Quote from: mimugmail on July 31, 2017, 09:51:36 PMSo... the only distribution I got to see the failover script was Sophos, in this case both UTM and XG and both are big scripts...Quote from: jorgevisentini on July 31, 2017, 08:21:27 PMQuote from: mimugmail on July 31, 2017, 08:10:16 PMI know.
Ok, but this means we have to use if_ipsec which is currently not supported.
But this functionality is not specific to StrongSwan, it does not have failover, we can read in its documentation.
This is a functionality implemented in the specific part of each product. Each one implements its logic and works together with Strongswan, Libreswan...
Libreswan has it's own interface support (software), and FreeBSD introduced with 11.0 if_ipsec (OS). Don't know how exactly Sophos does it, they also use strongswan, but the old version 4 (no IKEv2!!!). Also ASA e.g. introduced route based VPN very late.
"