Re: Interface/IP limit on isakmpd, no listen-on in ipsec.conf, IPSec failover enhancement, IPSec tunnel rebuild enhancement

2014-02-17 Thread Andy
Hi, Does anyone have any ideas on this? How can we configure isakmpd to only listen on certain IP addresses to avoid this limitation when it tries to listen on *every* IP address? I see listen-on in isakmpd.conf, but we are using ipsec.conf and I understand these are mutually-exclusive..

Re: Interface/IP limit on isakmpd, no listen-on in ipsec.conf, IPSec failover enhancement, IPSec tunnel rebuild enhancement

2014-02-17 Thread Andy
Face-palm!!! When I tried it before I only created /etc/isakmpd.conf not; /etc/isakmpd/isakmpd.conf chmod 600 /etc/isakmpd/isakmpd.conf isakmpd.conf [general] listen-on=pubip1,pubip2,pubip3 Dohh, Have to miss the obvious in a man page every now and then I guess.. Hopefully my fail-over

Re: Interface/IP limit on isakmpd, no listen-on in ipsec.conf, IPSec failover enhancement, IPSec tunnel rebuild enhancement

2014-02-15 Thread Sebastian Benoit
andy(a...@brandwatch.com) on 2014.02.12 12:22:57 +: Hi, I think this is a fairly simple one. Our firewalls are growing in complexity and the number of interfaces and IPs as time goes on, and we recently hit an isakmpd limit. When isakmpd starts it tries to bind to *every* single IP

Interface/IP limit on isakmpd, no listen-on in ipsec.conf, IPSec failover enhancement, IPSec tunnel rebuild enhancement

2014-02-12 Thread andy
Hi, I think this is a fairly simple one. Our firewalls are growing in complexity and the number of interfaces and IPs as time goes on, and we recently hit an isakmpd limit. When isakmpd starts it tries to bind to *every* single IP on the system. We have a LOT of IPs and isakmpd now fails to