[strongSwan] Problem with 'auto=start' on unused SA

Martin Willi martin at strongswan.org
Thu Jul 31 09:42:07 CEST 2014


> As far as I understand, there is no way to keep a tunnel up and running
> forever?

A tunnel can fail for many reasons, and auto=start only takes care for
initiating the tunnel during startup.

For always-up tunnels, I usually recommend to use auto=route. This makes
sure no matching traffic leaves unencrypted, and the kernel will trigger
a new SA should an existing one fail for whatever reason.

Regards
Martin



More information about the Users mailing list