Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» CARP/VIPs» CARP - IPSEC - failover - listen (500) in racoon.conf
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: CARP - IPSEC - failover - listen (500) in racoon.conf  (Read 2059 times)
0 Members and 1 Guest are viewing this topic.
heiko
Hero Member
*****
Offline Offline

Posts: 663


Get a load of that!


View Profile
« on: March 02, 2007, 02:24:20 pm »

Hello,

now i set with an established carp cluster and ipsec syncronize enabled, the tab on ipsec failover to my carp wan ip. In the /var/etc/racoon.conf  at the top of the file it shows listen (isakmp "wan-carp" (500)); and i think it´s fine.

I delete the wan carp ip and now it shows (isakmp "blank" (500); and i think, it is not OK, because all tunnels are down and not comes up....., also when i deleted the special config of the cluster.

In the webgui the system logs shows on the tab "ipsecvpn" :

racoon: ERROR: /var/etc/racoon.conf:2: "500" parse error

This ist in the v.1.01 and also in the newest releng_snapshot version shown.

Is it by design? or a litte bug?
My Test-Tunnels comes not up..

Very special greetings from Germany
Heiko
Logged
sullrich
Hero Member
*****
Offline Offline

Posts: 5135



View Profile WWW
« Reply #1 on: March 02, 2007, 02:26:31 pm »

This has been fixed in a recent snapshot.  Please upgrade.
Logged
heiko
Hero Member
*****
Offline Offline

Posts: 663


Get a load of that!


View Profile
« Reply #2 on: March 02, 2007, 03:03:47 pm »

I have upgraded to the snapshot from 27.02., but it is also the same behaviour,

??
Heiko
Logged
heiko
Hero Member
*****
Offline Offline

Posts: 663


Get a load of that!


View Profile
« Reply #3 on: March 03, 2007, 09:10:58 am »

Hello,
with the build from 3. march, the failover adress is setting correctly when it is deleted.

NOW, the failover IP ist not syncing to the backup carp member. Hm, the Ipsec tunnels syncing correctly.

Greetings from Germany
Heiko

« Last Edit: March 03, 2007, 09:13:48 am by heiko » Logged
sullrich
Hero Member
*****
Offline Offline

Posts: 5135



View Profile WWW
« Reply #4 on: March 03, 2007, 03:00:54 pm »

I dont think we sync that value.  You will have to input the value on each cluster member.
Logged
heiko
Hero Member
*****
Offline Offline

Posts: 663


Get a load of that!


View Profile
« Reply #5 on: March 03, 2007, 03:23:24 pm »

Hi,

OK, I understand, is it possible to sync this automatically? The manual setting is easily to forget.
It would be a great help for my projects in Moskau, St. Petersburg and Switzerland.

Bye, Heiko

Logged
sullrich
Hero Member
*****
Offline Offline

Posts: 5135



View Profile WWW
« Reply #6 on: March 04, 2007, 01:32:35 pm »

Hi,

OK, I understand, is it possible to sync this automatically? The manual setting is easily to forget.
It would be a great help for my projects in Moskau, St. Petersburg and Switzerland.

Bye, Heiko



Not at the moment, no.
Logged
heiko
Hero Member
*****
Offline Offline

Posts: 663


Get a load of that!


View Profile
« Reply #7 on: March 04, 2007, 04:57:29 pm »

Hello Scott,

maybe later. It doesn't greatly matter.

Greetings from Germany and special thanks for your help.

Heiko
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.025 seconds with 19 queries.