[strongSwan] fails to retry after DNS failure
noel.kuntze+strongswan-users-ml at thermi.consulting
Mon May 8 10:23:35 CEST 2017
That's not a bug, that's intentional behaviour.
Charon stops trying to initiate or negotiate when a permanent error
is encountered that it can not handle by itself. Use auto=route, if you
need to make sure CHILD_SAs are reinitiated when they're down,
but needed. There's no option to force retrying in any case.
Closeaction only applies to CHILD_SAs getting closed and dpdaction only to dpd timeouts.
So obviously neither applies.
On 08.05.2017 10:07, Daniel Pocock wrote:
> I've got some of the following in a branch-office configuration on OpenWRT:
> StrongSWAN version 5.3.3
> conn mainoffice
> With this configuration (dpdaction, closeaction, keyingtries) I would
> expect the branch office to make every effort to reconnect and keep
> trying forever.
> I've observed that if the ISP link goes down (e.g. removing the fibre),
> if the ISP link is not ready when StrongSWAN starts up (e.g. after a
> router reboot) or if the VPN server is restart then the branch office
> fails to reconnect.
> Looking at the logs (logread on OpenWRT) I notice an error about DNS
> failure for "vpn.example.org" and then it would give up.
> I changed the line "right=vpn.example.org" to "right=A.B.C.D" and the
> problem went away. Now it really keeps retrying.
> I'd like to open a bug report for this but I couldn't log in to the bug
> Users mailing list
> Users at lists.strongswan.org
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: OpenPGP digital signature
More information about the Users