Hi Michael, > VPN connection is established:
There are no CHILD_SAs listed there. Only IKE_SAs. Could you send the logs of when the SAs are established (including the initial messages where the NAT is detected). What strongSwan version(s) are you using? > If I configure forceencaps then the xfrm policy is not set up Why? What is logged? Anyway, if it doesn't work with forceencaps, which randomizes NAT-D payloads to fake a NAT situation, it probably won't work either if an actual NAT is detected otherwise. Regards, Tobias _______________________________________________ Users mailing list [email protected] https://lists.strongswan.org/mailman/listinfo/users
