Netwatch to flush ipsec installed-sa

Hi,

As many are aware of ipsec tunnels suffer from the need to manually flush installed-sa from now and then. I tried to use Netwatch to start a one line script to do the flush. Unfortunately netwatch doesn’t ping from a prefered source address, making it unusable to test a remote tunnel address.
Did anyone find or think of a workaround ?

Kindest regards

Any idea anyone on how to netwatch vpns ?
Thanks.

Greeting !
Anyone there ? Is this a dummy question ?
Thanks to any comment.

Not a dummy question :wink:

I don’t have a solution at hand, too.
Perhaps you could do something with policy routing to force out your netwatch pings with a specific source address?

Best regards,
Christian Meis

Thank you cmit. I was in trouble with my self-confidence :wink:
Moreover I did get it running with policy routing rule.
I owe you kudos today.

Many many thanks.

Good to hear your self-confidence is restored :wink:

Best regards,
Christian Meis