Re: [strongSwan] VPN connection loss problem

2014-10-11 Thread Andreas Steffen
. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Phase 2: our client ID returned doesn't match my proposal betweetn two StrongSwans

2014-10-08 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] preloading client certificates

2014-10-03 Thread Andreas Steffen
the responder send a copy of that cert. Why is that? The certificate request is not for a copy of the root CA but for a certificate *issued* by the requested root CA. Regards Andreas == Andreas Steffen

Re: [strongSwan] preloading client certificates

2014-10-02 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] StrongSwan as IKEv2 VPN client with EAP-TLS

2014-09-27 Thread Andreas Steffen
but it is enforced on the server side. Is there a way to do what I am trying to do? Thanks in advance. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution

Re: [strongSwan] Intermediate CAs unknown to peer?

2014-09-25 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] Colliding subnets, NETMAP and charon/pluto

2014-09-14 Thread Andreas Steffen
@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users -- == Andreas

Re: [strongSwan] Regarding Key Generation in strongswan 4.2.8

2014-09-07 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640

Re: [strongSwan] [strongswan-5.1.1] Unable to establish tunnel using two level certificate Authentication

2014-09-03 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Issue with DES Encryption Algorithm

2014-08-21 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640

Re: [strongSwan] Issue with DES Encryption Algorithm

2014-08-21 Thread Andreas Steffen
tester plugin . ^^^ from what I see, this plugin has never supported DES. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org

Re: [strongSwan] [Strongswan] no config named 'client'

2014-08-18 Thread Andreas Steffen
to do now, I really need your help, any one could help me? Thank you very much == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org

Re: [strongSwan] [Strongswan] no config named 'client'

2014-08-18 Thread Andreas Steffen
to uninstall strongswan? Thanks for your help 2014-08-19 12:36 GMT+08:00 Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef...@strongswan.org: Hello Amysue, you have to build strongSwan with ./configure --sysconfdir=/etc Regards Andreas

Re: [strongSwan] Sizing information

2014-07-17 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

[strongSwan] ANNOUNCE: strongswan-5.2.0 released

2014-07-10 Thread Andreas Steffen
://wiki.strongswan.org/versions/52 Best regards Tobias Brunner, Martin Willi, Andreas Steffen The strongSwan Team == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution

Re: [strongSwan] Android VPN

2014-06-30 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640

[strongSwan] ANNOUNCE: strongswan-5.2.0rc1 released

2014-06-29 Thread Andreas Steffen
problems that you may encounter. Best regards Tobias Brunner, Martin Will Andreas Steffen The strongSwan Team == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution

Re: [strongSwan] Query for derivation of MSk key in EAP-MSCHAPv2

2014-06-18 Thread Andreas Steffen
wrote: Hi, Need some info on MSK key derivation when strongswan uses EAP-MSCHAPv2 when used in Ikev2. Any pointer or info will be helpful.. Thanks Mukesh == Andreas Steffen andreas.stef

Re: [strongSwan] ipsec attest adding aik at attestation server

2014-06-11 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] DN-based ID not confirmed by Certificate

2014-05-31 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] Error with EAP-PEAP connection

2014-05-12 Thread Andreas Steffen
/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied

Re: [strongSwan] Problem with 4in6 and 6in4 ipsec tunnel

2014-04-26 Thread Andreas Steffen
, Rakesh Bansod == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University

Re: [strongSwan] Issues when loading rsa private key

2014-04-05 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] charon not sending DELETE payload

2014-04-02 Thread Andreas Steffen
/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications

Re: [strongSwan] charon not sending DELETE payload

2014-04-02 Thread Andreas Steffen
Andreas Steffen [mailto:andreas.stef...@strongswan.org] Sent: Wednesday, April 02, 2014 1:00 PM To: Gupta, Rohan 1. (NSN - IN/Bangalore); users@lists.strongswan.org Subject: Re: [strongSwan] charon not sending DELETE payload Hi Gupta, if you are using the setkey command which is part of the ipsec

Re: [strongSwan] SHA-256 for IKE_AUTH (IKEv2) ?

2014-03-31 Thread Andreas Steffen
for which the RFC 3447 includes SHA-256. Best Regards Mugur == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet

Re: [strongSwan] dhcp plugin: mac address unpredictable?

