[strongSwan] fails to retry after DNS failure
daniel at pocock.pro
Mon May 8 10:07:41 CEST 2017
I've got some of the following in a branch-office configuration on OpenWRT:
StrongSWAN version 5.3.3
With this configuration (dpdaction, closeaction, keyingtries) I would
expect the branch office to make every effort to reconnect and keep
I've observed that if the ISP link goes down (e.g. removing the fibre),
if the ISP link is not ready when StrongSWAN starts up (e.g. after a
router reboot) or if the VPN server is restart then the branch office
fails to reconnect.
Looking at the logs (logread on OpenWRT) I notice an error about DNS
failure for "vpn.example.org" and then it would give up.
I changed the line "right=vpn.example.org" to "right=A.B.C.D" and the
problem went away. Now it really keeps retrying.
I'd like to open a bug report for this but I couldn't log in to the bug
More information about the Users