Re: IPSEC,CARP,sasyncd -- IPSEC failover not working

2017-06-20 Thread Philipp Buehler
Am 20.06.2017 11:13 schrieb claudiu vasadi: Now some question: 1) On fw2, I omit the ipsecctl command and start only isakmpd and sasyncd. If I check the SA's and flows, they will be synced from fw1 but is this how it should be or do I need to have ipsec.conf on fw2 as well and issue the "ipse

IPSEC,CARP,sasyncd -- IPSEC failover not working

2017-06-20 Thread claudiu vasadi
Hello everyone, I'm in dire need of sasyncd help Here's the current setup I have: - 2x OpenBSD 6.1 amd64 redundant firewalls (em0 (ext_if), em1 (int_if), carp0 (carp_if over em0), carp1 (carp_if over em1)) - carp0 has 16 public IP's (ex: 1.1.1.1->1.1.1.16) - carp1 has 1x internal IP (ex: 10.10.10