Hi All,

I have a question about strongswan xauth. When I use strongswan to get 
connection with a  VPN device, I always get this error"xauth miss match" in 
peer side, and cannot get connect with that device, I have capture packet, I 
find that it is because the phase I packet contains 
draft-beaulieu-ike-xauth-02.txt, so the peer side will consider it has xauth 
information(of course, it is not right), so will reject this connect.
I have check some documents, find thar when I configure the strongswan with 
"--disable-xauth-vid" this draft-beaulieu-ike-xauth-02.txt will disappear. So I 
want to check you, is this the perfect solution for this problem? This just 
disable the function of Xauth? And if I also need this function how can I do?

Thanks very much!!

Brian

Attachment: phase_I_.pcap
Description: phase_I_.pcap

_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to