diff options
author | Patrick Uiterwijk <puiterwijk@redhat.com> | 2015-10-21 18:26:32 +0000 |
---|---|---|
committer | Patrick Uiterwijk <puiterwijk@redhat.com> | 2015-10-21 18:26:32 +0000 |
commit | b1db3bafd8bfde6fac9cc8c7fc3a5bedd39a1483 (patch) | |
tree | 17af532d874396bdc111a61e4eff9610a09d19bf | |
parent | e1edce6717ef06a224c7044f52eddf5f9979c24d (diff) | |
download | ansible-b1db3bafd8bfde6fac9cc8c7fc3a5bedd39a1483.tar.gz ansible-b1db3bafd8bfde6fac9cc8c7fc3a5bedd39a1483.tar.xz ansible-b1db3bafd8bfde6fac9cc8c7fc3a5bedd39a1483.zip |
Disable persist-tun for openvpn
This should solve the issue where RHEL7 machines that get a network
hiccup need an OpenVPN restart to restore their routes.
The code is broken in the current upstream OpenVPN release, such that
it does tear down some of the routes during a ping-restart (when the
connection is dropped due to network hiccups), but the reconnection
code does not restore the routes.
I am working on an upstream patch to fix this, but in the meantime
disabling persist-tun will make sure that OpenVPN does the entire
initialization upon reconnection, which makes sure that all routes
are created.
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
-rw-r--r-- | files/openvpn/client.conf | 1 | ||||
-rw-r--r-- | roles/openvpn/client/files/client.conf | 1 | ||||
-rw-r--r-- | roles/openvpn/server/files/server.conf | 1 |
3 files changed, 0 insertions, 3 deletions
diff --git a/files/openvpn/client.conf b/files/openvpn/client.conf index d274e72ac..abb5d03d1 100644 --- a/files/openvpn/client.conf +++ b/files/openvpn/client.conf @@ -13,7 +13,6 @@ resolv-retry infinite nobind persist-key -persist-tun ca ca.crt cert client.crt diff --git a/roles/openvpn/client/files/client.conf b/roles/openvpn/client/files/client.conf index d274e72ac..abb5d03d1 100644 --- a/roles/openvpn/client/files/client.conf +++ b/roles/openvpn/client/files/client.conf @@ -13,7 +13,6 @@ resolv-retry infinite nobind persist-key -persist-tun ca ca.crt cert client.crt diff --git a/roles/openvpn/server/files/server.conf b/roles/openvpn/server/files/server.conf index c824b12dd..3ba8fab11 100644 --- a/roles/openvpn/server/files/server.conf +++ b/roles/openvpn/server/files/server.conf @@ -6,7 +6,6 @@ comp-lzo ping-timer-rem -persist-tun persist-key ca ca.crt |