[Openswan Users] recommended settings for a permanently up connection
joshihirenn at gmail.com
Tue Feb 19 01:55:32 EST 2008
I want a net-to-net connection to be permanent.
It should come up across link failures, ipsec service restarts, machine
As per 'man ipsec.conf' i tried following parameters:
plutowait=yes (because sometimes some of my tunnels doesn't get
established due to - "*can not start crypto helper: failed to find any
I tested this parameters using VMWare setup. But to my surprise it doesn't
My observation is -
after peer is declared dead (from both the sides),
1) sometimes gateway-2 tries to reestablish the connection by initiating
main mode repeatedly. gateway-1 also tries to do this but by initiating the
connection only <keyingtries> times. Eventually when peer becomes available,
connection is reestablished.
2) sometimes both tries to reestablish the connection only <keyingtries>
times. Connection is not reestablished when peer becomes available.
What could be the reason of this uneven behavior?
Thanks in advance.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Users