Re: IPSec fails with NO_PROPOSAL_CHOSEN when connecting from recent MacOS/iOS clients

2022-02-18 Thread fixied
On Fri, Feb 18, 2022 at 15:06 Stuart Henderson wrote... > On Fri, Feb 18, 2022 at 11:43 AM I wrote: >> ike passive esp transport proto udp from $public_ip to any \ >> main auth "hmac-sha2-256" enc "aes-256" group "modp2048" \ >> quick auth "hmac-sha2-256" enc "aes-256" group "modp2048" \ >>

Re: IPSec fails with NO_PROPOSAL_CHOSEN when connecting from recent MacOS/iOS clients

2022-02-18 Thread fixied
Matthew Ernisse writes... > How are you setting the proposals on the MacOS end? Your first instance I > think you figured out that you had not specified PSK and so you had a mismatch > there. In the second case you didn't supply the iked(8) debugging information > so I'm not sure what is

Re: IPSec fails with NO_PROPOSAL_CHOSEN when connecting from recent MacOS/iOS clients

2022-02-18 Thread fixied
On Fri, Feb 18, 2022 at 11:43 AM I wrote: > I recently started seeing some ipsec clients fail on newer versions of > MacOS and iOS. After MacOS 12.1, connecting to my head end now fails > with NO_PROPOSAL_CHOSEN using mod1024 in my ipsec.conf. I've also > tried, with no success: > > main auth

IPSec fails with NO_PROPOSAL_CHOSEN when connecting from recent MacOS/iOS clients

2022-02-18 Thread fixied
I recently started seeing some ipsec clients fail on newer versions of MacOS and iOS. After MacOS 12.1, connecting to my head end now fails with NO_PROPOSAL_CHOSEN using mod1024 in my ipsec.conf. I've also tried, with no success: main auth "hmac-sha2" enc "aes" group modp1024 quick auth

smtpd bounce messages and non-existent users

2022-02-15 Thread fixied
I have a server configured to accept mail for the domain of the server itself (example.org) and virtual domains (example.com). The virtual domain has several mappings of users to both local mbox accounts and remote forwarding. That works correctly. The problems I'm having are: 1. When I send