is optimized
# dh_exponent_ansi_x9_42 = no
}
=
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
Users@lists.strongswan.org
https
,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users
resolve
(all on a single line)
in the charon section of strongswan.conf. We usually do not recommend to
set the load directive manually, but maybe it is necessary for this
distribution package.
I'll try that.
Do the packets show up in a packet sniffer on biene?
Yes.
Regards,
--
Wolfgang
sides almost simultanously, no connection is
established.
With socket-raw a connection is established and I may restart each side at
will.
Do the packets show up in a packet sniffer on biene?
Yes, they did.
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
minutes).
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users
.
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users
all this and all other connections which also the IKE SA of name.
I think it would be better if charon behaved like that:
ipsec down name{*}
and for every IKE SA name[n] which has no other childs
ipsec down name[n]
Or the documentation is changed.
Regards
--
Wolfgang Walter
Studentenwerk München
. This doubles the number of rekeying events. Would it be
possible to have a sort of a second-class-field:
conn LEO15D-to-TUMBER_D
leftfavour=yes
which would mean:
if a second child-sa gets established close that one which was initiated from
right
Regards
Andreas
Regards,
--
Wolfgang Walter
will probably not do what you expect. Use ipsec down
name{*} and/or ipsec down name[*] instead.
Regards
Andreas
On 11/11/2010 08:15 PM, Wolfgang Walter wrote:
Hello,
I use strongswan 4.4.1.
The manual says that
ipsec down name
will terminate connection name
, received critical signal
With 4.4.1 I don't geht this error.
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users
If mobike=no is added to ei_dotter_ipv6 this does not happen.
I think it does not make sense to move transportmode connections between ipv4
and ipv6.
Regards,
--
Wolfgang Walter
Studentenwerk München
Anstalt des öffentlichen Rechts
___
Users mailing list
11 matches
Mail list logo