, just a quota change */
-      set_address (&n->primary_address,
-                  address, session, bandwidth_in, bandwidth_out, GNUNET_YES);
+      set_primary_address (n, blc_ctx->address, blc_ctx->session,
+          blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_YES);
       break;
     }
     /* ATS asks us to switch a life connection; see if we can get
        a CONNECT_ACK on it before we actually do this! */
-    set_address (&n->alternative_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_CONNECTED_SWITCHING_BLACKLIST;
-    check_blacklist (&n->id,
-                    GNUNET_TIME_absolute_get (),
-                    address, session);
-    break;
-  case S_RECONNECT_ATS:
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_RECONNECT_BLACKLIST;
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_RECONNECT_BLACKLIST:
-    /* ATS asks us to switch while we were trying to reconnect; switch to new
-       address and check blacklist again */
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_RECONNECT_SENT:
-    /* ATS asks us to switch while we were trying to reconnect; switch to new
-       address and check blacklist again */
-    set_address (&n->primary_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_RECONNECT_BLACKLIST;
-    n->timeout = GNUNET_TIME_relative_to_absolute (BLACKLIST_RESPONSE_TIMEOUT);
-    check_blacklist (&n->id,
-                    n->connect_ack_timestamp,
-                    address, session);
-    break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    if (n->primary_address.session == session)
+    set_alternative_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
+    GNUNET_STATISTICS_update (GST_stats, gettext_noop
+        ("# Attempts to switch addresses"), 1, GNUNET_NO);
+    send_session_connect (&n->alternative_address);
+    break;
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    if ( (ACK_SEND_CONNECT_ACK == n->ack_state) )
     {
-      /* ATS switches back to still-active session */
-      free_address (&n->alternative_address);
-      n->state = S_CONNECTED;
-      break;
+      /* Send pending CONNECT_ACK message */
+      n->ack_state = ACK_SEND_SESSION_ACK;
+      send_connect_ack_message (n->primary_address.address,
+          n->primary_address.session, n->connect_ack_timestamp);
     }
-    /* ATS asks us to switch a life connection, update blacklist check */
-    set_address (&n->alternative_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    check_blacklist (&n->id,
-                    GNUNET_TIME_absolute_get (),
-                    address, session);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT));
+    send_session_connect (&n->primary_address);
     break;
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-    if (n->primary_address.session == session)
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    /* ATS asks us to switch while we were trying to reconnect; switch to new
+       address and send CONNECT again */
+    set_primary_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out, GNUNET_NO);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT));
+    send_session_connect (&n->primary_address);
+    break;
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+    if ( (0 == GNUNET_HELLO_address_cmp(n->primary_address.address,
+        blc_ctx->address) && n->primary_address.session == blc_ctx->session) )
     {
       /* ATS switches back to still-active session */
       free_address (&n->alternative_address);
-      n->state = S_CONNECTED;
+      set_state (n, GNUNET_TRANSPORT_PS_CONNECTED);
       break;
     }
-    /* ATS asks us to switch a life connection, update blacklist check */
-    set_address (&n->alternative_address,
-                address, session, bandwidth_in, bandwidth_out, GNUNET_NO);
-    n->state = S_CONNECTED_SWITCHING_BLACKLIST;
-    check_blacklist (&n->id,
-                    GNUNET_TIME_absolute_get (),
-                    address, session);
-    break;
-  case S_DISCONNECT:
+    /* ATS asks us to switch a life connection, send */
+    set_alternative_address (n, blc_ctx->address, blc_ctx->session,
+        blc_ctx->bandwidth_in, blc_ctx->bandwidth_out);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT,
+        GNUNET_TIME_relative_to_absolute (SETUP_CONNECTION_TIMEOUT));
+    send_session_connect (&n->alternative_address);
+    break;
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
     /* not going to switch addresses while disconnecting */
     return;
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     GNUNET_assert (0);
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
     break;
   }
+
+  GNUNET_CONTAINER_DLL_remove (pending_bc_head, pending_bc_tail, blc_ctx);
+  GNUNET_HELLO_address_free(blc_ctx->address);
+  GNUNET_free_non_null (blc_ctx->ats);
+  GNUNET_free (blc_ctx);
+  return;
+}
+
+
+/**
+ * For the given peer, switch to this address.
+ *
+ * Before accepting this addresses and actively using it, a blacklist check
+ * is performed. If this blacklist check fails the address will be destroyed.
+ *
+ * @param peer identity of the peer to switch the address for
+ * @param address address of the other peer,
+ * @param session session to use or NULL if transport should initiate a session
+ * @param ats performance data
+ * @param ats_count number of entries in ats
+ * @param bandwidth_in inbound quota to be used when connection is up,
+ *     0 to disconnect from peer
+ * @param bandwidth_out outbound quota to be used when connection is up,
+ *     0 to disconnect from peer
+ */
+void
+GST_neighbours_switch_to_address (const struct GNUNET_PeerIdentity *peer,
+                                 const struct GNUNET_HELLO_Address *address,
+                                 struct Session *session,
+                                 const struct GNUNET_ATS_Information *ats,
+                                 uint32_t ats_count,
+                                 struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in,
+                                 struct GNUNET_BANDWIDTH_Value32NBO bandwidth_out)
+{
+  struct NeighbourMapEntry *n;
+  struct GST_BlacklistCheck *blc;
+  struct BlacklistCheckSwitchContext *blc_ctx;
+  int c;
+
+  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+              "ATS has decided on an address for peer %s\n",
+              GNUNET_i2s (peer));
+  GNUNET_assert (NULL != address->transport_name);
+  if (NULL == (n = lookup_neighbour (peer)))
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                "Peer %s is unknown, suggestion ignored\n",
+                GNUNET_i2s (peer));
+    return;
+  }
+
+  /* Check if plugin is available */
+  if (NULL == (GST_plugins_find (address->transport_name)))
+  {
+    /* we don't have the plugin for this address */
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                "Plugin `%s' is unknown, suggestion for peer %s ignored\n",
+                address->transport_name,
+                GNUNET_i2s (peer));
+    GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+    return;
+  }
+  if ((NULL == session) &&
+      (GNUNET_HELLO_address_check_option (address, GNUNET_HELLO_ADDRESS_INFO_INBOUND)))
+  {
+    /* This is a inbound address and we do not have a session to use! */
+    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+                "Inbound address without session `%s'! Destroying address...\n",
+                GST_plugins_a2s (address));
+    GNUNET_ATS_address_destroyed (GST_ats, address, NULL);
+    return;
+  }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+    "ATS suggests %s address '%s' session %p for "
+    "peer `%s' in state %s/%s (quota in/out %u %u )\n",
+    GNUNET_HELLO_address_check_option (address,
+        GNUNET_HELLO_ADDRESS_INFO_INBOUND) ? "inbound" : "outbound",
+    GST_plugins_a2s (address), session, GNUNET_i2s (peer),
+    GNUNET_TRANSPORT_ps2s (n->state), print_ack_state (n->ack_state),
+    ntohl (bandwidth_in.value__), ntohl (bandwidth_out.value__));
+
+  /* Perform blacklist check */
+  blc_ctx = GNUNET_new (struct BlacklistCheckSwitchContext);
+  blc_ctx->address = GNUNET_HELLO_address_copy (address);
+  blc_ctx->session = session;
+  blc_ctx->bandwidth_in = bandwidth_in;
+  blc_ctx->bandwidth_out = bandwidth_out;
+  blc_ctx->ats_count = ats_count;
+  blc_ctx->ats = NULL;
+  if (ats_count > 0)
+  {
+    blc_ctx->ats = GNUNET_malloc (ats_count * sizeof (struct GNUNET_ATS_Information));
+    for (c = 0; c < ats_count; c++)
+    {
+      blc_ctx->ats[c].type = ats[c].type;
+      blc_ctx->ats[c].value = ats[c].value;
+    }
+  }
+
+  GNUNET_CONTAINER_DLL_insert (pending_bc_head, pending_bc_tail, blc_ctx);
+  if (NULL != (blc = GST_blacklist_test_allowed (peer, address->transport_name,
+      &switch_address_bl_check_cont, blc_ctx)))
+  {
+    blc_ctx->blc = blc;
+  }
 }
 