2014-03-19 Thread Andreas Steffen
, and charon doesn't tell, either. (Maybe I am too blind to see?) Would it be possible to hardwire the mac address in the certificate? Every helpful response is highly appreciated Harri == Andreas Steffen

Re: [strongSwan] Unable to establish ipsec tunnel using certs of intermediate CA's

2014-03-04 Thread Andreas Steffen
in this regard is appreciated. Regards, Sriram. ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users -- == Andreas Steffen

Re: [strongSwan] Unable to establish ipsec tunnel using certs of intermediate CA's

2014-03-04 Thread Andreas Steffen
:3b:c8:a4:62:b3:06:61:7e:9a:c0 authkey: c3:59:68:a5:73:e8:b8:76:45:06:3b:c8:a4:62:b3:06:61:7e:9a:c0 Regards, Sriram. On Tue, Mar 4, 2014 at 6:49 PM, Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef...@strongswan.org wrote: Hi Sriram, could you post the output

[strongSwan] ANNOUNCE: strongswan-5.1.2 released

2014-03-03 Thread Andreas Steffen
our blog entry http://www.strongswan.org/blog/2014/03/03/strongswan-5.1.2-released.html Best regards Tobias Brunner, Martin Willi, Andreas Steffen The strongSwan Team! == Andreas Steffen andreas.stef

Re: [strongSwan] issue with modpnull Diffie-Hellman group

2014-02-27 Thread Andreas Steffen
inacceptable 13[ENC] 1 generating IKE_SA_INIT response 0 [ N(NO_PROP) ] 13[NET] 1 sending packet: from 30.30.30.21[500] to 30.30.30.11[500] (36 bytes) Regards, Chinmaya == Andreas Steffen andreas.stef

Re: [strongSwan] NO_PROPOSAL_CHOSEN when connect with Fritzbox

2014-02-12 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Tunnel setup rate is slower with ECDH (openssl) than MODP (gmp) using strongswan (5.0.4) and load tester plugin

2014-02-04 Thread Andreas Steffen
tunnels per second. What I understand, the ECDH is faster than MODP. Can anyone please suggest me if I am missing anything?. Thanking you in advance for your support and help. Regards, Chinmaya == Andreas Steffen

Re: [strongSwan] NO_PROPOSAL_CHOSEN with android app

2014-02-03 Thread Andreas Steffen
configuration. Best Mohsen == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University

Re: [strongSwan] IPv4 lan in IKEv1 IPv6 tunnel

2013-12-21 Thread Andreas Steffen
lefthostaccess=yes right=%any6 rightsourceip=10.10.10.0/24 rightauth=pubkey keyexchange=ikev1 Config mode is not activated. Thanks for any help. Regards. == Andreas Steffen

Re: [strongSwan] Cannot open strongswan.org ?

2013-12-16 Thread Andreas Steffen
. If cannot open strongswan.org now ? == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies

Re: [strongSwan] Help with Strongswan crosscompile (Ubuntu - Synology)

2013-11-19 Thread Andreas Steffen
? ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org

Re: [strongSwan] strongSwan - Juniper/Cisco IKEv1 interoperability

2013-11-12 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH

[strongSwan] ANNOUNCE: strongswan-5.1.1rc1 released

2013-10-28 Thread Andreas Steffen
complete printf functions. Please test the release candidate and give feedback if you are running into any problems. ETA for the stable 5.1.1 release is November 1, 2013. Cheers Andreas Steffen, Tobias Brunner Martin Willi The strongSwan Team

Re: [strongSwan] IPSec -Charon versus Pluto

2013-10-18 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] Strongswan - Openswan

2013-10-16 Thread Andreas Steffen
it be any consideration to do that or it is a straight forward task? Thanks, Farid == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org

Re: [strongSwan] regarding adding connections

2013-10-11 Thread Andreas Steffen
of my questions are answered before. this time its urgent, please thank you, Rakesh == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution

Re: [strongSwan] virtual ip

2013-09-14 Thread Andreas Steffen
packet: from 10.73.127.45[4500] to 10.43.135.221[4500] /**/ Thanks Naveen == Andreas Steffen andreas.stef...@strongswan.org

