Re: [Swan] [libreswan/libreswan] IPsec/XAuth reusing lease for multiple clients behind same NAT (#166)

2018-02-12 Thread Paul Wouters
On Mon, 12 Feb 2018, MikeLund wrote: Hi, I've set up an IPsec/XAuth VPN using hwdsl2/setup-ipsec-vpn#314 (comment) Problem is: when two users connect from behind the same NAT, the first client's networking stops working. My guess on the cause of this is what I've named this issue: clients that

[Swan] libreswan 3.20 does NOT listen on UDP port 4500 for IPv6

2018-02-12 Thread Hao Chen
Hi All: I am working on "IPsec behind NAT" for IPv6. For IPv4, "pluto" listen on 4500 after start up. But for IPv6, "pluto" does NOT listen on it. But, for UDP port 500, "pluto" listen on IPv6 after startup How to let "libreswan" listen on 4500 for IPv6? Thanks [root@CentOS7 ~]# nets

Re: [Swan] libreswan 3.20 does NOT listen on UDP port 4500 for IPv6

2018-02-12 Thread Paul Wouters
On Mon, 12 Feb 2018, Hao Chen wrote: I am working on "IPsec behind NAT" for IPv6.  For IPv4, "pluto" listen on 4500 after start up. But for IPv6, "pluto" does NOT listen on it. But, for UDP port 500, "pluto" listen on IPv6 after startup How to let "libreswan" listen on 4500 for IPv6? 

Re: [Swan] libreswan 3.20 does NOT listen on UDP port 4500 for IPv6

2018-02-12 Thread Hao Chen
Thank you for your response. Are you saying: libreswan 3.20 does NOT support "IPv6 behind NAT" at all ?? Thanks From: Paul Wouters Sent: Monday, February 12, 2018 11:36 To: Hao Chen Cc: swan@lists.libreswan.org Subject: Re: [Swan] libreswan 3.20 does NOT listen o

Re: [Swan] libreswan 3.20 does NOT listen on UDP port 4500 for IPv6

2018-02-12 Thread Paul Wouters
> On Feb 12, 2018, at 15:56, Hao Chen wrote: > > Thank you for your response. > > Are you saying: libreswan 3.20 does NOT support "IPv6 behind NAT" at all ?? Yes. And I am saying I don’t know if the Linux kernel supports it. > > Thanks > From: Paul Wouters > Sent: Monday, February 12, 2