Quote from: jorgevisentini on July 31, 2017, 08:21:27 pmQuote from: mimugmail on July 31, 2017, 08:10:16 pmOk, but this means we have to use if_ipsec which is currently not supported. I know.But this functionality is not specific to StrongSwan, it does not have failover, we can read in its documentation.This is a functionality implemented in the specific part of each product. Each one implements its logic and works together with Strongswan, Libreswan...Libreswan has it's own interface support (software), and FreeBSD introduced with 11.0 if_ipsec (OS). Don't know how exactly Sophos does it, they also use strongswan, but the old version 4 (no IKEv2!!!). Also ASA e.g. introduced route based VPN very late.
Quote from: mimugmail on July 31, 2017, 08:10:16 pmOk, but this means we have to use if_ipsec which is currently not supported. I know.But this functionality is not specific to StrongSwan, it does not have failover, we can read in its documentation.This is a functionality implemented in the specific part of each product. Each one implements its logic and works together with Strongswan, Libreswan...
Ok, but this means we have to use if_ipsec which is currently not supported.
I see this one timely more realistic (OPN to OPN):https://github.com/opnsense/core/issues/952