Re: [strongSwan] ha plugin

2016-03-24 Thread Slava Bendersky
quot; To: "volga629" , "users" Sent: Thursday, 24 March, 2016 04:31:47 Subject: Re: [strongSwan] ha plugin Hi Slava, the Linux kernel still has to be patched whereas no change in iptables is required. A selection of ha kernel patches can be found here: https://download.strong

Re: [strongSwan] ha plugin

2016-03-24 Thread Andreas Steffen
Hi Slava, the Linux kernel still has to be patched whereas no change in iptables is required. A selection of ha kernel patches can be found here: https://download.strongswan.org/testing/ E.g. for a Linux 4.4 or 4.5 kernel apply ha-4.4-abicompat.patch.bz2 and for a Linux 4.2 or 4.3 kernel apply

[strongSwan] ha plugin

2016-03-23 Thread Slava Bendersky
Hello Everyone, I am trying build test case with HA plugin and lan2lan tunnel behind nat, but I want to confirm if patches posted on plugin wiki still required to rebuild kernel and iptables ? Slava. ___ Users mailing list Users@lists.strongswan.org

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-03-26 Thread Emeric POUPON
the DPD mechanism to detect the failure. What do you think? Regards, Emeric - Mail original - De: "Emeric POUPON" À: "Martin Willi" Cc: users@lists.strongswan.org Envoyé: Mardi 3 Mars 2015 17:36:13 Objet: Re: [strongSwan] HA plugin: stopping charon does not remove

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-03-03 Thread Emeric POUPON
efore cancelling threads, the job is being executed and it works as expected: the SA are being deleted on the passive node. Not sure it is the correct fix for that problem though? Best Regards, Emeric - Mail original - De: "Emeric POUPON" À: "Martin Willi" Cc: users@l

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-03-02 Thread Emeric POUPON
>> In that particular configuration (no monitoring/heartbeat) stopping >> charon on the active node should clear the connections on the remote >> gateway (OK) and on the other node (not OK), right? > >The active node will delete the IKE_SA, and send a close event to the >passive node. > That is wh

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-03-02 Thread Martin Willi
Hi, > In that particular configuration (no monitoring/heartbeat) stopping > charon on the active node should clear the connections on the remote > gateway (OK) and on the other node (not OK), right? The active node will delete the IKE_SA, and send a close event to the passive node. If you are no

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-02-27 Thread Emeric POUPON
artin Willi" À: "Emeric POUPON" Cc: users@lists.strongswan.org Envoyé: Vendredi 27 Février 2015 16:27:02 Objet: Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes > When charon is stopped on one of the nodes, DELETE are sent to the remote >

Re: [strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-02-27 Thread Martin Willi
> When charon is stopped on one of the nodes, DELETE are sent to the remote > hosts: Actually, it should not if it has an active heartbeat connection with the other node. If a node knows that another node is active, it should deactivate all responsible segments locally before shutting down, and

[strongSwan] HA plugin: stopping charon does not remove IKE_SA/CHILD_SA from other nodes

2015-02-27 Thread Emeric POUPON
Hello, I have set a HA cluster using strongswan 5.2.2. When charon is stopped on one of the nodes, DELETE are sent to the remote hosts: Feb 27 15:14:34 00[DMN] signal of type SIGINT received. Shutting down Feb 27 15:14:34 00[MGR] going to destroy IKE_SA manager and all managed IKE_SA's Feb 27 15