Nicole Hähnel nicole.haehnel at gmx.net
Fri Feb 15 03:31:47 EST 2008


we're using openswan 2.4.11 on SLES10SP1 kernel 
and netkey.
In the near future we have to connect about 40 sites,
so I have to monitor round about 40 tunnels on every gateway.
I tried to write a nagios check plugin to be sure that all tunnels are up.

I use this command from init script:
ipsec auto --status 2> /dev/null | grep -i "ipsec sa established" | wc 
-l | sed s/\ //g

But often I get more tunnels up than I have configured.
Any reasons for this behavior?

Is there another command to check how many tunnels are up?



