Re: [strongSwan] Throughput on high BDP networks

2015-06-03 Thread John A. Sullivan III
On Tue, 2015-06-02 at 22:23 -0400, jsulli...@opensourcedevel.com wrote: On June 1, 2015 at 11:48 AM Martin Willi mar...@strongswan.org wrote: Even at these rates, the CPU did not appear to be very busy. We had one at 85% occupied but that was the one running nuttcp. On the

[strongSwan] Perform action on crash?

2015-06-03 Thread Ruel, Ryan
I noticed that within starter, if charon happens to crash, starter will spawn a new charon. Is there any configuration options already existing in strongSwan to perform some action if a crash is detected? Ideally, I’d like for my server to send a crash e-mail. Regards, /Ryan

Re: [strongSwan] Throughput on high BDP networks

2015-06-03 Thread John A. Sullivan III
On Wed, 2015-06-03 at 15:51 -0400, John A. Sullivan III wrote: On Tue, 2015-06-02 at 22:23 -0400, jsulli...@opensourcedevel.com wrote: On June 1, 2015 at 11:48 AM Martin Willi mar...@strongswan.org wrote: Even at these rates, the CPU did not appear to be very busy. We had one

[strongSwan] Getting Authentication Failure with swanctl tool using strongswan-5.2.2

2015-06-03 Thread Chinmaya Dwibedy
  Hi,I am usingthe swanctl (command line interface) tool to configure the Charon daemon at IKEResponder. I have kept all the entries of  ipsec.conf and ipsec.secret file ( in /etcdirectory)  under comment. Here goes theconfiguration. /etc/ipsec.secrets(IKE Responder end):

Re: [strongSwan] Query regarding ipsec pool

2015-06-03 Thread Tobias Brunner
Hi Divya, Is 'offline' applicable only when timeout is 0? No, if timeout is 0 dynamic leases are disabled and every lease will have the status 'static'. The status 'offline' does not really exist, instead 'valid is the status of a lease that the client is currently not using (which would be

[strongSwan] Query regarding ipsec pool

2015-06-03 Thread divya mohan
Hi, I'm using strongswan IKEv2 configuration for DB (sqlite3) based server side virtual IP. I am using pool utility for managing the virtual IPs. From the documentation given at https://wiki.strongswan.org/projects/strongswan/wiki/Ipsecpool, I'm not clear on what the status means. Could you

Re: [strongSwan] Getting Authentication Failure with swanctl tool using strongswan-5.2.2

2015-06-03 Thread Noel Kuntze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello Chinmaya, That is because the secret argument of the IKE section is the PSK. You need to put the ID of the remote side in the id argument. Mit freundlichen Grüßen/Kind Regards, Noel Kuntze GPG Key ID: 0x63EC6658 Fingerprint: 23CA BB60

[strongSwan] left|rightauth in sql

2015-06-03 Thread Michael C. Cambria
Hi, How does one set both leftauth=pubkey and rightauth=pubkey using sql? The peer_configs table [0] is the only place I see something close. The table has auth_method, which defaults to 1. According to [1] this is AUTH_CLASS_PUBKEY The problem is that ipsec statusall shows the remove as