Re: [strongSwan] Problem: "unable to install policy -the same policy for reqid XXXX exists "

2018-11-23 Thread Sven Anders
Am 23.11.18 um 11:11 schrieb Tobias Brunner: > Hi Sven, > >> We are using strongSwan 5.6.2 on a Linux kernel 4.1.39. > > Try using a newer strongSwan version. So the problem is known? Which version should I use at least. Will 5.6.3 be enough or should I use 5.7.1 instead? >> The installed

Re: [strongSwan] Problem: "unable to install policy -the same policy for reqid XXXX exists "

2018-11-23 Thread Tobias Brunner
Hi Sven, > We are using strongSwan 5.6.2 on a Linux kernel 4.1.39. Try using a newer strongSwan version. > The installed policy (in this case) is the following: > > src 10.0.0.0/8 dst 192.168.3.67/32 > dir out priority 379519 ptype main > tmpl src 217.6.20.66 dst 84.160.101.118

[strongSwan] Problem: "unable to install policy -the same policy for reqid XXXX exists "

2018-11-23 Thread Sven Anders
Hello! We are using strongSwan 5.6.2 on a Linux kernel 4.1.39. Our problem is, that after some uptime the strongswan rejects connections with the following message: charon: 23422[CFG] unable to install policy 10.0.0.0/8 === 192.168.3.67/32 out for reqid 14832, the same policy for reqid 4388

[strongSwan] strongSwan site-to-site VPN on DMZ host with single interface

2018-11-23 Thread tom
Hello, how it be possible to run a strongSwan site-to-site VPN placed in a DMZ with only a single NIC? The strongSwan server is placed in my DMZ with a routable public IP 1.1.1.1 Public LAN 1.1.1.0/24. My local IP, where all outgoing traffic through the tunnel should bei NAT to is 10.0.0.1.