Re: [strongSwan] IPSec route based VPN - VTI interface TX Errors NoRoute

2021-09-02 Thread Tiago Stoco
Hi Noel, So you're running openwrt on an Arch Linux kernel? No, I am running a pure Arch Linux virtual machine. Although, I have another VM with OpenWRT in my lab. Originally OpenWRT was being used but because NFLOG was not working and I needed packets flowing through the iptables captured to f

Re: [strongSwan] IPSec route based VPN - VTI interface TX Errors NoRoute

2021-09-02 Thread Noel Kuntze
Hello Tiago, > Linux 5.13.12-arch1-1 So you're running openwrt on an Arch Linux kernel? > According to my understanding, the reply should be marked, dealt with the IPSec stack, and tunneled to the peer since it is on the VTI interface. Please correct me if I am wrong. Please pastebin the out

Re: [strongSwan] strongswan no shared key found

2021-09-02 Thread Tobias Brunner
Hi, [ENC] generating QUICK_MODE request 925866246 [ HASH SA No ID ID ] [NET] sending packet: from locip[500] to ipsecip[500] (172 bytes) [NET] received packet: from ipsecip[500] to locip[500] (108 bytes) [ENC] parsed INFORMATIONAL_V1 request 3675363864 [ HASH N((24576)) ] [IKE] received (24576)