Re: [strongSwan] AWS VPN to Cisco Unity

2020-04-30 Thread Jeff Puro
I have an issue with a pretty standard setup using Strongswan, wherein the tunnel comes up properly but the traffic to the actual server is never marked for ESP and thus never seems to get onto the tunnel. I've confirmed that I do not see any traffic for esp using tcpdump, and when I do a

[strongSwan] Fwd: duplicate IPSec SAs

2018-01-15 Thread Jeff
Andreas, Per Noel Kuntze's suggestion, I added charon.make_before_break=yes to both the initiator and responder. However I still accumulated duplicate IPSsec child SAs. Can you offer insight how I may fix this issue? thanks, Jeff Weber Forwarded Message Subject

[strongSwan] duplicate IPSec SAs

2018-01-02 Thread Jeff
ation of connections..unique and charon.make_before_break settings will fix my issue. Currently I am using the default values for each. Advice on a config change to fix duplicate IPSec SAs is requested. thanks, Jeff # common charon.conf file # Options for the charon IKE daemon. ch

[strongSwan] duplicate IPsec SAs

2017-12-19 Thread Jeff
k will fix my issue. Advice on config change is requested. thanks, Jeff initiator-strongswan.conf Description: Binary data initiator-swanctl.conf Description: Binary data responder-strongswan.conf Description: Binary data responder-swanctl.conf Description: Binary data

[strongSwan] strongSwan consulting

2017-11-20 Thread Jeff
Does the strongSwan project still provide consulting services? I have been unable to reach the posted consulting contact andreas.stef...@strongswan.org . thanks, Jeff

[strongSwan] always up VPN config

2017-11-09 Thread Jeff
responder: dpd_action=clear dpd_delay=60s Initial testing shows this works without a separate initiator "ping" process, which is attractive, but I'm sure there are many corner cases I have not considered. Will the above config create and maintain a stable VPN? thanks, Jeff

[strongSwan] kernel trap does not bring up VPN

2017-11-06 Thread Jeff
onf. I am looking for guidance crafting an initiator swanct.conf to automatically bring up the VPN for this situation. thanks, Jeff syslog-strongswan Description: Binary data swanctl.conf Description: Binary data

Re: [strongSwan] Enabling AES-NI in strongswan

2016-06-20 Thread Jeff Leung
bc for your reference. > kapil : can you point me to > > > On Mon, Jun 20, 2016 at 12:31 PM, Jeff Leung <jle...@v10networks.ca> > wrote: > > > > Hi, > > > > i am looking for ways to improve the throughput while using the >

Re: [strongSwan] Enabling AES-NI in strongswan

2016-06-20 Thread Jeff Leung
> Hi, > > i am looking for ways to improve the throughput while using the > strongswan IPSEC. > > I read that AES-GCM provides excellent throughput over default > AES-CBC- > 128 when used with AES-NI support in intel processors. > > > i want to enable AES-GCM128 cipher in my xeon E5

Re: [strongSwan] Strongswan using VTI - got it working!

2015-03-08 Thread Jeff Leung
Sorry to bring this topic up again, but here it goes... Alright, there seems to be issues with strongSwan 5.2 on the way how it sets up a Cisco VTI tunnel. I was able to get a working VTI tunnel established between 2 VyOS 1.1 machines that has strongSwan 4.5.2 bundled. The kernel version

Re: [strongSwan] Strongswan using VTI - got it working!

2015-03-08 Thread Jeff Leung
One thing to note in particular in both cases - VyOS does not delete the default route in table 220 as generated by strongSwan. I suspect for some reason the way how the VTI tunnels are configured is causing the network stack not to redirect marked packets to the VTI tunnel interface. To

[strongSwan] Issues establishing multiple IKEv1 Site-to-Site Tunnels to the same peer

2015-02-12 Thread Jeff Leung
to successfully establish multiple IKEv1 tunnels to the same peer. Were there changes from the days when pluto that is now considered as incompatible with strongSwan? -- Jeff ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman

[strongSwan] Is Centos 4.7 a viable distro for Strongswan?

2009-06-11 Thread Jeff Wild
iptables v1.4.3.2 Jeff ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

[strongSwan] Help ! Tunnel traffic problem protocol 50 unreachable

2009-05-04 Thread Jeff Wild
MR3, ISAKMP SA established); EVENT_SA_REPLACE in 214s Jeff Wild wild...@hotmail.com ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

[strongSwan] ping across tunnel but no other data

2009-04-30 Thread Jeff Wild
established); EVENT_SA_REPLACE in 214s Jeff Wild wild...@hotmail.com Jeff Wild Wild Information Systems LLC 2010 W. 131st place Westminster, CO 80234 303-514-9702 cell 303-562-0388 wk jeff.w...@wildinfosystems.com ___ Users mailing

[strongSwan] can ping across tunnel but no other data

2009-04-28 Thread Jeff Wild
owner 000 #5: net-net esp.8559b...@x0.x7.x6.25 (1224 bytes, 46s ago) esp.506b0...@x0.x7.x6.27 (954 bytes, 46s ago); tunnel 000 #1: net-net STATE_MAIN_R3 (sent MR3, ISAKMP SA established); EVENT_SA_REPLACE in 214s Jeff Wild wild...@hotmail.com ___ Users