Re: [strongSwan] unable to load plugin eap-ttls

2013-09-13 Thread Andreas Steffen
? ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

Re: [strongSwan] charon has unmet dependency: NONCE_GEN

2013-08-17 Thread Andreas Steffen
--enable-attr-sql --enable-sql --enable-eap-gtc Thanks, Karl == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet

Re: [strongSwan] Error using pki in StrongSwan 5.1.0

2013-08-10 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil

Re: [strongSwan] Bypassing traffic to local LAN

2013-08-10 Thread Andreas Steffen
three years so I am wondering if there is a better way, now with version 5.1.0 and charon, to achieve this? Thanks, Jiehan == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open

Re: [strongSwan] Static IP addresses to roadwarriors

2013-08-07 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

[strongSwan] ANNOUNCE: strongSwan 5.1.0 released including fix for CVE-2013-5018

2013-08-07 Thread Andreas Steffen
inconveniences. Best regards Tobias Brunner, Martin Willi, Andreas Steffen The strongSwan Team == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution

Re: [strongSwan] strongswan android app fails to connect when cert SAN contains DNS

2013-08-07 Thread Andreas Steffen
check failed: identity xyz.mycompany.com required selected peer config android inacceptable: constaint check failed regards, -smk == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux

[strongSwan] ANNOUNCE: strongswan-5.1.0rc1 released

2013-07-22 Thread Andreas Steffen
and report any issues. ETA for the stable 5.1.0 release is approximately the end of July. Best regards Tobias Brunner, Martin Willi, Andreas Steffen The strongSwan Team == Andreas Steffen andreas.stef

Re: [strongSwan] FW: Win7 machine certificate connection failing

2013-07-20 Thread Andreas Steffen
=add include /var/lib/strongswan/ipsec.conf.inc == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies

Re: [strongSwan] Strongswan failed to see the revoked certificate

2013-07-17 Thread Andreas Steffen
://lists.strongswan.org/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies

Re: [strongSwan] understanding %fromcert

2013-07-15 Thread Andreas Steffen
, if there is both a DN and one or more subjectAltName values, how does it choose which one to send? Will it try them all? Regards, Daniel == Andreas Steffen andreas.stef...@strongswan.org strongSwan

Re: [strongSwan] understanding %fromcert

2013-07-15 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Force UDP Encapsulation in 5.0.4?

2013-07-07 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Force UDP Encapsulation in 5.0.4?

2013-07-07 Thread Andreas Steffen
for IKEv2 prior to 5.0.0. I hope that is just a typo and it is fully supported in 5.0 going forward. Amazon does not route ESP packets so this is the only way to do transport mode in the same data center. Thanks for the help, Dan On Sun, Jul 7, 2013 at 8:58 PM, Andreas Steffen andreas.stef

Re: [strongSwan] Strongswan freeze

2013-07-04 Thread Andreas Steffen
with SPI cc84aaa8 and reqid {1156} Joshua J. Gross == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux

Re: [strongSwan] Setup client using main mode/draft-ietf-ipsec-nat-t-ike-02

2013-06-17 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH

Re: [strongSwan] CRL check and certificates extensions

2013-06-10 Thread Andreas Steffen
-eole.ac-dijon.fr == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied

Re: [strongSwan] loading private key file is failing with charon, when trying to establish IPsec tunnel with certifiactes.

2013-06-03 Thread Andreas Steffen
-netlink': loaded successfully -Bhargav On Sat, Jun 1, 2013 at 3:17 AM, Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef...@strongswan.org wrote: Hi Bhargav, The private key that you are trying to load is a PKCS#8 file, a format being used by openssl 1

Re: [strongSwan] loading private key file is failing with charon, when trying to establish IPsec tunnel with certifiactes.

