Re: [Swan] left/rightsubnets option

2018-04-24 Thread Erik Andersson
On 2018-04-24 00:29, Paul Wouters wrote: On Mon, 23 Apr 2018, Erik Andersson wrote: conn remote ... ...     right=10.48.28.81     rightid=10.48.28.81 rightsubnets=192.168.110.0/24,50.50.50.0/24   left=%any ... ... (have also tried rightsubnets={192.

[Swan] Overlapping traffic selectors and IKEv1

2018-04-24 Thread Ivan Kuznetsov
Hello We have a running IPsec/IKEv1 tunnel with a customer. Part of configuration: conn aCustomer connaddrfamily=ipv4 type=tunnel auto=start authby=secret left=A.B.C.D leftsubnets=30.191.90.169/32,30.191.90.170/32 right=E.F.G.H righ

Re: [Swan] Overlapping traffic selectors and IKEv1

2018-04-24 Thread Ivan Kuznetsov
24.04.2018 16:08, Ivan Kuznetsov пишет: Customer side equipment is some Cisco router, I don't know details. Our side is libreswan 3.21 Libreswan 3.21 under Linux (kernel 4.1.12) The question seems to be about Linux netkey stack, not libreswan. But if someone shows me the good URL to read I

Re: [Swan] Overlapping traffic selectors and IKEv1

2018-04-24 Thread Paul Wouters
On Tue, 24 Apr 2018, Ivan Kuznetsov wrote: conn aCustomer connaddrfamily=ipv4 type=tunnel auto=start authby=secret left=A.B.C.D leftsubnets=30.191.90.169/32,30.191.90.170/32 right=E.F.G.H rightsubnets=30.201.192.24/32,30.201.192.34/

Re: [Swan] Overlapping traffic selectors and IKEv1

2018-04-24 Thread Ivan Kuznetsov
Paul, thank you a lot! Ivan 24.04.2018 17:36, Paul Wouters пишет: On Tue, 24 Apr 2018, Ivan Kuznetsov wrote: conn aCustomer     connaddrfamily=ipv4     type=tunnel     auto=start     authby=secret     left=A.B.C.D     leftsubnets=30.191.90.169/32,30.191.90.170/32