Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Will switch to strongswan allow for High Availability?

    Scheduled Pinned Locked Moved IPsec
    6 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kapara
      last edited by

      Not sure what the technical reasons are for this not being possible but will the switch to StrongSwan for ipsec finally allow fault tolerant or ipsec failover on multi-wan?

      https://wiki.strongswan.org/projects/strongswan/wiki/HighAvailability

      Skype ID:  Marinhd

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Probably not on 2.2, but later on, perhaps

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • K
          kapara
          last edited by

          Possibly a bounty for the next version after 2.2… 😄

          Skype ID:  Marinhd

          1 Reply Last reply Reply Quote 0
          • C
            charliem
            last edited by

            Just reading the linked page now …. seems to be closely tied to linux kernel development.  Is ha currently an option for FreeBSD (outside of pfSense)?

            Or does the 'maybe later' have to include getting equivalent clusterip work into the freebsd kernel?

            1 Reply Last reply Reply Quote 0
            • K
              kapara
              last edited by

              Yeah not sure either.  I guess the best way to find out is I will post a bounty.  I am sure others will also be interested in a true IPSec failover solution.

              Skype ID:  Marinhd

              1 Reply Last reply Reply Quote 0
              • C
                charliem
                last edited by

                @kapara:

                Yeah not sure either.  I guess the best way to find out is I will post a bounty.  I am sure others will also be interested in a true IPSec failover solution.

                Or ask in the strongswan / freebsd communities.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.