Re: [strongSwan] VPN tunnel using TLS EAP is using wrong SCA cert

2018-11-16 Thread Tobias Brunner
Hi Anthony, > !!!Selected user cert is CN=TDY Test SCA 4 > 2018 Nov 14 00:35:36+00:00 wglng-17 charon [info] 06[CFG] certificate > \"C=US, O=Teledyne Controls Engineering, OU=Systems Engineering, CN=TDY Test > SCA 4\" key: 2048 bit RSA That's the server's certificate, selected to verify the

Re: [strongSwan] VPN tunnel using TLS EAP is using wrong SCA cert

2018-11-16 Thread Modster, Anthony
Hello Tobais We are using VICI (not from configuration files), so I hope were getting everything. For this setup are credential directory looks like this /media/sde1/certs/Org1: Org1.chain Org1.crt Org1.key Org1.sca1 Org1.ta /media/sde1/certs/Org2: Org2.chain Org2.crt Org2.key Org2.sca2

Re: [strongSwan] how to find initiator cookie in packet dump

2018-11-16 Thread Mirko Parthey
On Thu, Nov 08, 2018 at 10:47:18AM +0530, Yogesh Purohit wrote: >  I was trying to decrypt IKEv1 packets using wireshark 2.6. >  For decryption of Ikev1 one needs Initiator cookie and encryption key. I have > enabled log level for ike = 4 in strongswan.conf. > >  I can see complete dump in log

Re: [strongSwan] How to limit IKEv2 traffic per user?

2018-11-16 Thread Mirko Parthey
On Sat, Nov 10, 2018 at 11:17:36AM +, Houman wrote: > I have attempted to limit the VPN speed to 10Mbit per user.  But when I do a > DSL speed test with two devices simultaneously, it seems that the total > traffic > is limited to 10Mbit/s instead rather than each device having 10Mbit/s on >