 
@@ -2468,42 +2837,41 @@ utilization_transmission (void *cls,
 
 }
 
+
 void
 GST_neighbours_notify_data_recv (const struct GNUNET_PeerIdentity *peer,
-                 const struct GNUNET_HELLO_Address *address,
-                 struct Session *session,
-                 const struct GNUNET_MessageHeader *message)
+                                 const struct GNUNET_HELLO_Address *address,
+                                 struct Session *session,
+                                 const struct GNUNET_MessageHeader *message)
 {
   struct NeighbourMapEntry *n;
+
   n = lookup_neighbour (peer);
   if (NULL == n)
-  {
-      return;
-  }
+    return;
   n->util_total_bytes_recv += ntohs(message->size);
 }
 
+
 void
 GST_neighbours_notify_payload_recv (const struct GNUNET_PeerIdentity *peer,
-                 const struct GNUNET_HELLO_Address *address,
-                 struct Session *session,
-                 const struct GNUNET_MessageHeader *message)
+                                    const struct GNUNET_HELLO_Address *address,
+                                    struct Session *session,
+                                    const struct GNUNET_MessageHeader *message)
 {
   struct NeighbourMapEntry *n;
   n = lookup_neighbour (peer);
   if (NULL == n)
-  {
-      return;
-  }
+    return;
   n->util_payload_bytes_recv += ntohs(message->size);
 }
 
 
 void
 GST_neighbours_notify_data_sent (const struct GNUNET_PeerIdentity *peer,
-                     const struct GNUNET_HELLO_Address *address,
-                     struct Session *session,
-                     size_t size)
+                                 const struct GNUNET_HELLO_Address *address,
+                                 struct Session *session,
+                                 size_t size)
 {
   struct NeighbourMapEntry *n;
   n = lookup_neighbour (peer);
@@ -2514,16 +2882,15 @@ GST_neighbours_notify_data_sent (const struct GNUNET_PeerIdentity *peer,
   n->util_total_bytes_sent += size;
 }
 
+
 void
 GST_neighbours_notify_payload_sent (const struct GNUNET_PeerIdentity *peer,
-    size_t size)
+                                    size_t size)
 {
   struct NeighbourMapEntry *n;
   n = lookup_neighbour (peer);
   if (NULL == n)
-  {
-      return;
-  }
+    return;
   n->util_payload_bytes_sent += size;
 }
 
