[strongSwan] A way to make my internal DNS server resolves all DNS requests (internal and internet)?

2017-06-14 Thread Sarefrech
hi all, I've been using INTERNAL_DNS_DOMAIN with attr plugin to let my IPAD requests dns resolutions to my intranet DNS servers. That works ok.   However I would to know if/how I could : - ideally send all DNS requests (whole internet & internal)  to my internal DNS servers. I did not find

[strongSwan] iPhone iOS devices disconnecting when screen if off.

2017-06-14 Thread Felipe Arturo Polanco
Hi, We are facing a problem with our Strongswan 5.4 IKEv1 xAUTH with PSK server. Basically we can get all the devices login fine and get their IPs but when the iphone turn off the screen, after a few seconds the connection drops. I have many servers with this issue and only happens to devices

[strongSwan] S2S VPN with dynamic DNS

2017-06-14 Thread Dusan Ilic
Hi, I have a S2S IPsec tunnel setup that have problems now when one side of the tunnel have been assigned a new public IP. The hostname used have been immediately updated by way od dynamic DNS, and the TTL have expired two hours ago. When trying to up the tunnel on the side with the changed

Re: [strongSwan] Best practices regarding monitoring

2017-06-14 Thread Peter Hofmann
Hi, On Fri, Jun 09, 2017 at 09:11:27PM +0200, Noel Kuntze wrote: > Besides DPD, there's no standard that charon implements for that. I am > also not aware of any that uses CHILD_SAs. alright, too bad. :-/ So, am I correct to assume that you guys usually evaluate the output of `ipsec statusall`