Most common android esp flow issue is using its bad sha2_256. Ensure your esp= line does not include it ?
Sent from my phone > On Jul 24, 2018, at 06:04, Tan Chee Eng <m...@tan-ce.com> wrote: > > Hi, > > I'm following this example to set up libreswan on my server: > https://libreswan.org/wiki/VPN_server_for_remote_clients_using_IKEv1_XAUTH_with_Certificates > > The configuration works when I manually connect to the VPN. However, > when I enable "Always-on VPN", the connection doesn't seem to work at > all. > > The logs (and wireshark) reveal that IKE succeeds, but after there, > there are no ESP packets from my Android device to the server, except > for NAT-keepalive. > > Has anyone encountered anything like this? > > Regards, > Chee Eng > _______________________________________________ > Swan mailing list > Swan@lists.libreswan.org > https://lists.libreswan.org/mailman/listinfo/swan _______________________________________________ Swan mailing list Swan@lists.libreswan.org https://lists.libreswan.org/mailman/listinfo/swan