[strongSwan] ipsec statusall not responding

Thomas Egerer hakke_007 at gmx.de
Tue May 13 16:31:05 CEST 2014


On 05/11/2014 07:27 AM, Nanda Gopal wrote:
> Hi,
> 
> I have a IPSec setup, which has 8 IKEv1 or 8 IKEv2  Protect Policies configured, tunnels established successfully with the Security gateway.
> An application program reads the   "ipsec statusall" output and based on the tunnel unavailability, will modify the ipsec.conf with a new right id and performs "ipsec update", resulting in a new tunnel getting established.
Hi,

I don't know if this helps, since if you are out of worker
threads, this will not work either, but since strongswan
4.5.3 you can call 'ipsec statusallnb' where nb stands for
non-blocking. It should be noted, that there is a chance
you may not see all SAs with this command.

Cheers, Thomas

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 551 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20140513/17b8d253/attachment.pgp>


More information about the Users mailing list