Re: [strongSwan] nat traversal in ikev1 and ikev2

2009-11-13 Thread Andreas Steffen
/* > 寫道: > > > 寄件者: Andreas Steffen > 主旨: Re: [strongSwan] nat traversal in ikev1 and ikev2 > 收件者: "Jessie Liu" > 副本: users@lists.strongswan.org > 日期: 2009年11月13日,五,下午4:45 > > Hi Jessie, > > NAT traversal cannot be d

Re: [strongSwan] nat traversal in ikev1 and ikev2

2009-11-13 Thread Jessie Liu
Hi,    I do some tests with two computers connected directly.  IKE_AUTH message still sends through UDP/4500.  why will this happen? ... thanks. ^___^ --- 09/11/13 (五),Andreas Steffen 寫道: 寄件者: Andreas Steffen 主旨: Re: [strongSwan] nat traversal in ikev1 and ikev2 收件者: "Jessie Liu

Re: [strongSwan] nat traversal in ikev1 and ikev2

2009-11-13 Thread Andreas Steffen
Hi Jessie, NAT traversal cannot be disabled in the IKEv2 charon daemon. If you don't like automatic port floating to UDP/4500 due to the MOBIKE protocol (RFC 4555) which happens even if no NAT situation exists then you can disable MOBIKE by adding mobike=no to ipsec.conf in the connection defi

[strongSwan] nat traversal in ikev1 and ikev2

2009-11-13 Thread Jessie Liu
Hi all, I saw in ipsec.conf that nat_traversal configuration is only for IKEv1. why it is non-configured in IKEv2? it should be optional, right? if i want to disable nat traversal in ikev2, what should i do?   Thanks. ___ 您的生活即時通 - 溝通、娛樂、生