Re: [strongSwan] Header verification failed and NAT mapping changed

2012-03-20 Thread Kim Zeitler
Hi Tobias, I forgot about this yesterday, but this was actually a bug in 4.5.0. While charon detects that it is behind a NAT, and properly responds to requests, it does not update the port internally and still uses port 500 for its own requests and for installing the SA in the kernel.

[strongSwan] Header verification failed and NAT mapping changed

2012-03-19 Thread Kim Zeitler
Thank you for any help and pointers. Kim Zeitler ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

Re: [strongSwan] Header verification failed and NAT mapping changed

2012-03-19 Thread Kim Zeitler
Hi Tobias, Very strange. Due to the NAT this packet should actually be sent from port 4500 to port 4500. The complete log of moon (and sun) would help to see whether there is something wrong with the NAT detection etc. Here are excerpts of the two log files. I tried to get similar time

Re: [strongSwan] VPN from iPad to ubuntu-10.4

2011-06-22 Thread Kim Zeitler
Hello Andreas, I tried to use the iPad's pure-IPsec configuration, and no ESP packets were seen. So I concluded that with L2TP-over-IPsec I was one step more close to the goal ;-) from your mail I see that you tried to use a 'pure' ipsec connection. In my experience L2TP is to much hazzle

[strongSwan] Site-To-Site becomes unreasonable slow within 12h of running

2011-06-21 Thread Kim Zeitler
Hello, as our company has expanded lately we introduced strogSwan to our infrastructure to allow both Windows7 Roadwarriors and Site-to-Site connections. The RW Setup works like a charm and gives us no trouble at all. But out Site-to-Site setup shows some strange behaviour. This 'strange'