[strongSwan] Strongswan: Disabling repeated authentication for ikev2.

2009-06-09 Thread Balaji J
Hi ppl, Is there any way to configure strongswan for disabling the repeated authentication notify payload(rfc4478) it sends with IKE_AUTH reply? Basically, i want to disable the repeated authentication in strongswan. Is it possible? Thanks in advance. Regards, ...Balaji.J ___

Re: [strongSwan] Newbie Question... IP ROUTES

2009-06-09 Thread Daniel Mentz
Michael Camino wrote: > When i run a tracert from 10.0.3.1 to 10.0.2.1 it appears the traffic is > going out my router interface instead over the vpn interface. First of all there's no such thing as a VPN interface. There used to be one with KLIPS but with Linux 2.6 and the native IPsec stack pa

Re: [strongSwan] Notification message 40501 connecting to Cisco router

2009-06-09 Thread Andreas Steffen
Hi Rod, no, strongSwan hasn't been tested with Cisco load balancing and does not recognize the 40501 notification. Probably Cisco wants to redirect the IPsec SA to an alternative VPN gateway. Best regards Andreas rriver...@verizon.net wrote: > Hi, > > This is my first post to this forum. I

[strongSwan] Notification message 40501 connecting to Cisco router

2009-06-09 Thread rrivers_2
Hi, This is my first post to this forum. I would like to thank everyone that has worked on this project. I have been using strongSwan in a road warrior configuration to connect to Cisco routers. I have been able to do this with several customers but recently when I tried to connect to a new

[strongSwan] Newbie Question... IP ROUTES

2009-06-09 Thread Michael Camino
Hello, I am a relative newbie with strongswan but i have sucessfully gotten it installed and working on my CENTOS Linux Box. I am having a weird issue but I am sure it will be a quick fix when someone points me in the right direction. First a brief layout... Server 1(10.0.2.3)>10.0.2.0/24 n

[strongSwan] Notification message 40501 connecting to Cisco router

2009-06-09 Thread rrivers_2
___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

[strongSwan] Choise of CA

2009-06-09 Thread J.Witvliet
Hi all, Excuse if my question is slightly off-topic But as we all need a "CA/RA/OCSP" in some sort of degree, I'm interested in what CA people have chosen. Afaics, CA's can be split-up in roughly three sections: 1) elementary CA's, Like the commandline tools from openSSL, tinyCA, pyCA 2) Ra