Re: [Swan] tunnel error after 24h

2018-03-14 Thread Paul Wouters
On Tue, 13 Mar 2018, valentin vlasov wrote: I have some tunnel made it with different partners. Only one of them give me this strange behaviour. Tunnel it's between my Libreswan 3.15 (netkey) on 2.6.32-696.16.1.el6.x86_64 (centSO 6.9) and a Cisco ASA 5520. Please try 3.24 once we release it

Re: [Swan] Host-to-host tunnel and VTI

2018-03-14 Thread Paul Wouters
On Tue, 13 Mar 2018, Erik Andersson wrote: Ok thanks! Trying to replace klips with netkey. I experience some weird klips kernel crashes on kernel 4.14 (haven't looked into it in detail). Also, klips seems not to be able to "fully" hook up to the kernel crypto API in kernel version 4.14. Yes,

Re: [Swan] Basic netkey routing issue

2018-03-14 Thread Paul Wouters
On Wed, 14 Mar 2018, Erik Andersson wrote: I've set up a simple scenario (following the example described in https://libreswan.org/wiki/Subnet_to_subnet_VPN_with_PSK). The tunnels are established successfully. ping: sendto: Network is unreachable The problem is that the packet is lost bef

[Swan] Basic netkey routing issue

2018-03-14 Thread Erik Andersson
Hi all, I've set up a simple scenario (following the example described in https://libreswan.org/wiki/Subnet_to_subnet_VPN_with_PSK). The tunnels are established successfully. But when I issue this command on the "west" gateway: $ ping -n -c 4 -I 192.0.1.254 192.0.2.254 I get the following e