Project

General

Profile

Issue #697

HA: nodes fail to sync data because of UDP packet drops

Added by Emeric Poupon almost 6 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
-
Affected version:
5.2.0
Resolution:

Description

Hello,

As discussed in the mailing list (https://lists.strongswan.org/pipermail/dev/2014-August/001048.html)
UDP packet drops on the HA link prevent nodes to be fully synchronized.

This leads to a lot of errors when:
- resyncing a segment with hundreds of tunnels.
- negociating thousands of tunnels in a short delay.

Implementing a bandwidth limiter and increasing the receive buffer size of the HA socket helped, but there are still problems.

Regards,

Also available in: Atom PDF