[Openswan Users] Ipsec auto --up {tunnelname} hangs

Greg Scott GregScott at InfraSupportEtc.com
Wed Jun 18 21:42:38 EDT 2008


> Are you using DNS names in your conn description, while
> with the MPLS down your DNS is unreachable?

No.  Everything is real IP Addresses.  

The problem only seems to happen when the primary MPLS route drops for a
second or two and then comes back.  When I tested all this, I disabled
the MPLS router by hand, watched the failover, and then put the MPLS
router back online and watched the failback.  Everything worked, but in
my test case, the MPLS router was offline for a couple of minutes.

> You should run with plutodebug= and see why it is hanging instead.

I will post results here - where would I look for the debug info it will
leave?  This may take a while because that system is in production and
running several other always-up tunnels.  

Let me see if I can reproduce the problem here at my place in a test
environment.  Hmmm - I was just trying to think about how I would set up
the required routers and the thought hit me, maybe I can rig up
something virtual...  Give me a couple days to see what I can come up
with.  

- Greg


More information about the Users mailing list