Re: [strongSwan] strongswan-5.1.x, NATed routing pb

2014-03-19 Thread Volker RĂ¼melin
Hi Serge, I am running our of ideas of what could be checked further and how to fix it. The setup was perfectly working under strongswan 4.3 and works well for other connections and even with the Win8 roadwarrior (behind the NAT). Could you go throught once again through the logs and probably

[strongSwan] ipcomp stats

2014-03-19 Thread Raoul Duke
Hi, I would like to see stats on what value-add users are getting from ipcomp. Currently "ipsec statusall" returns me the bytes_in and bytes_out per user. When ipcomp is in play - are these stats before or after compression? Would it be feasible to add stats (byte counters) for the other (before

Re: [strongSwan] dhcp plugin: mac address unpredictable?

2014-03-19 Thread Andreas Steffen
Hi Harri, the MAC address does not change if the new certificate has the same subjectDistinguishedName or subjectAlternativeName chosen as the IKEv2 ID. As an alternative you could explicitly register the client IKEv2 ID as a dhcp-client-identifier attribute with your DHCP server as in the follow

[strongSwan] dhcp plugin: mac address unpredictable?

2014-03-19 Thread Harald Dunkel
Hi folks, I have to restrict the IP address pool of my DHCP server to known MAC addresses only. In this context I have 2 questions about the dhcp plugin (using identity_lease = yes): Wiki says, the mac address is derived from the "IKEv2 identity". Does this mean the mac address changes, if I rene