Re: [Swan] Problem with subnet-to-subnet setup behind NAT'ed networks

2016-02-12 Thread Jacob Vind
On 11/02/16 15:48, Matt Rogers wrote: You should try adding DPD settings to your config. Specifically dpdaction=restart which will try to renegotiate if there's an interruption that goes past the dpdtimeout value. Hi Matt, Great, thanks. Yes that seems to do it, I added this 20 hours ago

[Swan] Problem with subnet-to-subnet setup behind NAT'ed networks

2016-02-11 Thread Jacob Vind
Hi, I really hope we can get some help, we are trying to set up a subnet-to-subnet Libreswan based IPSEC connection between two sites of ours. But we are having problems with it, we can get it to startup and working for a while (time varies from few minutes to hours). I hope someone will

Re: [Swan] Problem with subnet-to-subnet setup behind NAT'ed networks

2016-02-11 Thread Tony Whyman
Jacob, I have a similar and working setup using Libreswan/Ubuntu. The main difference is that I have the tunnels working peer-to-peer rather than subnet-to-subnet and it may be worth your while testing and proving the peer to peer case before moving to the subnet-to-subnet case. Otherwise,

Re: [Swan] Problem with subnet-to-subnet setup behind NAT'ed networks

2016-02-11 Thread Matt Rogers
- Original Message - > From: "Jacob Vind" <libres...@harm.dk> > To: swan@lists.libreswan.org > Sent: Thursday, February 11, 2016 7:59:01 AM > Subject: [Swan] Problem with subnet-to-subnet setup behind NAT'ed networks > > Hi, > > I really hope we