Re: [strongSwan] key length

2009-03-19 Thread Michael Roy
:) overridemtu only helps with IPsec ESP payload packets and the Yes. It doesn't help while changing MTU on the interface really helps, of course: ip link set eth1 mtu 1200 This is in my case. KLIPS IPsec stack from the FreeS/WAN project. It does not help I have: Using Linux 2.6 IPsec

Re: [strongSwan] Strongswan and Watchguard Edge

2009-03-19 Thread Daniel Mentz
Tica wrote: Just replace: 1.1.1.1 = External IP - left 2.2.2.2 = External IP - right 192.168.0.0/24 = Internal IP - left 10.1.1.0/24 = Internal IP - right left=1.1.1.1 leftid=1.1.1.1 leftsubnet=192.168.0.0/24 leftfirewall=yes lefthostaccess=yes