[strongSwan] Problem with 'auto=start' on unused SA
Martin Willi
martin at strongswan.org
Thu Jul 31 09:42:07 CEST 2014
> As far as I understand, there is no way to keep a tunnel up and running
> forever?
A tunnel can fail for many reasons, and auto=start only takes care for
initiating the tunnel during startup.
For always-up tunnels, I usually recommend to use auto=route. This makes
sure no matching traffic leaves unencrypted, and the kernel will trigger
a new SA should an existing one fail for whatever reason.
Regards
Martin
More information about the Users
mailing list