@@ -2548,96 +2915,69 @@ master_task (void *cls,
   GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
              "Master task runs for neighbour `%s' in state %s with timeout in %s\n",
              GNUNET_i2s (&n->id),
-             print_state(n->state),
+             GNUNET_TRANSPORT_ps2s(n->state),
              GNUNET_STRINGS_relative_time_to_string (delay,
                                                      GNUNET_YES));
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
     /* invalid state for master task, clean up */
     GNUNET_break (0);
-    n->state = S_DISCONNECT_FINISHED;
     free_neighbour (n, GNUNET_NO);
     return;
-  case S_INIT_ATS:
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out waiting for ATS to provide address\n",
                  GNUNET_i2s (&n->id));
-      n->state = S_DISCONNECT_FINISHED;
-      free_neighbour (n, GNUNET_NO);
-      return;
-    }
-    break;
-  case S_INIT_BLACKLIST:
-    if (0 == delay.rel_value_us)
-    {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                 "Connection to `%s' timed out waiting for BLACKLIST to approve address\n",
-                 GNUNET_i2s (&n->id));
-      n->state = S_DISCONNECT_FINISHED;
       free_neighbour (n, GNUNET_NO);
       return;
     }
     break;
-  case S_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out waiting for other peer to send CONNECT_ACK\n",
                  GNUNET_i2s (&n->id));
-      disconnect_neighbour (n);
-      return;
-    }
-    break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-    if (0 == delay.rel_value_us)
-    {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                  "Connection to `%s' timed out waiting BLACKLIST to approve address to use for received CONNECT\n",
-                  GNUNET_i2s (&n->id));
-      n->state = S_DISCONNECT_FINISHED;
-      free_neighbour (n, GNUNET_NO);
+      /* We could not send to this address, delete address and session */
+      if (NULL != n->primary_address.session)
+        GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address,
+            n->primary_address.session);
+      GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL);
+
+      /* Remove address and request and additional one */
+      unset_primary_address (n);
+      set_state_and_timeout (n, GNUNET_TRANSPORT_PS_INIT_ATS,
+          GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
       return;
     }
     break;
-  case S_CONNECT_RECV_ATS:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out waiting ATS to provide address to use for CONNECT_ACK\n",
                  GNUNET_i2s (&n->id));
-      n->state = S_DISCONNECT_FINISHED;
-      free_neighbour (n, GNUNET_NO);
-      return;
-    }
-    break;
-  case S_CONNECT_RECV_BLACKLIST:
-    if (0 == delay.rel_value_us)
-    {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                 "Connection to `%s' timed out waiting BLACKLIST to approve address to use for CONNECT_ACK\n",
-                 GNUNET_i2s (&n->id));
-      n->state = S_DISCONNECT_FINISHED;
       free_neighbour (n, GNUNET_NO);
       return;
     }
     break;
-  case S_CONNECT_RECV_ACK:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out waiting for other peer to send SESSION_ACK\n",
                  GNUNET_i2s (&n->id));
       disconnect_neighbour (n);
       return;
     }
     break;
-  case S_CONNECTED:
+  case GNUNET_TRANSPORT_PS_CONNECTED:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out, missing KEEPALIVE_RESPONSEs\n",
                  GNUNET_i2s (&n->id));
       disconnect_neighbour (n);
@@ -2646,82 +2986,61 @@ master_task (void *cls,
     try_transmission_to_peer (n);
     send_keepalive (n);
     break;
-  case S_RECONNECT_ATS:
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out, waiting for ATS replacement address\n",
                  GNUNET_i2s (&n->id));
       disconnect_neighbour (n);
       return;
     }
     break;
-  case S_RECONNECT_BLACKLIST:
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                 "Connection to `%s' timed out, waiting for BLACKLIST to approve replacement address\n",
-                 GNUNET_i2s (&n->id));
-      disconnect_neighbour (n);
-      return;
-    }
-    break;
-  case S_RECONNECT_SENT:
-    if (0 == delay.rel_value_us)
-    {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out, waiting for other peer to CONNECT_ACK replacement address\n",
                  GNUNET_i2s (&n->id));
       disconnect_neighbour (n);
       return;
     }
     break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    if (0 == delay.rel_value_us)
-    {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
-                 "Connection to `%s' timed out, missing KEEPALIVE_RESPONSEs\n",
-                 GNUNET_i2s (&n->id));
-      disconnect_neighbour (n);
-      return;
-    }
-    try_transmission_to_peer (n);
-    send_keepalive (n);
-    break;
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
     if (0 == delay.rel_value_us)
     {
-      GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                  "Connection to `%s' timed out, missing KEEPALIVE_RESPONSEs (after trying to CONNECT on alternative address)\n",
                  GNUNET_i2s (&n->id));
+      GNUNET_STATISTICS_update (GST_stats, gettext_noop
+          ("# Failed attempts to switch addresses (no response)"), 1, GNUNET_NO);
       disconnect_neighbour (n);
       return;
     }
     try_transmission_to_peer (n);
     send_keepalive (n);
     break;
-  case S_DISCONNECT:
-    GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
+    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
                "Cleaning up connection to `%s' after sending DISCONNECT\n",
                GNUNET_i2s (&n->id));
     free_neighbour (n, GNUNET_NO);
     return;
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     /* how did we get here!? */
     GNUNET_assert (0);
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
     break;
   }
-  if ( (S_CONNECTED_SWITCHING_CONNECT_SENT == n->state) ||
-       (S_CONNECTED_SWITCHING_BLACKLIST == n->state) ||
-       (S_CONNECTED == n->state) )
+  if ( (GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT == n->state) ||
+       (GNUNET_TRANSPORT_PS_CONNECTED == n->state) )
   {
-    /* if we are *now* in one of these three states, we're sending
+    /* if we are *now* in one of the two states, we're sending
        keep alive messages, so we need to consider the keepalive
        delay, not just the connection timeout */
     delay = GNUNET_TIME_relative_min (GNUNET_TIME_absolute_get_remaining (n->keep_alive_time),
@@ -2745,11 +3064,14 @@ send_session_ack_message (struct NeighbourMapEntry *n)
 {
   struct GNUNET_MessageHeader msg;
 
