[strongSwan] auto=route makes local iOS DHCP fail

2015-03-06 Thread Zesen Qian
Hello list, I set auto=route in a site-to-site tunnel, to keep the tunnel alive, which makes an iOS in local net cannot get IP via DHCP. ipsec.conf: https://bpaste.net/show/218b4db1df8b 0.DHCP client on PC(dhclient) works fine. 1.I can close the tunnel temporarily to let iOS get IP, and then re-es

[strongSwan] StrongSwan support for IPsec pre-fragmentation

2015-03-06 Thread Harry Chan-Maestas
Hi, I am a new StrongSwan user, having switched recently from racoon, and I have a question about IPsec packet fragmentation. In racoon, there is a configuration option "esp_frag". When enabled, racoon will set IPsec to fragment jumbo frames before ESP is applied. I have been look through StrongS

Re: [strongSwan] [strongSwan-dev] need for calling TASK_IKE_CONFIG before TASK_CHILD_CREATE in task_manager_v2.c

2015-03-06 Thread Ravi Kanth Vanapalli
Dear Martin, In case of Strongswan Android Market App, the IP address assignment, MTU setting to the ipsec0 interface is handled Android framework VPN JNI module.This will be after the IKE_SA and Child_SA is setup. Could you please give more details, how the configuration setup happens in the S

Re: [strongSwan] Charon reset

2015-03-06 Thread Martin Willi
Hi Ken, > 09[DMN] thread 9 received 11 > 09[LIB] dumping 2 stack frame addresses: > 09[LIB] /lib64/libpthread.so.0 @ 0x7fb8fd3ab000 [0x7fb8fd3ba710] > 09[LIB] -> sigaction.c:0 > 09[LIB] /lib64/libc.so.6 @ 0x7fb8fce13000 [0x7fb8fd1a2ed8] > 09[LIB] -> interp.c:0 > 09[DMN] killing oursel