On Wed, 2011-06-29 at 16:38 +0200, Laurent CARON wrote:
> On 29/06/2011 16:05, Tom Eastep wrote:
> > Have you ensured that the VPN continues to use the original interface?
> > It must because the tunnel end-point IP addresses are referenced in the
> > SPDs on both systems.
> 
> 
> Whenever I restart shorewall (while VPN is running) to add second ISP, I 
> continue to receive ESP from the remote side, but local openswan stops 
> sending to the remote peer.

The two dumps have totally different IPSEC configurations.

In the 1-ISP dump, IPSEC is configured to tunnel 192.168.17.0/24 <=>
192.168.0.0/24 using a tunnel between 213.215.28.11 and 213.215.22.162.

In the 2-ISP dump, IPSEC is configured to use *transport mode* and in
one direction only - from 192.168.17.0/24 => 192.168.0.0/24.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: This is a digitally signed message part

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to