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO, "Sending SESSION_ACK message to peer `%s'\n",
+              GNUNET_i2s (&n->id));
+
   msg.size = htons (sizeof (struct GNUNET_MessageHeader));
   msg.type = htons (GNUNET_MESSAGE_TYPE_TRANSPORT_SESSION_ACK);
   (void) send_with_session(n,
                           (const char *) &msg, sizeof (struct GNUNET_MessageHeader),
-                          UINT32_MAX, GNUNET_TIME_UNIT_FOREVER_REL,
+                          UINT32_MAX, GNUNET_TIME_UNIT_FOREVER_REL, GNUNET_NO,
                           NULL, NULL);
 }
 
@@ -2763,8 +3085,9 @@ send_session_ack_message (struct NeighbourMapEntry *n)
  * @param address address of the other peer, NULL if other peer
  *                       connected to us
  * @param session session to use (or NULL)
+ * @return #GNUNET_OK if the message was fine, #GNUNET_SYSERR on serious error
  */
-void
+int
 GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
                                    const struct GNUNET_PeerIdentity *peer,
                                    const struct GNUNET_HELLO_Address *address,
@@ -2774,15 +3097,19 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
   struct GNUNET_TIME_Absolute ts;
   struct NeighbourMapEntry *n;
 
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
               "Received CONNECT_ACK message from peer `%s'\n",
               GNUNET_i2s (peer));
 
   if (ntohs (message->size) != sizeof (struct SessionConnectMessage))
   {
     GNUNET_break_op (0);
-    return;
+    return GNUNET_SYSERR;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# CONNECT_ACK messages received"),
+                            1, GNUNET_NO);
   scm = (const struct SessionConnectMessage *) message;
   GNUNET_break_op (ntohl (scm->reserved) == 0);
   if (NULL == (n = lookup_neighbour (peer)))
@@ -2791,27 +3118,30 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
                               gettext_noop
                               ("# unexpected CONNECT_ACK messages (no peer)"),
                               1, GNUNET_NO);
-    return;
+    return GNUNET_SYSERR;
   }
   ts = GNUNET_TIME_absolute_ntoh (scm->timestamp);
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
     GNUNET_break (0);
     free_neighbour (n, GNUNET_NO);
-    return;
-  case S_INIT_ATS:
-  case S_INIT_BLACKLIST:
+    return GNUNET_SYSERR;
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
     GNUNET_STATISTICS_update (GST_stats,
                               gettext_noop
                               ("# unexpected CONNECT_ACK messages (not ready)"),
                               1, GNUNET_NO);
     break;
-  case S_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
     if (ts.abs_value_us != n->primary_address.connect_timestamp.abs_value_us)
-      break; /* ACK does not match our original CONNECT message */
-    n->state = S_CONNECTED;
-    n->timeout = GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT);
+    {
+      GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+                  "CONNECT_ACK ignored as the timestamp does not match our CONNECT request\n");
+      return GNUNET_OK;
+    }
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+        GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT));
     GNUNET_STATISTICS_set (GST_stats,
                           gettext_noop ("# peers connected"),
                           ++neighbours_connected,
@@ -2819,9 +3149,11 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
     connect_notify_cb (callback_cls, &n->id,
                        n->primary_address.bandwidth_in,
                        n->primary_address.bandwidth_out);
-    /* Tell ATS that the outbound session we created to send CONNECT was successfull */
-    GST_ats_add_address (n->primary_address.address, n->primary_address.session);
-    set_address (&n->primary_address,
+    /* Tell ATS that the outbound session we created to send CONNECT was successful */
+    GST_ats_add_address (n->primary_address.address,
+                         n->primary_address.session,
+                         NULL, 0);
+    set_primary_address (n,
                 n->primary_address.address,
                 n->primary_address.session,
                 n->primary_address.bandwidth_in,
@@ -2829,21 +3161,18 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
                 GNUNET_YES);
     send_session_ack_message (n);
     break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
     GNUNET_STATISTICS_update (GST_stats,
                               gettext_noop
                               ("# unexpected CONNECT_ACK messages (not ready)"),
                               1, GNUNET_NO);
     break;
-  case S_CONNECTED:
-    /* duplicate CONNECT_ACK, let's answer by duplciate SESSION_ACK just in case */
+  case GNUNET_TRANSPORT_PS_CONNECTED:
+    /* duplicate CONNECT_ACK, let's answer by duplicate SESSION_ACK just in case */
     send_session_ack_message (n);
     break;
-  case S_RECONNECT_ATS:
-  case S_RECONNECT_BLACKLIST:
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
     /* we didn't expect any CONNECT_ACK, as we are waiting for ATS
        to give us a new address... */
     GNUNET_STATISTICS_update (GST_stats,
@@ -2851,47 +3180,48 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
                               ("# unexpected CONNECT_ACK messages (waiting on ATS)"),
                               1, GNUNET_NO);
     break;
-  case S_RECONNECT_SENT:
-    /* new address worked; go back to connected! */
-    n->state = S_CONNECTED;
-    send_session_ack_message (n);
-    break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    /* duplicate CONNECT_ACK, let's answer by duplciate SESSION_ACK just in case */
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    /* Reconnecting with new address address worked; go back to connected! */
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+        GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT));
     send_session_ack_message (n);
     break;
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
     /* new address worked; adopt it and go back to connected! */
-    n->state = S_CONNECTED;
-    n->timeout = GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+        GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT));
     GNUNET_break (GNUNET_NO == n->alternative_address.ats_active);
 
