On Wed, 2011-06-29 at 21:19 +0200, Laurent Caron (Phone) wrote:

> 
> So it might be an openswan bug when dealing with multiple default
> routes?

It very much looks like you are using different OpenSwan configurations
as well as different Shorewall configurations. Are you restarting
OpenSWan as well as Shorewall?

A couple of things that I notice:

a) You are running kernel 2.6.39 which is very bleeding edge.
b) The output of 'ip route ls' looks like none I've ever seen before; 
   it is unsorted. In my experience, it has always been sorted from
   most specific to most general which puts default routes at the end of
   the listing.

I know of at least one Shorewall user who uses OpenSwan extensively with
multiple default routes; he has reported no issues such as yours.

-Tom
-- 
Tom Eastep        \ When I die, I want to go like my Grandfather who
Shoreline,         \ died peacefully in his sleep. Not screaming like
Washington, USA     \ all of the passengers in his car
http://shorewall.net \________________________________________________

Attachment: signature.asc
Description: This is a digitally signed message part

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to