Re: [strongSwan] rightid=%any or wild characters - ikev1 not working

2010-01-14 Thread Andreas Steffen
Hello Ashish, I'm currently on a holiday in Australia and thus I have only limited time in answering questings on the strongSwan mailing list. Best regards Andreas ashish mahalka wrote: > Hi Andreas, > > It would be really nice if you could give me some information on the > problem that I have

Re: [strongSwan] [strongswan]ikev2 with plutostart=yes

2010-01-14 Thread ashish mahalka
Hi Daniel, I checked the config.log in my host-2 machine. I did observe the following lines: USE_PLUTO_FALSE='#' USE_PLUTO_TRUE='' " Please let me know if u need any other info. regards, Ashish On 1/14/10, Daniel Mentz wrote: > ashish mahalka wrote: >> _Host-2_ >> >> netstat --raw -a -p >> A

Re: [strongSwan] How to drop connection when VPN client disconnect from gataway

2010-01-14 Thread Kalaj
Hi, Andreas, I try so much config methods still can't ground the problem, the connections become more and more if server didn't restart, is it possible to drop the connections auto when vpn client disconnect from server? Thanks! On Thu, Jan 14, 2010 at 5:17 AM, Andreas Steffen wrote: > Hi Kalaj

Re: [strongSwan] rightid=%any or wild characters - ikev1 not working

2010-01-14 Thread ashish mahalka
Hi Andreas, It would be really nice if you could give me some information on the problem that I have described in the mail below. Thanks for all the help! regards, Ashish On 1/13/10, ashish mahalka wrote: > Hello, > > I am unable to establish an ikev1 SA when I specify the rightid in the > fol

Re: [strongSwan] Connection established, cant ping hosts behind gateway

2010-01-14 Thread Russ Cox
I've got a little further with this for anyone interested. I ran a tcpdump from a machine on my internal network for any traffic from/to the rw machine - when pinging, I could see packets arriving on the internal machine but no replies on the rw. This kind of made sense, the vpn gateway is not a

[strongSwan] Connection established, cant ping hosts behind gateway

2010-01-14 Thread Russ Cox
Hi all, I'm trying to set up a strongswan gateway, behind a NAT router for roadwarrior use. I can initiate the connection from another debian machine also using strongswan (also behind NAT), virtual ip is assigned correctly and I'm able to ping/ssh to the gateway machine on its private ip addres

Re: [strongSwan] How to drop connection when VPN client disconnect from gataway

2010-01-14 Thread Kalaj
I disabled the DPD, but the connections still alive, it seems wait for EVENT_SA_EXPIRE? On Thu, Jan 14, 2010 at 5:17 AM, Andreas Steffen wrote: > Hi Kalaj, > > since you enabled DPD with > >  dpd_action: clear; dpd_delay: 40s; dpd_timeout: 130s > > The connection should get deleted after about 3