2013-06-03 Thread Andreas Steffen
. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] Android client fails to connect with allocating SPI failed: Invalid argument (22)

2013-05-30 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH

Re: [strongSwan] Issues with loading imv-os and imv-attestation modules with Freeradius

2013-05-24 Thread Andreas Steffen
/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Open Source VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications

Re: [strongSwan] DES in Strongswan

2013-05-07 Thread Andreas Steffen
# ipsec listalgs, we can see the DES in the list! So my questiion is WHY? # ipsec listalgs 000 List of registered ESP Algorithms: 000 000 encryption: DES_CBC 3DES_CBC CAST_CBC BLOWFISH_CBC NULL AES_CBC == Andreas Steffen

Re: [strongSwan] No matching peer config w/ Secret and NAT-T

2013-05-07 Thread Andreas Steffen
-- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

Re: [strongSwan] Strongswan with freeradius on Debian server

2013-04-30 Thread Andreas Steffen
Login incorrect. Is there a way to make it work with an ldap authentication ? Ldap plugins is loaded on my strongswan server. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN

Re: [strongSwan] CISCO UDP encapsulation

2013-04-26 Thread Andreas Steffen
Why should we? Andreas On 04/26/2013 11:16 PM, Noel Kuntze wrote: Hello, Is it planned to add support for CISCO's proprietary UDP encapsulation? Regards, Noel == Andreas Steffen andreas.stef

Re: [strongSwan] Strongswan with freeradius on Debian server

2013-04-25 Thread Andreas Steffen
rightrsasigkey=%cert auto=add Could anyone tell me where the password must be set ? Or is there a way to force my server asking for user's credentials each time ? Thanks for you help. -- == Andreas

Re: [strongSwan] Strongswan with freeradius on Debian server

2013-04-25 Thread Andreas Steffen
of TLS (-1), TLS session fails. Thu Apr 25 12:11:27 2013 : Auth: Login incorrect (TLS Alert read:fatal:certificate unknown): [login] (from client serv-tests port 9 cli 192.168.110.65[4500]) == Andreas Steffen

Re: [strongSwan] libipsec vs kernel implementation

2013-04-22 Thread Andreas Steffen
to it or something? Regards, Noel == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University

Re: [strongSwan] Android config file location

2013-04-22 Thread Andreas Steffen
limits me to. Thanks, John == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications

Re: [strongSwan] Help (dh Algorithms) ecp_192, ecp_224, ecp_256, ecp_384 and ecp_521

2013-04-20 Thread Andreas Steffen
algorithms using strongswan but i didn't find these algorithms : ecp_192,ecp_224,ecp_256,ecp_384 and ecp_521 please, i want to know if the strongswan supports it or no, if yes how can i use it? == Andreas Steffen

Re: [strongSwan] no virtual IP found for %any requested

2013-04-14 Thread Andreas Steffen
___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users -- == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN

Re: [strongSwan] keep tunnel alive

2013-04-08 Thread Andreas Steffen
, Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef...@strongswan.org wrote: It seems as if you didn't have a CHILD_SA in the first place. Didn't the IKE negotiation complete successfully or did the peer delete the CHILD_SA because of inactivity (e.g. Windows clients

Re: [strongSwan] How can I allow only specific IP use PSK auth?

2013-04-06 Thread Andreas Steffen
? == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil

[strongSwan] ANNOUNCE: strongswan-5.0.3 released

2013-04-06 Thread Andreas Steffen
regards Tobias Brunner, Andreas Steffen, Martin Willi Reto Bürki, Reto Guadagnini, Adrian Rüegsegger The extended strongSwan Team == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux

Re: [strongSwan] CRL caching

2013-04-06 Thread Andreas Steffen
CRL is stale or not. If a CA revokes a certificate immediately after successful CRL fetch, how long does it take for Strongswan to make the Certificate stale . How can such problems be avoided? Thanks! Jordan. On Thu, Apr 4, 2013 at 9:08 PM, Andreas Steffen andreas.stef

Re: [strongSwan] keep tunnel alive

2013-04-06 Thread Andreas Steffen
: Hi, What can I do on strongswan to keep a tunnel alive even if there's no traffic flowing ? I've dpdaction set to restart. What else can be done ? Regards, == Andreas Steffen

Re: [strongSwan] Weird NAT IP as username.

2013-04-06 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640

Re: [strongSwan] Weird NAT IP as username.

