Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Automated recovery of Tunnels

    Scheduled Pinned Locked Moved IPsec
    6 Posts 3 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      azmtnbike
      last edited by

      I am sure I missed this somewhere, but I have had a couple of instances where I lost power and the router recovered well.  However, I had to manually go in and reestablish the tunnels.  Can this be automated?

      Jon

      1 Reply Last reply Reply Quote 0
      • R
        rpsmith
        last edited by

        2.0 is much better about re-establishing an IPsec tunnel.  also, OpenVPN site-to-site seems to be bullet proof in just about every way.

        Roy…

        1 Reply Last reply Reply Quote 0
        • A
          azmtnbike
          last edited by

          I am on 2.0, now the newest RC candidate.  After a WAN failure I have to manually re-establish each tunnel.  I thought maybe that I had just missed a config option somewhere.  But it sounds like this is expected on IPSEC?

          Jon

          1 Reply Last reply Reply Quote 0
          • R
            rpsmith
            last edited by

            if you have traffic trying to go out the tunnel, the links should re-establish.  do you have pfs 2.0 on both ends?

            Roy…

            1 Reply Last reply Reply Quote 0
            • A
              azmtnbike
              last edited by

              Thanks Roy,

              That is about a simple answer I have had to any issue.  When I would look at IPSEC status and see the connection dropped and the "connect VPN" icon next to it, I thought I had to manually intervene.  Two of my VPN connections are to training rooms that aren't always active.  I tried it out and you were correct.

              Thanks for setting my mind at ease.

              Jon

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                If you specify a keep-alive IP that's in the remote subnet (inside the remote phase 2 network), it will bring up the tunnels automatically every time.

                The connect button just sends a ping on the tunnel, nothing fancy.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.