Re: [strongSwan] ISAKMP packet ignored with right=%any ?

2020-04-28 Thread Alex K
On Tue, Apr 28, 2020, 20:19 Philippe Marrot wrote: > > All Firewall policies are already set to ACCEPT , and all others tunnels > (using 500/4500) are working. > > Any other ideas ?. > It seems the rightid does not match. I would check responder and initiator logs, perhaps increasing verbosity.

Re: [strongSwan] ISAKMP packet ignored with right=%any ?

2020-04-28 Thread Philippe Marrot
All Firewall policies are already set to ACCEPT , and all others tunnels (using 500/4500) are working. Any other ideas ?. thank you. PM. Le mar. 28 avr. 2020 à 17:03, Noel Kuntze a écrit : > Hi, > > Make sure the iptables chain policies are all set to Accept. > Flushing the ruleset does not re

Re: [strongSwan] ISAKMP packet ignored with right=%any ?

2020-04-28 Thread Noel Kuntze
Hi, Make sure the iptables chain policies are all set to Accept. Flushing the ruleset does not reset the chain policies. Kind regards Noel Am 28.04.20 um 15:18 schrieb Philippe Marrot: > Not firewall issue, I tried without and other static site to ste tunnels are > working. signature.asc De

[strongSwan] ISAKMP packet ignored with right=%any ?

2020-04-28 Thread Philippe Marrot
Hi everyone, I'm struggling with a site to site IKEv2 tunnel for a peer using dynamic IP. It seems that the first Ikev2 init packet is totally ignored. I don't know why. When using a static IP , all goes well. *Config dynamic:* I use the following ipsec.conf (ip and peer named changed): conn pee