Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-08 Thread Kim Zeitler
On 11/08/17 08:37, Claudio Jeker wrote: On Tue, Nov 07, 2017 at 04:13:51PM +0100, Jeremie Courreges-Anglas wrote: On Tue, Nov 07 2017, Kim Zeitler wrote: On 11/07/17 15:31, Jeremie Courreges-Anglas wrote: On Tue, Nov 07 2017, Stuart Henderson wrote: I have a question concerning routes an

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Claudio Jeker
On Tue, Nov 07, 2017 at 04:13:51PM +0100, Jeremie Courreges-Anglas wrote: > On Tue, Nov 07 2017, Kim Zeitler wrote: > > On 11/07/17 15:31, Jeremie Courreges-Anglas wrote: > >> On Tue, Nov 07 2017, Stuart Henderson wrote: > > > > I have a question concerning routes and ospf. > We ar

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Claudio Jeker
On Tue, Nov 07, 2017 at 02:42:29PM +, Stuart Henderson wrote: > On 2017/11/07 15:31, Jeremie Courreges-Anglas wrote: > > On Tue, Nov 07 2017, Stuart Henderson wrote: > > > On 2017-11-07, Kim Zeitler wrote: > > >> This is a cryptographically signed message in MIME format. > > >> > > >> ---

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Kim Zeitler
On 11/07/17 16:13, Jeremie Courreges-Anglas wrote: On Tue, Nov 07 2017, Kim Zeitler wrote: On 11/07/17 15:31, Jeremie Courreges-Anglas wrote: On Tue, Nov 07 2017, Stuart Henderson wrote: I have a question concerning routes and ospf. We are using iked(8) with a gif(4) interface and ospfd(8

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Jeremie Courreges-Anglas
On Tue, Nov 07 2017, Kim Zeitler wrote: > On 11/07/17 15:31, Jeremie Courreges-Anglas wrote: >> On Tue, Nov 07 2017, Stuart Henderson wrote: > I have a question concerning routes and ospf. We are using iked(8) with a gif(4) interface and ospfd(8) to set up=20 routing. >>>

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Kim Zeitler
On 11/07/17 15:31, Jeremie Courreges-Anglas wrote: On Tue, Nov 07 2017, Stuart Henderson wrote: I have a question concerning routes and ospf. We are using iked(8) with a gif(4) interface and ospfd(8) to set up=20 routing. If the ipsec tunnel is down, no ospf route is set and the default rou

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Stuart Henderson
On 2017/11/07 15:31, Jeremie Courreges-Anglas wrote: > On Tue, Nov 07 2017, Stuart Henderson wrote: > > On 2017-11-07, Kim Zeitler wrote: > >> This is a cryptographically signed message in MIME format. > >> > >> --ms030007050806020307030407 > >> Content-Type: text/plain; charset=utf-8

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Jeremie Courreges-Anglas
On Tue, Nov 07 2017, Stuart Henderson wrote: > On 2017-11-07, Kim Zeitler wrote: >> This is a cryptographically signed message in MIME format. >> >> --ms030007050806020307030407 >> Content-Type: text/plain; charset=utf-8; format=flowed >> Content-Language: en-GB >> Content-Transfer-En

Re: iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Stuart Henderson
On 2017-11-07, Kim Zeitler wrote: > This is a cryptographically signed message in MIME format. > > --ms030007050806020307030407 > Content-Type: text/plain; charset=utf-8; format=flowed > Content-Language: en-GB > Content-Transfer-Encoding: quoted-printable > > Hello > > I have a questi

iked + gif + ospfd - use null-route to stop default route being used in case of no vpn

2017-11-07 Thread Kim Zeitler
Hello I have a question concerning routes and ospf. We are using iked(8) with a gif(4) interface and ospfd(8) to set up routing. If the ipsec tunnel is down, no ospf route is set and the default route used. Is it sensible and possible to add a null-route from the vpn-gateway to the remote-