Hello,

with strongSwan you are not supposed to manipulate the SAD/SPD
with an external command line tool as "setkey" or
"ip xfrm state/policy add" because the IKEv1/IKEv2 daemons will
not become aware of any external SAD/SPD changes. All changes
must be communicated through the strongSwan daemon interfaces.

Regards

Andreas

On 29.05.2012 16:23, krishna chaitanya wrote:
> HI Team,
> 
> I am new to strongswan. We are working on an implementation of IPsec. 
> 
> I earlier worked with racoon where I used setkey for SAD/SPD manipulation.
> 
> In strongswan I had configured the SA's using IPsec.conf file, but is
> there a tool where we could manipulate SAD/SPD using shell. 
> 
> 
> Thanks,
> KC.Sanapala

======================================================================
Andreas Steffen                         [email protected]
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Dev mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/dev

Reply via email to