This package has Vyatta conntrack-sync configuration cli and show commands.
Details
Jan 27 2025
Hey all,
Jul 2 2024
Apr 12 2024
Apr 11 2024
Apr 9 2024
https://conntrack-tools.netfilter.org/manual.html#sync-aa
conntrackd allows you to deploy an symmetric Active-Active setup based on a static approach. For example, assume that you have two virtual IPs, vIP1 and vIP2, and two firewall replicas, FW1 and FW2. You can give the virtual vIP1 to the firewall FW1 and the vIP2 to the FW2.
Jan 19 2024
@I-n-d-y Try to get it working without VyOS CLI.
Provide the required contrack config. As I'm not sure that it will work correctly at all.
Jan 9 2024
Nov 16 2023
I have a similar setup where I have two VyOS VMs used as VPN routers with some firewalling enabled. Since I use OSPF for dynamic routing I am not able to synchronize the sessions between both routers so in case one VPN router fails the other one can't take over flawlessly. Having conntrack-sync configuration separated from VRRP would be a great benefit.
Nov 15 2023
Created a related feature request but for VRRP here
https://vyos.dev/T5745
I had entered the command as you have suggested and I think it's working somehow.
Nov 10 2023
Yes I mean sudo ip vrf exec FOO /usr/sbin/conntrackd -C /run/conntrackd/conntrackd.conf
It has been a while since I had setup the HA VRF. I attached the interfaces on both routers to use this VRF but then conntrack-sync wasn't woking anymore. Do you mean if I had also tried to manually start the service and configure it to use this VRF?
Nov 9 2023
Did you try to start this service in VRF?
Nov 8 2023
Make sure conntrack-sync works with active-active HA configuration with BGP environment & IPv6
Sep 14 2023
Aug 2 2023
Jun 26 2020
Jun 25 2020
Sorry it took so long! I've cherry-picked it into crux, will be in 1.2.6.
Sep 23 2019
Bump
May 14 2019
@syncer Any chance of getting this merged into 1.2.2?
Apr 23 2019
Any chance of getting this merged into 1.2.2?