Re: [Swan-dev] IKEv1 and XFRMi interface

2020-09-15 Thread Antony Antony
I had a quic look. IKEv1 need extra message (3 round trips) as opposed to IKEv2(2 round trips). And initiator is installing policies in different order. the test outputs as it is now are confusing because it seems a copy of IKEv2 outputs. May be create tests with eastnet-westnet, delete IKEv2

[Swan-dev] leftikeport= does not set tcp port

2020-09-15 Thread Paul Wouters
Some changes were made a while ago to the TCP port handling. You no longer specify a port in 'config setup'. Instead there is listen-tcp=yes|no and listen-udp=yes|no For UDP, you can set custom ikeport's using leftikeport= and rightikeport. For TCP, you can set the port to connect to using

[Swan-dev] [libreswan/libreswan] pluto segfault in nat_traversal (#367) (fwd)

2020-09-15 Thread Paul Wouters
-- Forwarded message -- Date: Tue, 15 Sep 2020 11:23:20 From: Daniel Wendler Cc: Subscribed To: libreswan/libreswan Subject: [libreswan/libreswan] pluto segfault in nat_traversal (#367) Over the last weeks we upgrade our VPN Gateways from v3.27 / v3.29 to mostly v3.31.