Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic

2018-03-13 Thread Shuchen He
@lists.strongswan.org Subject: Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic Hi, I don't see the virtual IP address 10.2.1.211/32 installed on your physical USB interface with IP address 10.39.63.211. Does the command ip route list table 220 show any source route en

Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic

2018-03-13 Thread Shuchen He
From: Noel Kuntze Sent: Wednesday, 14 March 2018 12:24 AM To: Shuchen He; users@lists.strongswan.org Subject: Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic Hi, Please provide the outputs of `iptables-save -c`, `ip a`, `ip r show table all` and `ip ru`. Btw, modp768 is

Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic

2018-03-13 Thread Noel Kuntze
Hi, Please provide the outputs of `iptables-save -c`, `ip a`, `ip r show table all` and `ip ru`. Btw, modp768 is considered broken, same for 1024. Kind regards Noel On 12.03.2018 11:45, Shuchen He wrote: > Hi, > > I have setup a VPN between ASA and strongswan using IKE1. The strongswan work >

Re: [strongSwan] Strongswan IPSec VPN is up but does not pass traffic

2018-03-13 Thread Andreas Steffen
Hi, I don't see the virtual IP address 10.2.1.211/32 installed on your physical USB interface with IP address 10.39.63.211. Does the command ip route list table 220 show any source route entries? Regards Andreas On 12.03.2018 11:45, Shuchen He wrote: > Hi, > > I have setup a VPN between AS

[strongSwan] Strongswan IPSec VPN is up but does not pass traffic

2018-03-12 Thread Shuchen He
Hi, I have setup a VPN between ASA and strongswan using IKE1. The strongswan work as remote VPN using PSK XAuth. The VPN tunnel is up but I can not ping the remote site. Below is the configuration and some output. My observation at the moment is that the Linux kernel has setup everything but