Stephen Marley wrote:
Is there a way to make a pair of carp hosts to renegotiate with an existing ipsec peer when a new carp master is elected? I tried it once and it didn't work out.
Hakan is working on sasync that synchronize IPSec SAs, but as of May 25th, it's not ready for public consumption just yet.
sk