Hi Michael,

> VPN connection is established:

There are no CHILD_SAs listed there.  Only IKE_SAs.  Could you send the
logs of when the SAs are established (including the initial messages
where the NAT is detected).  What strongSwan version(s) are you using?

> If I configure forceencaps then the xfrm policy is not set up

Why?  What is logged?  Anyway, if it doesn't work with forceencaps,
which randomizes NAT-D payloads to fake a NAT situation, it probably
won't work either if an actual NAT is detected otherwise.

Regards,
Tobias

_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to