I have two ipsec tunnels to remote locations. All of a sudden, both tunnels were down and would not re-establish.
So, I find both tunnels down and there is nothing that will allow them back up. I noted there was a new version 7.404 in which the IPSEC had a vulnerability and it is fixed in this new urgent version.
I installed the new version and both tunnels are instantly back up.
My question is this - did Astaro developers shut down the tunnels to force the end user to update due to the vulernability? If so, I did not get any sort of notification of such and the endpoints had to call me to tell me the tunnels were down. That is not right if that is the case, unless the exploit was already taking place rampantly but again, no notification of any kind.
I appreciate that if it was a serious vulnerability that maybe it may warrant a forced tunnel shutdown by the vendor but notification needs to also take place.
Now then, if Astaro had nothing to do with the tunnels going down, could I have been exploited in some fashion???
How can I tell?? What logs should I investigate and what should I look for.
This to me is a bit of a serious situation.
This thread was automatically locked due to age.