[Openswan Users] One Hour Disconnect?

Paul Wouters paul at xelerance.com
Thu Dec 15 22:08:26 CET 2005


On Thu, 15 Dec 2005, Peter McGill wrote:

> The connection is established, and works for about one
> hour. The logs seem to indicate that the ISAKMP SA
> is renegotiated at about 45 minutes in. I have tested
> the connection after this and it is still working, but at
> about one hour we receive a Delete SA from the
> Nortel box and the connection goes down without
> reconnecting. At this point I have to manually force
> reconnection via: ipsec auto --up or --route.

> conn sunoco-172-16-19-net-to-london-office-net
> left=66.11.74.93
> leftnexthop=%defaultroute
> leftsubnet=172.21.0.0/16
> alsoflip=sunoco-toronto
> rightsubnet=172.16.0.0/14
> auto=route

use auto=start, not auto=reoute

Paul


More information about the Users mailing list