Re: [strongSwan] Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address

2018-06-26 Thread rajeev nohria
Hi Tobias, Which parameter to configure the specific remote IP address for a connection, so that we can reject the messages from any other IP address? I am assuming we are talking about one of parameter in swanctl.conf. If we are talking about connections..remote_addrs.. I did configure

Re: [strongSwan] Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address

2018-05-23 Thread Tobias Brunner
Hi Rajeev, > I would > imagine it should be rejected. Why? Unless you configure specific remote IP addresses for a connection there is no reason to reject messages from any IPs. Regards, Tobias

Re: [strongSwan] Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address

2018-05-22 Thread rajeev nohria
:cada:c406::200[C=US, O=CableLabs, CN=00:01:5c:96:16:00] 15[IKE] scheduling rekeying in 13604s 15[IKE] maximum IKE_SA lifetime 15044s On Tue, May 22, 2018 at 9:08 AM, Tobias Brunner <tob...@strongswan.org> wrote: > Hi Rajeev, > > > Is there way to Stronswan to ignore IKE-SA-INIT response from a bogus > > IPv6 address? Strongswan replies to all the IKE-SA-INIT receive from all > > IP addresses. > > Use iptables. > > Regards, > Tobias >

Re: [strongSwan] Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address

2018-05-22 Thread Tobias Brunner
Hi Rajeev, > Is there way to Stronswan to ignore IKE-SA-INIT response from a bogus > IPv6 address? Strongswan replies to all the IKE-SA-INIT receive from all > IP addresses.  Use iptables. Regards, Tobias

[strongSwan] Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address

2018-05-22 Thread rajeev nohria
I use Davici Interface with Strongswan 5.5 Is there way to Stronswan to ignore IKE-SA-INIT response from a bogus IPv6 address? Strongswan replies to all the IKE-SA-INIT receive from all IP addresses. thanks, Rajeev