[strongSwan] leftID and rightID

2011-09-30 Thread nima chavooshi
Hi Realy thanks for your attention and complete reply. Then,according to your explanation it's better that i set SubjectAltName instead of DN,is that true? In prevoius mail,you told if I do not set leftid or my cerificate does not contain DN or SubjectAltName,then one default value will be selected

Re: [strongSwan] diffie hellman or RSA

2011-09-30 Thread nima chavooshi
Hi Then, why do i have to set certification on conn conf section for any connection? RSA method in strongswan only is used in authentication not key exchange?Am I right ? Eexcuse me for these dummy questions. On Mon, Sep 26, 2011 at 8:58 AM, nima chavooshi wrote: > Hi > Then, why do i have to s

Re: [strongSwan] Charon doesn't set the routes

2011-09-30 Thread Diego Woitasen
On Fri, Sep 30, 2011 at 1:52 PM, Diego Woitasen wrote: > On Fri, Sep 30, 2011 at 8:12 AM, Diego Woitasen wrote: >> Hi, >>  I have the configure below. I don't know why Charon doesn't set the >> routes after SA establishment. It's a net-to-net tunnel and works >> perfectly for hosts behind the gat

Re: [strongSwan] Charon doesn't set the routes

2011-09-30 Thread Diego Woitasen
On Fri, Sep 30, 2011 at 8:12 AM, Diego Woitasen wrote: > Hi, >  I have the configure below. I don't know why Charon doesn't set the > routes after SA establishment. It's a net-to-net tunnel and works > perfectly for hosts behind the gateway but if I want to connect from > one of the gateways to a

[strongSwan] Charon doesn't set the routes

2011-09-30 Thread Diego Woitasen
Hi, I have the configure below. I don't know why Charon doesn't set the routes after SA establishment. It's a net-to-net tunnel and works perfectly for hosts behind the gateway but if I want to connect from one of the gateways to a host behind the peer I have to configure the route with "src" manu