I've ended up with a combination of a leftupdown script which is
modified to not unconfigure the interface, plus a cron job which checks
the output of birdc show protocols all and runs ipsec auto --down
[tunnelname] then waits ten seconds and runs ipsec auto --up
[tunnelname] if bird reports a failure, which finally seems to be an
adequate workaround for achieving a reasonable approximation the desired
stability.

That cron job is relatively recent, and I have not done testing to
determine whether the cron job makes the modified leftupdown script
obsolete.

An earlier version of the cron job relied on looking at the output of
ipsec status to determine whether a tunnel was working, and in some
cases that led to the script not restarting a tunnel that needed to be
restarted.

The startup at boot order problem mentioned in this bug report has not
occurred recently.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1751379

Title:
  libreswan unconfigures vti interfaces in temporary network outage

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libreswan/+bug/1751379/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to