LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Director not sending icmp unreachable to expired clients

To: Julian Anastasov <ja@xxxxxx>
Subject: Re: Director not sending icmp unreachable to expired clients
Cc: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
From: Janusz Krzysztofik <jkrzyszt@xxxxxxxxxxxx>
Date: Tue, 13 Feb 2007 13:17:35 +0100
Julian Anastasov wrote:
        Hello,

Hi Julian,

        Any support for ISAKMP keep alives in your devices?

If you mean DPD (dead peer detect) - yes, it is supported (I use OpenSwan), but it does not work very well for me. In my case, several tunnels can use the same ISAKMP association, and only one of them is removed when the peer is assumed dead. Other tunnels stay on, ignoring ICMP port unreachable messages my patched director is sending, until they expire.

My current workaround is not using DPD, but setting a short rekey period (15 mins or less).

Cheers,
Janusz

<Prev in Thread] Current Thread [Next in Thread>