IPSEC key sync

From: Kalev Lember
Date: Thu Jul 20 2006 - 19:12:40 EST


OpenBSD has sasyncd daemon to synchronize IPSEC keys between two or more
hosts that should act as failover gateways. I am wondering if it is
possible to do this with Linux.

There are IP_VS_PROTO_ESP and IP_VS_PROTO_AH configuration options which
claim to do "ESP and AH load balancing support". I am wondering what
does this exactly mean? I tried IPVS compiled with those options with
keepalived and it didn't seem to synchronize keys.

Maybe sasyncd should be ported to Linux?

Kalev Lember
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/