Hi Alexander,

> I've attached a chunk of the log which hopefully shows what was happening.

It shows that DPDs do not get through in one direction (response from
the peer).  So maybe other traffic in that direction is also affected.
You also seem to use an IP from the remote subnet inside the tunnel so
maybe that is a problem too (see [1]), but this should not affect IKE
traffic.  Try to check with e.g. tcpdump/Wireshark how traffic flows and
where it might get dropped.

Regards,
Tobias

[1]
https://wiki.strongswan.org/projects/strongswan/wiki/ForwardingAndSplitTunneling

_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users

Reply via email to