Re: State of IPsec, iked (OpenIKED) and redundancy (CARP)

2016-10-06 Thread Daniel Polak
Hello Jasper, I wanted to use iked in a redundant configuration too and wasn't sure whether iked and sasyncd play nice together. I contacted Reyk Floeter (the main developer of iked) and it turns out there is room for improvement. We use OpenBSD for the Muniam managed firewalls and need redun

State of IPsec, iked (OpenIKED) and redundancy (CARP)

2016-09-28 Thread Jasper Siepkes
Hi everyone @ misc! I'm trying to determine what the state is of using iked (OpenIKED) with redundancy (with CARP). Should such a setup work in OpenBSD 6.0? The iked.conf (5) man page implies that using CARP for redundancy is a supported configuration: "This option is used for setups using sasy