-    GST_ats_add_address (n->alternative_address.address, n->alternative_address.session);
-    set_address (&n->primary_address,
-                n->alternative_address.address,
-                n->alternative_address.session,
-                n->alternative_address.bandwidth_in,
-                n->alternative_address.bandwidth_out,
-                GNUNET_YES);
+    /* Notify about session... perhaps we obtained it */
+    GST_ats_add_address (n->alternative_address.address,
+        n->alternative_address.session, NULL, 0);
+    /* Set primary addresses */
+    set_primary_address (n, n->alternative_address.address,
+        n->alternative_address.session, n->alternative_address.bandwidth_in,
+        n->alternative_address.bandwidth_out, GNUNET_YES);
+    GNUNET_STATISTICS_update (GST_stats, gettext_noop
+        ("# Successful attempts to switch addresses"), 1, GNUNET_NO);
+
     free_address (&n->alternative_address);
     send_session_ack_message (n);
     break;
-  case S_DISCONNECT:
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
     GNUNET_STATISTICS_update (GST_stats,
                               gettext_noop
                               ("# unexpected CONNECT_ACK messages (disconnecting)"),
                               1, GNUNET_NO);
-    break;
-  case S_DISCONNECT_FINISHED:
+    return GNUNET_SYSERR;
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     GNUNET_assert (0);
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
-    break;
+    return GNUNET_SYSERR;
   }
+  return GNUNET_OK;
 }
 
 
@@ -2901,7 +3231,7 @@ GST_neighbours_handle_connect_ack (const struct GNUNET_MessageHeader *message,
  *
  * @param peer identity of the peer where the session died
  * @param session session that is gone
- * @return GNUNET_YES if this was a session used, GNUNET_NO if
+ * @return #GNUNET_YES if this was a session used, #GNUNET_NO if
  *        this session was not in use
  */
 int
@@ -2919,7 +3249,8 @@ GST_neighbours_session_terminated (const struct GNUNET_PeerIdentity *peer,
     bcc_next = bcc->next;
     if (bcc->na.session == session)
     {
-      GST_blacklist_test_cancel (bcc->bc);
+      if (NULL != bcc->bc)
+        GST_blacklist_test_cancel (bcc->bc);
       GNUNET_HELLO_address_free (bcc->na.address);
       GNUNET_CONTAINER_DLL_remove (bc_head,
                                   bc_tail,
@@ -2933,90 +3264,98 @@ GST_neighbours_session_terminated (const struct GNUNET_PeerIdentity *peer,
   {
     if (session == n->alternative_address.session)
     {
-      free_address (&n->alternative_address);
-      if ( (S_CONNECTED_SWITCHING_BLACKLIST == n->state) ||
-          (S_CONNECTED_SWITCHING_CONNECT_SENT == n->state) )
-       n->state = S_CONNECTED;
+      if ( (GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT == n->state) )
+        set_state (n, GNUNET_TRANSPORT_PS_CONNECTED);
       else
-       GNUNET_break (0);
+        free_address (&n->alternative_address);
     }
     return GNUNET_NO; /* doesn't affect us further */
   }
 
