Please have a look at: https://forum.opnsense.org/index.php?topic=5547.0"ipsec: IKEv2 can handle multiple phase 1 with the same IP"I'm using this feature with ASA in order to handle SAs based on the key-id field to separate connections. This would allow you to failover to X backup interfaces.Perhaps this already fits you needs and just need some documentation
Ok, but this means we have to use if_ipsec which is currently not supported.
Quote from: mimugmail on July 31, 2017, 09:05:50 amPlease have a look at: https://forum.opnsense.org/index.php?topic=5547.0"ipsec: IKEv2 can handle multiple phase 1 with the same IP"I'm using this feature with ASA in order to handle SAs based on the key-id field to separate connections. This would allow you to failover to X backup interfaces.Perhaps this already fits you needs and just need some documentationWhat would a rough sketch of the documentation look like? Whether or not this fits the OP's needs, it should fit mine, I think.
Quote from: mimugmail on July 31, 2017, 08:10:16 pmOk, but this means we have to use if_ipsec which is currently not supported. I know.But this functionality is not specific to StrongSwan, it does not have failover, we can read in its documentation.This is a functionality implemented in the specific part of each product. Each one implements its logic and works together with Strongswan, Libreswan...