[strongSwan] Tunnel gets disconnected

Tobias Brunner tobias at strongswan.org
Thu Jul 14 10:08:15 CEST 2016

Hi Matthias,

> I've peers where some (all, 2 of 8, etc.) tunnels get disconnected after
> some time.

How?  Is there a delete sent?  If so, by whom?

> Is there a way to configure StrongSwan to keep all tunnel up all the
> time without DPD?

auto=route is definitely the best way to ensure the tunnel is created
(or recreated) automatically and no plaintext traffic leaves the host.

> Why does StrongSwan shut down tunnels?

Why do you think strongSwan does so?  Did you check the logs for what's
actually going on?


