From: Harry G. <ha...@hg...> - 2004-04-23 15:42:36
|
At 10:53 AM -0400 4/23/04, Rob Moore wrote: >I have roughly 35 IPCops out there, acting as firewalls and VPN >appliances back to the home office. Occasionally the VPNs go down (due >to poweroutages, DSL disconnections, etc.). I'd love to know how to make >the VPN come back up automatically when connectivity is restored. Can >anyone help me with this? There are several scripts floating around, including one I wrote that's on the distribution (/usr/local/bin/dynchk). These can be customized to do what you want. I have 9 sites and run dynchk every 5 minutes via cron against all sites. I'd suggest searching the mailing list archives for more of them. The basic idea is to ping the GREEN address of every network. If the network doesn't respond, tell IPSEC to stop it, reload its parameters and restart it. My VPNs are all on dyndns. When their ISPs change their addresses, the switch is made fast enough that no one seems to notice or complain. Probably because that's done in the wee hours of the morning. Harry |