Dear Andrey
Thank you for your reply. I was able to find a configuration that
establishes the IPSec tunnel now!
It was a bit of a trial and error and I have tried/changed several things;
so I am not 100% sure what the minimum set of changes required would have
been, but I think I understand that
On 13.05.2018 02:37, Andreas Scherrer wrote:
> My interpretation of [2]'s statement:
>
> "If no security association is found, the packet is put on hold and the
> IKE daemon is asked to negotiate an appropriate one."
>
> is that it should somehow be automagic. But in my current configuration,
>