2013-04-06 Thread Andreas Steffen
logs with username '192.168.3.254' in my Radius accounting DB, so I worry about it should be the correct username, or not, user's traffic accounting may be not accurate. -- Kris On Sat, Apr 6, 2013 at 10:43 PM, Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef

Re: [strongSwan] Strongswan needs periodic restart to re-enable traffic between sites

2013-04-04 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] CRL caching

2013-04-04 Thread Andreas Steffen
./ / == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH

Re: [strongSwan] Authentication of a CERT payload with only the subject certificate

2013-03-26 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH

Re: [strongSwan] Configure RoadWarrior

2013-03-26 Thread Andreas Steffen
-optimal RAID status == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University

[strongSwan] ANNOUNCE: strongswan-5.0.3rc1 released

2013-03-26 Thread Andreas Steffen
IKE packets. ikedscp = 00 | DSCP field Please test our release candidate and report any problems. ETA for the stable 5.0.3 release is end of March 2013. Kind regards Andreas == Andreas Steffen

Re: [strongSwan] use of libgmp

2013-03-19 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland

Re: [strongSwan] Unable to use Certificate Path Chain (SUBCAs)

2013-03-09 Thread Andreas Steffen
9 17:28:43 charon: 09[NET] sending packet: from 192.168.20.126[500] to 192.168.20.112[500] (76 bytes)/ Regards, Rashid == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN

Re: [strongSwan] [strongSwan-dev] strongswan performance

2013-03-06 Thread Andreas Steffen
://www.strongswan.org/docs/Steffen_Klassert_Parallelizing_IPsec.pdf == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet

Re: [strongSwan] strongswan+freeradius+debian consultation

2013-03-02 Thread Andreas Steffen
actual configuration? in positive case ¿ is there another way to add the eap-radius plugin? thanks in advance. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

Re: [strongSwan] Error no IKE config found when trying to connect a roadwarrior

2013-02-23 Thread Andreas Steffen
error when I try to connect with an iPhone or the GreenBow VPN client, so I guess there must be something wrong on the server side. How can I fix this? What else can I test? Lars == Andreas Steffen

Re: [strongSwan] crlcheckinterval in charon

2013-02-08 Thread Andreas Steffen
? If that exists then I could just have a cron which periodically tells charon to re-check it. Thanks. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

Re: [strongSwan] strongSwan 5.0.1 AH ?

2013-02-04 Thread Andreas Steffen
. == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences

Re: [strongSwan] PF_KEY with IPv4+IPv6 in charon

2013-01-28 Thread Andreas Steffen
PF_KEY messages in IPv4+IPv6 environment? It doesnot work on my setup, although IPv4 or IPv6 works just fine. Thanks, Jay == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

[strongSwan] ANNOUNCE: strongswan-5.0.2rc1 released

2013-01-20 Thread Andreas Steffen
source using the Intel rdrand instruction found on Ivy Bridge processors. Enjoy the release candidate and please report back any issues encountered so that we can fix them before the final release. Best regards Andreas == Andreas

Re: [strongSwan] Strongswan OpenVPN client

2013-01-07 Thread Andreas Steffen
] IKE_SA deleted I/charon (17492): 00[LIB] intentionally leaking private key reference due to a bug in the framework == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

Re: [strongSwan] Timeout Errors using Network Manager on Ubuntu 12.10

2013-01-07 Thread Andreas Steffen
== Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences

Re: [strongSwan] Compilation failure for android frond end

2013-01-02 Thread Andreas Steffen
/plugins/openssl/openssl_pkcs7.c:24:25: fatal error: openssl/cms.h: No such file or directory. Any idea? Thanks Andy == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution

Re: [strongSwan] Compilation failure for android frond end

2013-01-02 Thread Andreas Steffen
this? Thanks Andy On Thu, Jan 3, 2013 at 9:30 AM, Andreas Steffen andreas.stef...@strongswan.org mailto:andreas.stef...@strongswan.org wrote: Hello Andy, our instructions recommend to get the openssl code and header files from our repository: The openssl Directory

Re: [strongSwan] Help with Strongswan configuration (Virtual-IP, Subnet, DNS, ...) needed

2012-12-23 Thread Andreas Steffen
if necessary. Do you have an idea if there is some wrong configuration on my side? == Andreas Steffen andreas.stef...@strongswan.org strongSwan - the Linux VPN Solution!www.strongswan.org

<    1   2   3   4   5   6   7   8   9   10   >