login
Header Space

 
 

Re: Redundant Firewalls, CARP + IPSEC + SASYNCD

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Dag Richards <dagrichards@...>
Cc: <misc@...>
Date: Thursday, May 3, 2007 - 2:07 pm

Ok that setup is similar to what I have and I do have carp interfaces on
both sides of the firewall. I was able to configure sasynd but when running
netstat -rnf encap was not able to see any of the flows on the slave
machine, but then I realized or thought that it was because the ISAKMPD
session was not established on the slave machine.

If your trying to establish the ISAKMPD session from the slave box which
does not have control of the active carp interface, how is the ISAKMPD/IPSEC
connection established? Doesn't it need to be established for sasynd to know
about the SA's? or upon failover does the session then get established on
the fly? Do you use isakmpd.conf or ipsec.conf to control your flows?

Thanks.

On 5/2/07, Dag Richards <dagrichards@speakeasy.net> wrote:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Redundant Firewalls, CARP + IPSEC + SASYNCD, Dag Richards, (Thu May 3, 1:42 am)
Re: Redundant Firewalls, CARP + IPSEC + SASYNCD, , (Thu May 3, 2:07 pm)
Re: Redundant Firewalls, CARP + IPSEC + SASYNCD, Dag Richards, (Thu May 3, 2:42 pm)
speck-geostationary