[Swan] Trigger for tunnel status change

Paul Wouters paul at nohats.ca
Thu Apr 9 19:38:35 UTC 2020

On Wed, 8 Apr 2020, rene.neumann at zpesystems.com wrote:

> I have a stupid question but exist there a trigger which would indicate a status change in the tunnel, for example, the tunnel went up
> or down? I played with the leftupdown option but found that this only triggers when you actually bring the tunnel up or down, but not
> when the tunnel actually goes up or down.

It should be triggered when the tunnel goes up or down. It is how most
people handle their billing and accounting for VPN usage.

An older option is the statsbin= option. See "man ipsec.conf". It's data
format is uhm, abominable. We just inherited it a long time ago.

> What I mean here is that when I have a connection with the start mode add and the remote site is then starting the connection the
> script will not trigger and the same is true for when the tunnel goes down?

It shouldn't matter which endpoint starts the initiating. Once it is up,
the updown script runs (actually it runs a number of times for different


More information about the Swan mailing list