LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-16-2007, 11:42 PM   #1
xnomad
Member
 
Registered: Jun 2005
Posts: 53

Rep: Reputation: 15
Does IPSec work with bonded interfaces?


Once again Please ignore I've found my error, had a typo on one of the IP addresses (I made it a 40 bit address :-P oops)


Hi,

I'm setting up a router cluster with CENTOS 5.0 and Linux HA (Heartbeat)

I'm currently trying to get setkey working with a bonded interface (rather than the virtual IP for heartbeat, for starters) and I am starting to think that the reason setkey is not working is because of the bonded interface.

When I run setkey -f /etc/setkey.conf I get the following error (I have replaced the IP addresses with the names our_external IP and their_external IP etc. for security reasons):

line 5: Name or service not known at [ out ipsec
esp/tunnel/(our external ip)-(their external ip)/require;]
parse failed, line 5.

Our external IP is the bonded interface of bond eth0 and eth3.

My setkey.conf file looks like the following:

#!/usr/sbin/setkey -f
flush;
spdflush;
spdadd (our extrenal ip)/32 (vpn internal ip)/32 any -P out ipsec
esp/tunnel/(our external ip)-(their external ip)/require;
spdadd (vpn internal ip)/32 (our external ip)/32 any -P in ipsec
esp/tunnel/(their external ip)-(our external ip)/require;


I've tried this simple setkey setup on other machines without bonded interfaces and it worked. I can't seem to google anything about IPSec and bonding, should it work?

Cheers,

Last edited by xnomad; 12-17-2007 at 12:01 AM.
 
Old 12-17-2007, 02:20 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
//removing from zero posts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Losing packets on bonded ethernet channels Mugsy69 Linux - Networking 2 10-20-2007 10:16 PM
bonded interfaces 2x slower than one bedge Linux - Networking 1 03-06-2007 04:55 PM
How to find *hardware* mac addresses on bonded interfaces? TotalDefiance Linux - Software 3 06-06-2006 11:53 AM
2 dynamic address cable modems, bonded matthewlking Linux - Networking 6 04-19-2006 10:18 AM
IPSec tunnel over multiple interfaces tylerl Linux - Networking 0 07-21-2005 05:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration