OpenBSD SEC(4) for Route Based IPSec VPNs
undeadly.org
undeadly.org
Bit surprised that even though there seems to be interest in IPSec in OpenBSD nobody ever finished sasyncd. Which is used to create an IPSec failover setup between OpenBSD hosts. However sasyncd was never fully finished. It can't sync existing SA states. Meaning the first failover works, but the second time you failover you are missing SA's.
> The reason I started on this was to better interoperate with "site-to-site" vpns, in particular AWS Site-to-Site VPNs, and the Auto-Discovery VPN (ADVPN) stuff on fortinet fortigate appliances. Both of these negotiate IPsec tunnels that can carry any traffic at the IPsec level, but use BGP and routes to direct traffic into those tunnels.
Also, as this tunnel interface still integrates with OpenBSD isakmpd (IKEv1) and iked (IKEv2) daemons, you can use certificate-based authentication without installing some bespoke, proprietary agent for key management.