   n->expect_latency_response = GNUNET_NO;
+  /* The session for neighbour's primary address died */
   switch (n->state)
   {
-  case S_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
     GNUNET_break (0);
     free_neighbour (n, GNUNET_NO);
     return GNUNET_YES;
-  case S_INIT_ATS:
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
     GNUNET_break (0);
     free_neighbour (n, GNUNET_NO);
     return GNUNET_YES;
-  case S_INIT_BLACKLIST:
-  case S_CONNECT_SENT:
-    free_address (&n->primary_address);
-    n->state = S_INIT_ATS;
-    n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-    // FIXME: need to ask ATS for suggestions again?
-    n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+    /* The session used to send the CONNECT terminated:
+     * this implies a connect error*/
+    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+                "Failed to send CONNECT in %s with `%s' %p: session terminated\n",
+                "CONNECT_SENT",
+                GST_plugins_a2s (n->primary_address.address),
+                n->primary_address.session,
+                GNUNET_i2s (peer));
+
+    /* Destroy the address since it cannot be used */
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL);
+    unset_primary_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_INIT_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
     break;
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
     /* error on inbound session; free neighbour entirely */
     free_address (&n->primary_address);
     free_neighbour (n, GNUNET_NO);
     return GNUNET_YES;
-  case S_CONNECTED:
-    free_address (&n->primary_address);
-    n->state = S_RECONNECT_ATS;
-    n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-    /* FIXME: is this ATS call needed? */
-    n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
+  case GNUNET_TRANSPORT_PS_CONNECTED:
+    /* Our primary connection died, try a fast reconnect */
+    unset_primary_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
     break;
-  case S_RECONNECT_ATS:
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
     /* we don't have an address, how can it go down? */
     GNUNET_break (0);
     break;
-  case S_RECONNECT_BLACKLIST:
-  case S_RECONNECT_SENT:
-    n->state = S_RECONNECT_ATS;
-    n->timeout = GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT);
-    // FIXME: need to ask ATS for suggestions again?
-    n->suggest_handle = GNUNET_ATS_suggest_address (GST_ats, &n->id);
-    break;
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-    /* primary went down while we were checking secondary against
-       blacklist, adopt secondary as primary */
-    free_address (&n->primary_address);
-    n->primary_address = n->alternative_address;
-    memset (&n->alternative_address, 0, sizeof (struct NeighbourAddress));
-    n->timeout = GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT);
-    n->state = S_RECONNECT_BLACKLIST;
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+    GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+                "Failed to send CONNECT in %s with `%s' %p: session terminated\n",
+                "RECONNECT_SENT",
+                GST_plugins_a2s (n->primary_address.address),
+                n->primary_address.session,
+                GNUNET_i2s (peer));
+
+    /* Destroy the address since it cannot be used */
+    GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL);
+    unset_primary_address (n);
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_ATS,
+        GNUNET_TIME_relative_to_absolute (ATS_RESPONSE_TIMEOUT));
     break;
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
     /* primary went down while we were waiting for CONNECT_ACK on secondary;
        secondary as primary */
+
+    /* Destroy the inbound address since it cannot be used */
+    if (GNUNET_YES
+        == GNUNET_HELLO_address_check_option (n->primary_address.address,
+            GNUNET_HELLO_ADDRESS_INFO_INBOUND))
+      GNUNET_ATS_address_destroyed (GST_ats, n->primary_address.address, NULL);
     free_address (&n->primary_address);
     n->primary_address = n->alternative_address;
     memset (&n->alternative_address, 0, sizeof (struct NeighbourAddress));
-    n->timeout = GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT);
-    n->state = S_RECONNECT_SENT;
+    set_state_and_timeout (n, GNUNET_TRANSPORT_PS_RECONNECT_ATS,
+        GNUNET_TIME_relative_to_absolute (FAST_RECONNECT_TIMEOUT));
     break;
-  case S_DISCONNECT:
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
     free_address (&n->primary_address);
     break;
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     /* neighbour was freed and plugins told to terminate session */
     return GNUNET_NO;
     break;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
     break;
   }
@@ -3037,8 +3376,9 @@ GST_neighbours_session_terminated (const struct GNUNET_PeerIdentity *peer,
  * @param address address of the other peer, NULL if other peer
  *                       connected to us
  * @param session session to use (or NULL)
+ * @return #GNUNET_OK if the message was fine, #GNUNET_SYSERR on serious error
  */
-void
+int
 GST_neighbours_handle_session_ack (const struct GNUNET_MessageHeader *message,
                                   const struct GNUNET_PeerIdentity *peer,
                                   const struct GNUNET_HELLO_Address *address,
@@ -3052,38 +3392,89 @@ GST_neighbours_handle_session_ack (const struct GNUNET_MessageHeader *message,
   if (ntohs (message->size) != sizeof (struct GNUNET_MessageHeader))
   {
     GNUNET_break_op (0);
-    return;
+    return GNUNET_SYSERR;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# SESSION_ACK messages received"),
+                            1, GNUNET_NO);
   if (NULL == (n = lookup_neighbour (peer)))
-    return;
-  /* check if we are in a plausible state for having sent
-     a CONNECT_ACK.  If not, return, otherwise break */
-  if ( ( (S_CONNECT_RECV_ACK != n->state) &&
-        (S_CONNECT_SENT != n->state) ) ||
-       (2 != n->send_connect_ack) )
   {
+    GNUNET_break_op (0);
+    return GNUNET_SYSERR;
+  }
+
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Received %s for peer `%s' in state %s/%s\n",
+              "SESSION_ACK",
+              GNUNET_i2s (peer),
+              GNUNET_TRANSPORT_ps2s (n->state),
+              print_ack_state (n->ack_state));
+
+  /* Check if we are in a plausible state for having sent
+     a CONNECT_ACK.  If not, return, otherwise break.
+
+     The remote peers sends a SESSION_ACK as a response for a CONNECT_ACK
+     message.
+
+     We expect a SESSION_ACK:
+     - If a remote peer has sent a CONNECT, we responded with a CONNECT_ACK and
+     now wait for the ACK to finally be connected
+     - If we sent a CONNECT_ACK to this peer before */
+
+  if (   (GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK != n->state) &&
+         (ACK_SEND_SESSION_ACK != n->ack_state))
+  {
+    GNUNET_log (GNUNET_ERROR_TYPE_WARNING,
+                "Received unexpected SESSION_ACK message from peer `%s' in state %s/%s\n",
+                GNUNET_i2s (peer),
+                GNUNET_TRANSPORT_ps2s (n->state),
+                print_ack_state (n->ack_state));
+
     GNUNET_STATISTICS_update (GST_stats,
-                              gettext_noop ("# unexpected SESSION ACK messages"), 1,
+                              gettext_noop ("# unexpected SESSION_ACK messages"), 1,
                               GNUNET_NO);
-    return;
+    return GNUNET_OK;
   }
-  n->state = S_CONNECTED;
-  n->timeout = GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT);
-  GNUNET_STATISTICS_set (GST_stats,
-                        gettext_noop ("# peers connected"),
-                        ++neighbours_connected,
-                        GNUNET_NO);
-  connect_notify_cb (callback_cls, &n->id,
+
+  /* We are connected */
+  if (GNUNET_NO == GST_neighbours_test_connected(&n->id))
+  {
+    /* Notify about connection */
+    connect_notify_cb (callback_cls, &n->id,
                      n->primary_address.bandwidth_in,
-                     n->primary_address.bandwidth_out);
+                     n->primary_address.bandwidth_out);\
+
+     GNUNET_STATISTICS_set (GST_stats,
+                            gettext_noop ("# peers connected"),
+                            ++neighbours_connected,
+                            GNUNET_NO);
+  }
+
+  if (GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT == n->state)
+  {
+    /* We tried to switch addresses while being connect. We explicitly wait
+     * for a CONNECT_ACK before going to GNUNET_TRANSPORT_PS_CONNECTED,
+     * so we do not want to set the address as in use! */
+    return GNUNET_OK;
+  }
+
+  set_state_and_timeout (n, GNUNET_TRANSPORT_PS_CONNECTED,
+    GNUNET_TIME_relative_to_absolute (GNUNET_CONSTANTS_IDLE_CONNECTION_TIMEOUT));
 
-  GST_ats_add_address (n->primary_address.address, n->primary_address.session);
-  set_address (&n->primary_address,
+  /* Add session to ATS since no session was given (NULL) and we may have
+   * obtained a new session */
+  GST_ats_add_address (n->primary_address.address, n->primary_address.session,
+      NULL, 0);
+
+  /* Set primary address to used */
+  set_primary_address (n,
               n->primary_address.address,
               n->primary_address.session,
               n->primary_address.bandwidth_in,
               n->primary_address.bandwidth_out,
               GNUNET_YES);
+  return GNUNET_OK;
 }
 
