Hi Noel,
> I just noticed, that the strongSwan app still displays the tunnel as
> active, although a CHILD rekey event failed, because of a DH
> group/algorithm mismatch.
As long as the original CHILD_SA is still established the connection is
not broken, so displaying the connection as active is
Hi,
I could finally get over this issue.
The main problem was that the .so's for the plugins were not building.
The following configure line helped me generate the .so's [I had to pass the
--target and --host properly]
./configure --with-random-device=/dev/urandom --target=mips64-octeon-linux-
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hello Martin,
I don't use RADIUS accounting in this setup, but the plugin is loaded. I think
charon follows a wrong code path, which causes the error.
Regards,
Noel Kuntze
GPG Key id: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F
Hi Andrej,
> Surprisingly, getaddrinfo() started to prefer IPv4 all the time,
> All IPv6 addresses set by StrongSwan are now marked as expired, i.e.,
> "deprecated".
Looks like a regression that has been introduced with [1]. You may try
to revert that patch to restore the pre-5.2.0 behavior.
Pr
Hi Noel,
> 31[IKE] DH group ECP_521 inacceptable, requesting ECP_512_BP
> 31[IKE] IKE_SA strongswan-app[38] state change: CONNECTING => DESTROYING
> 31[DMN] thread 31 received 11
> 31[LIB] dumping 11 stack frame addresses:
> 31[LIB] /usr/lib/libpthread.so.0 @ 0x7fed6a5a7000 [0x7fed6a5b64b0]
> 3