From 9ea0cb90a6f7685cd29f018895aefbb70e25a5d6 Mon Sep 17 00:00:00 2001 From: jim-p Date: Tue, 6 Mar 2012 14:30:41 -0500 Subject: [PATCH] Be more intelligent when managing OpenVPN client connections bound to CARP VIPs. If the interface is in BACKUP status, do not start the client. Add a section to rc.carpmaster and rc.carpbackup to trigger this start/stop. If an OpenVPN client is active on both the master and backup system, they will cause conflicting connections to the server. Servers do not care as they only accept, not initiate. --- etc/inc/openvpn.inc | 4 ++++ etc/rc.carpbackup | 10 ++++++++++ etc/rc.carpmaster | 10 ++++++++++ 3 files changed, 24 insertions(+) diff --git a/etc/inc/openvpn.inc b/etc/inc/openvpn.inc index 9729217bc8..01a6f6ae7f 100644 --- a/etc/inc/openvpn.inc +++ b/etc/inc/openvpn.inc @@ -672,6 +672,10 @@ function openvpn_restart($mode, $settings) { if (isset($settings['disable'])) return; + /* Do not start if we are a CARP backup on this vip! */ + if ((substr($settings['interface'], 0, 3) == "vip") && (get_carp_interface_status($settings['interface']) == "BACKUP")) + return; + /* start the new process */ $fpath = $g['varetc_path']."/openvpn/{$mode_id}.conf"; mwexec_bg("/usr/local/sbin/openvpn --config {$fpath}"); diff --git a/etc/rc.carpbackup b/etc/rc.carpbackup index 68f4e2c610..165dd9e393 100755 --- a/etc/rc.carpbackup +++ b/etc/rc.carpbackup @@ -32,10 +32,20 @@ require_once("functions.inc"); require_once("config.inc"); require_once("notices.inc"); +require_once("openvpn.inc"); $notificationmsg = "A carp cluster member has resumed the state 'BACKUP'"; notify_via_smtp($notificationmsg); notify_via_growl($notificationmsg); +/* Stop OpenVPN clients running on this VIP, since multiple active OpenVPN clients on a CARP cluster can be problematic. */ +global $config; +foreach ($config['openvpn']['openvpn-client'] as $settings) { + if ($settings['interface'] == $argv[1]) { + log_error("Stopping OpenVPN instance on {$settings['interface']} because of transition to CARP backup."); + openvpn_restart('client', $settings); + } +} + ?> \ No newline at end of file diff --git a/etc/rc.carpmaster b/etc/rc.carpmaster index 5b85e0383d..aaac8682bd 100755 --- a/etc/rc.carpmaster +++ b/etc/rc.carpmaster @@ -32,10 +32,20 @@ require_once("functions.inc"); require_once("config.inc"); require_once("notices.inc"); +require_once("openvpn.inc"); $notificationmsg = "A carp cluster member has resumed the state 'MASTER'"; notify_via_smtp($notificationmsg); notify_via_growl($notificationmsg); +/* Start OpenVPN clients running on this VIP, since they should be in the stopped state while the VIP is CARP Backup. */ +global $config; +foreach ($config['openvpn']['openvpn-client'] as $settings) { + if ($settings['interface'] == $argv[1]) { + log_error("Starting OpenVPN instance on {$settings['interface']} because of transition to CARP master."); + openvpn_restart('client', $settings); + } +} + ?> \ No newline at end of file