 
@@ -3099,7 +3490,6 @@ GST_neighbours_test_connected (const struct GNUNET_PeerIdentity *target)
   return test_connected (lookup_neighbour (target));
 }
 
-
 /**
  * Change the incoming quota for the given peer.
  *
@@ -3126,8 +3516,9 @@ GST_neighbours_set_incoming_quota (const struct GNUNET_PeerIdentity *neighbour,
   GNUNET_BANDWIDTH_tracker_update_quota (&n->in_tracker, quota);
   if (0 != ntohl (quota.value__))
     return;
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG, "Disconnecting peer `%4s' due to `%s'\n",
-              GNUNET_i2s (&n->id), "SET_QUOTA");
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Disconnecting peer `%4s' due to SET_QUOTA\n",
+              GNUNET_i2s (&n->id));
   if (GNUNET_YES == test_connected (n))
     GNUNET_STATISTICS_update (GST_stats,
                               gettext_noop ("# disconnects due to quota of 0"),
@@ -3135,6 +3526,18 @@ GST_neighbours_set_incoming_quota (const struct GNUNET_PeerIdentity *neighbour,
   disconnect_neighbour (n);
 }
 
+void delayed_disconnect (void *cls,
+    const struct GNUNET_SCHEDULER_TaskContext* tc)
+{
+  struct NeighbourMapEntry *n = cls;
+
+  n->delayed_disconnect_task = GNUNET_SCHEDULER_NO_TASK;
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Disconnecting by request from peer %s\n",
+              GNUNET_i2s (&n->id));
+  free_neighbour (n, GNUNET_NO);
+}
+
 
 /**
  * We received a disconnect message from the given peer,
@@ -3144,26 +3547,28 @@ GST_neighbours_set_incoming_quota (const struct GNUNET_PeerIdentity *neighbour,
  * @param msg the disconnect message
  */
 void
-GST_neighbours_handle_disconnect_message (const struct GNUNET_PeerIdentity
-                                          *peer,
-                                          const struct GNUNET_MessageHeader
-                                          *msg)
+GST_neighbours_handle_disconnect_message (const struct GNUNET_PeerIdentity *peer,
+                                          const struct GNUNET_MessageHeader *msg)
 {
   struct NeighbourMapEntry *n;
   const struct SessionDisconnectMessage *sdm;
 
-  GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
               "Received DISCONNECT message from peer `%s'\n",
               GNUNET_i2s (peer));
   if (ntohs (msg->size) != sizeof (struct SessionDisconnectMessage))
   {
-    // GNUNET_break_op (0);
+    GNUNET_break_op (0);
     GNUNET_STATISTICS_update (GST_stats,
                               gettext_noop
-                              ("# disconnect messages ignored (old format)"), 1,
+                              ("# disconnect messages ignored (malformed)"), 1,
                               GNUNET_NO);
     return;
   }
+  GNUNET_STATISTICS_update (GST_stats,
+                            gettext_noop
+                            ("# DISCONNECT messages received"),
+                            1, GNUNET_NO);
   sdm = (const struct SessionDisconnectMessage *) msg;
   if (NULL == (n = lookup_neighbour (peer)))
     return;                     /* gone already */
@@ -3204,12 +3609,7 @@ GST_neighbours_handle_disconnect_message (const struct GNUNET_PeerIdentity
     GNUNET_break_op (0);
     return;
   }
-  if (GNUNET_YES == test_connected (n))
-    GNUNET_STATISTICS_update (GST_stats,
-                             gettext_noop
-                             ("# other peer asked to disconnect from us"), 1,
-                             GNUNET_NO);
-  disconnect_neighbour (n);
+  n->delayed_disconnect_task = GNUNET_SCHEDULER_add_now (&delayed_disconnect, n);
 }
 
 
@@ -3231,7 +3631,7 @@ struct IteratorContext
 
 
 /**
- * Call the callback from the closure for each connected neighbour.
+ * Call the callback from the closure for each neighbour.
  *
  * @param cls the `struct IteratorContext`
  * @param key the hash of the public key of the neighbour
@@ -3248,8 +3648,6 @@ neighbours_iterate (void *cls,
   struct GNUNET_BANDWIDTH_Value32NBO bandwidth_in;
   struct GNUNET_BANDWIDTH_Value32NBO bandwidth_out;
 
-  if (GNUNET_YES != test_connected (n))
-    return GNUNET_OK;
 
   if (NULL != n->primary_address.address)
   {
@@ -3261,8 +3659,11 @@ neighbours_iterate (void *cls,
     bandwidth_in = GNUNET_CONSTANTS_DEFAULT_BW_IN_OUT;
     bandwidth_out = GNUNET_CONSTANTS_DEFAULT_BW_IN_OUT;
   }
-  ic->cb (ic->cb_cls, &n->id,
+  ic->cb (ic->cb_cls,
+          &n->id,
           n->primary_address.address,
+          n->state,
+          n->timeout,
           bandwidth_in, bandwidth_out);
   return GNUNET_OK;
 }
@@ -3304,6 +3705,9 @@ GST_neighbours_force_disconnect (const struct GNUNET_PeerIdentity *target)
                              gettext_noop
                              ("# disconnected from peer upon explicit request"), 1,
                              GNUNET_NO);
+  GNUNET_log (GNUNET_ERROR_TYPE_INFO,
+              "Forced disconnect from peer %s\n",
+              GNUNET_i2s (target));
   disconnect_neighbour (n);
 }
 
