Re: Statefull VPN failover a fork from Re: iptables vs pf

2005-10-21 Thread Brian A. Seklecki
More to the point, how to find this info. 1: Go to http://www.openbsd.org/cgi-bin/man.cgi 2: click apropos 3: make sure current is selected 4: query sync 5: click on sasynchd(8) and sasychd.conf(5)

Re: Statefull VPN failover a fork from Re: iptables vs pf

2005-10-21 Thread Theo de Raadt
Please note that at this time, sasyncd can fail IPSEC associations to a 2nd machine But not yet fail them back, when the master recovers The developer of this stuff hasn't finished it yet.

Statefull VPN failover a fork from Re: iptables vs pf

2005-10-20 Thread dagrichards
I have been moving a single Linux FW to a pair of OBSD machines, lured by carp and pfsync. This has been working well in my test environment. This also lead me to vpns running with ISAKMPD, replaceing a Freeswan box, and forestalling purchasing proprietary products for site to site partner

Re: Statefull VPN failover a fork from Re: iptables vs pf

2005-10-20 Thread Spruell, Darren-Perot
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] I have been moving a single Linux FW to a pair of OBSD machines, lured by carp and pfsync. This has been working well in my test environment. This also lead me to vpns running with ISAKMPD, replaceing a Freeswan box, and forestalling