I have small network.
RA1, RA2, RB1, RB2 - are routers with debian jessie. RC1 is router with debian wheezy.
RA1 and RA2 are together in A collocation, and are connected by the same network.
RB1 and RB2 are together in B collocation, and are connected by the same network.
RC1 is on C collocation.
Between B and C there is leased transmision.
For security reason i need to encrypt traffic between collocations. And - to protect leased transmission failure - i've created openvpn tunnels:
1. RA1-RB1, RA1-RB2, RA2-RB1, RA2-RB2 over internet
2. RB1-RC1, RB2-RC1 over transmission.
All tunnels works fine via independent internet links.
It was working fine. All routers are in one area 0, all are ASBR, one of routers is always DR, second is BDR - they're in full state - always works fine.
I redistribute to ospf only specific networks using prefix list.
I have plans to create openvpn tunnels from B to C over internet and from A to B over transmission - but i didn't realized it yet.
When i've put ospf over vpn tunnels - they're tun type - everything goes fine. But - after few days - some OSPF goes down. IP Traffic via openvpn was ok, i saw helo packets on both sides of tunnel, but - on one side second router was in Init state, and on second - there was no information about it in ip show ospf neighbours.
I've checked (via netstat -ng) that second router in this schema was not join 18.104.22.168 multicast group - and show ip ospf interface <name of tunel> - didn't show that it join OSPFAllRouters group.
Putting down/up tunnel - doesn't help. Changing type of interface via vtysh to point-to-point - also don't.
Once(RA2-RB2) - when i changed type of tunnel to tap - it helps - for short time. But - changing of RA1-RB2) - doesn't. But - after some time link between RA2 and RB2 stop working too.
Restart of ospfd usualy helps for some time - but after few changes in network or some time it's broken again.
All time works tunnel from RA2-RB1. All other tunnel after some time/some changes - goes to Init state and don't work.
Does anybody have any idea what can be wrong?
Is anybody using ospfd over openvpn links in simmilar scenario?