@@ -3325,28 +3729,23 @@ GST_neighbour_get_latency (const struct GNUNET_PeerIdentity *peer)
     return GNUNET_TIME_UNIT_FOREVER_REL;
   switch (n->state)
   {
-  case S_CONNECTED:
-  case S_CONNECTED_SWITCHING_CONNECT_SENT:
-  case S_CONNECTED_SWITCHING_BLACKLIST:
-  case S_RECONNECT_SENT:
-  case S_RECONNECT_ATS:
-  case S_RECONNECT_BLACKLIST:
+  case GNUNET_TRANSPORT_PS_CONNECTED:
+  case GNUNET_TRANSPORT_PS_CONNECTED_SWITCHING_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_RECONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_RECONNECT_ATS:
     return n->latency;
-  case S_NOT_CONNECTED:
-  case S_INIT_BLACKLIST:
-  case S_INIT_ATS:
-  case S_CONNECT_RECV_BLACKLIST_INBOUND:
-  case S_CONNECT_RECV_ATS:
-  case S_CONNECT_RECV_BLACKLIST:
-  case S_CONNECT_RECV_ACK:
-  case S_CONNECT_SENT:
-  case S_DISCONNECT:
-  case S_DISCONNECT_FINISHED:
+  case GNUNET_TRANSPORT_PS_NOT_CONNECTED:
+  case GNUNET_TRANSPORT_PS_INIT_ATS:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ATS:
+  case GNUNET_TRANSPORT_PS_CONNECT_RECV_ACK:
+  case GNUNET_TRANSPORT_PS_CONNECT_SENT:
+  case GNUNET_TRANSPORT_PS_DISCONNECT:
+  case GNUNET_TRANSPORT_PS_DISCONNECT_FINISHED:
     return GNUNET_TIME_UNIT_FOREVER_REL;
   default:
     GNUNET_log (GNUNET_ERROR_TYPE_ERROR,
                 "Unhandled state `%s'\n",
-                print_state (n->state));
+                GNUNET_TRANSPORT_ps2s (n->state));
     GNUNET_break (0);
     break;
   }
@@ -3386,14 +3785,15 @@ void
 GST_neighbours_start (void *cls,
                       NotifyConnect connect_cb,
                       GNUNET_TRANSPORT_NotifyDisconnect disconnect_cb,
-                      GNUNET_TRANSPORT_PeerIterateCallback peer_address_cb,
+                      GNUNET_TRANSPORT_NeighbourChangeCallback peer_address_cb,
                       unsigned int max_fds)
 {
   callback_cls = cls;
   connect_notify_cb = connect_cb;
   disconnect_notify_cb = disconnect_cb;
-  address_change_cb = peer_address_cb;
+  neighbour_change_cb = peer_address_cb;
   neighbours = GNUNET_CONTAINER_multipeermap_create (NEIGHBOUR_TABLE_SIZE, GNUNET_NO);
+  registered_quota_notifications = GNUNET_CONTAINER_multipeermap_create (NEIGHBOUR_TABLE_SIZE, GNUNET_NO);
   util_transmission_tk = GNUNET_SCHEDULER_add_delayed (UTIL_TRANSMISSION_INTERVAL,
       utilization_transmission, NULL);
 }
@@ -3417,7 +3817,6 @@ disconnect_all_neighbours (void *cls,
   GNUNET_log (GNUNET_ERROR_TYPE_DEBUG,
              "Disconnecting peer `%4s', %s\n",
               GNUNET_i2s (&n->id), "SHUTDOWN_TASK");
-  n->state = S_DISCONNECT_FINISHED;
   free_neighbour (n, GNUNET_NO);
   return GNUNET_OK;
 }
@@ -3429,6 +3828,9 @@ disconnect_all_neighbours (void *cls,
 void
 GST_neighbours_stop ()
 {
+  struct BlacklistCheckSwitchContext *cur;
+  struct BlacklistCheckSwitchContext *next;
+
   if (NULL == neighbours)
     return;
   if (GNUNET_SCHEDULER_NO_TASK != util_transmission_tk)
@@ -3437,15 +3839,37 @@ GST_neighbours_stop ()
     util_transmission_tk = GNUNET_SCHEDULER_NO_TASK;
   }
 
-  GNUNET_CONTAINER_multipeermap_iterate (neighbours,
-                                        &disconnect_all_neighbours,
-                                         NULL);
+  GNUNET_CONTAINER_multipeermap_iterate (neighbours, &disconnect_all_neighbours,
+      NULL );
   GNUNET_CONTAINER_multipeermap_destroy (neighbours);
+
+  next = pending_bc_head;
+  for (cur = next; NULL != cur; cur = next )
+  {
+    next = cur->next;
+    GNUNET_CONTAINER_DLL_remove (pending_bc_head, pending_bc_tail, cur);
+
+    if (NULL != cur->blc)
+    {
+      GST_blacklist_test_cancel (cur->blc);
+      cur->blc = NULL;
+    }
+    if (NULL != cur->address)
+      GNUNET_HELLO_address_free (cur->address);
+    GNUNET_free_non_null (cur->ats);
+    GNUNET_free (cur);
+  }
+
+  GNUNET_CONTAINER_multipeermap_iterate (registered_quota_notifications,
+      &free_notification_cb, NULL);
+  GNUNET_CONTAINER_multipeermap_destroy (registered_quota_notifications);
+  registered_quota_notifications = NULL;
+
   neighbours = NULL;
   callback_cls = NULL;
   connect_notify_cb = NULL;
   disconnect_notify_cb = NULL;
-  address_change_cb = NULL;
+  neighbour_change_cb = NULL;
 }