On Wed, 2011-06-29 at 16:38 +0200, Laurent CARON wrote: > On 29/06/2011 16:05, Tom Eastep wrote: > > Have you ensured that the VPN continues to use the original interface? > > It must because the tunnel end-point IP addresses are referenced in the > > SPDs on both systems. > > > Whenever I restart shorewall (while VPN is running) to add second ISP, I > continue to receive ESP from the remote side, but local openswan stops > sending to the remote peer.
The two dumps have totally different IPSEC configurations. In the 1-ISP dump, IPSEC is configured to tunnel 192.168.17.0/24 <=> 192.168.0.0/24 using a tunnel between 213.215.28.11 and 213.215.22.162. In the 2-ISP dump, IPSEC is configured to use *transport mode* and in one direction only - from 192.168.17.0/24 => 192.168.0.0/24. -Tom -- Tom Eastep \ When I die, I want to go like my Grandfather who Shoreline, \ died peacefully in his sleep. Not screaming like Washington, USA \ all of the passengers in his car http://shorewall.net \________________________________________________
signature.asc
Description: This is a digitally signed message part
------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
