Multiple IPsec tunnels between the same source and destination IP addresses #1239
-
Hi all, I want to ask if it is possible to create two IPsec tunnels between the same source and destination IP addresses with libreswan? The goal is to use ECMP (with FRR) across both IPsec tunnels. My configurations is below: Site01: conn vpn2-to-192.168.50.2 Site02: conn vpn2-to-192.168.50.1 The IPsec tunnels get established successfully and the VTI interfaces get created. But I cannot ping between the VTI interfaces. IPsec Status from Site02: 000 #1: "vpn1-to-192.168.50.1":4500 STATE_PARENT_I3 (PARENT SA established); EVENT_SA_REKEY in 25598s; idle; IP tunnel ouput: / # ip tunnel |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Do not use VTI for more than one tunnel, use XFRIMi interfaces (eg ipsec-device=1 for one connection and ipsec-interface=2 for the other connection. Then you get an "ipsec1" and "ipsec2" interface. I'm not sure if it will work with two different 0/0 to 0/0 tunnels. You might need to do some manual routes to make it work. But I guess you will do manual routes anyway to device into which IPsec tunnel / interface to send packets through |
Beta Was this translation helpful? Give feedback.
Do not use VTI for more than one tunnel, use XFRIMi interfaces (eg ipsec-device=1 for one connection and ipsec-interface=2 for the other connection. Then you get an "ipsec1" and "ipsec2" interface.
I'm not sure if it will work with two different 0/0 to 0/0 tunnels. You might need to do some manual routes to make it work. But I guess you will do manual routes anyway to device into which IPsec tunnel / interface to send packets through