Hi Tobias,
    I understand that IKE_AUTH response should contain IDr payload.

Topology
_______
Netgear (Initiator)   ---- Strongswan(Responder)
   35.0.0.1                      35.0.0.2

>>>> 13[CFG] looking for peer configs matching 35.0.0.2[%any]...35.0.0.1[]
> >>>>>>>>>>>>>>the problem is that the IDi is empty ([])
>

                     But I don't agree with the above point. Netgear is not
sending an empty IDi payload. It's sending  a valid IDi payload with proper
identification data and I attached IKEv2 packet dumps (strongswan -Netgear)
for your reference.  I guess there is some problem in Strongswan IKE_AUTH
request parsing code for dn identification.

Please correct me , If I am wrong.


Thanks in advance.



> Regards,
> Saravanan N
>

Attachment: IKEV2_decoded_packet.pcap
Description: Binary data

_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to