Re: [strongSwan] Resubmission as plaintext - Strongswan with ESP-NULL and ESP-NONE , NULL encryption and NONE integrity

2017-01-06 Thread Andreas Steffen
Hi, strongSwan does not support NULL-NONE. Configuration of a data integrity algorithm is mandatory. Best regards Andreas On 07.01.2017 04:14, ss admin wrote: I am running Strongswan Linux strongSwan U5.4.0/K2.6.32-358.el6.i686. I am trying to create a tunnel from a Cisco ASA 5520 8.4(7).

[strongSwan] Resubmission as plaintext - Strongswan with ESP-NULL and ESP-NONE , NULL encryption and NONE integrity

2017-01-06 Thread ss admin
I am running Strongswan Linux strongSwan U5.4.0/K2.6.32-358.el6.i686.  I am trying to create a tunnel from a Cisco ASA 5520 8.4(7).  I am trying to create a tunnel with the transform set ESP-NULL and ESP-NONE, essentially I am going for pure performance and do not want any encryption or

Re: [strongSwan] Questions about configuring SA lifetimes

2017-01-06 Thread Noel Kuntze
On 06.01.2017 19:02, Michael Wages wrote: > Thanks for the response. Do you know if I can differentiate between the > different SA timeouts. Like can I have each of the four I listed set to a > different lifetime? Read the article about expiry and replacement of IKE and IPsec SAs[1]. [1]