Wednesday, May 29, 2024

Re: [7.5/amd64] ipsec + npppd + sasyncd + carp - doesn't pick up the VPN session at switchover

On 2024/05/29 18:08, Vitaliy Makkoveev wrote:
> On Wed, May 29, 2024 at 01:23:47PM -0000, Stuart Henderson wrote:
> > On 2024-05-29, Vitaliy Makkoveev <mvs@openbsd.org> wrote:
> > > On Wed, May 29, 2024 at 12:48:41PM +0200, Radek wrote:
> > >> Thank you, that explains everything.
> > >> Does wireguard support replication? Will it work properly in my CARP setup?
> > >>
> > >
> > > No for both questions. However, wireguard allows to create complicated
> > > connections where one wg(4) interface could have multiple associated
> > > peers on "client" side too.
> >
> > It maybe worth seeing whether wg combined with ifstated might
> > do the trick (bring wg down when carp is down, and vice-versa).
> >
>
> ifstated can't help, he wants seamless switch between "servers".

Depends on the exact use case, I can think of some situations
where it could help.

No comments:

Post a Comment