[strongSwan] DHCP flood

2016-03-22 Thread Daniel Flynn
Good Day All, I am configuring my strongSwan instance on Debian Wheezy for a single road warrior to be able to connect via IKEv2. It works, but whenever I establish the tunnel from the remote client, the Debian instance floods the network with DHCP lease requests. Destroy the connection and the

[strongSwan] What is expected ? Host with traffic type "Transport" and SecGW with traffic type "

2016-03-22 Thread Nanda Gopal
> Hello, > > I have a use-case (I'd rather call it an abuse case :) ), where I create > two tunnels , 1 IKEv1 and 1 IKEv2. I configure each entry in the DUT as > traffic type "Tunnel" [which means I don't want my DUT to create a tunnel > with Transport mode at all] > > I create the corresponding po

[strongSwan] charon.fragment parameter

2016-03-22 Thread Ruslan Kalakutsky
Hello, I've faced up with some issues with ISP who block ICMP 'fragmentation needed' messages, as well as drops fragmented UDP packets. It affects AUTH messages of used IKEv2 protocol. As it claimed at documentation [1] charon.fragment_size is Maximum size (complete IP datagram size in bytes) of

[strongSwan] Remove default policy

2016-03-22 Thread Naveen Neelakanta
Hello, Is it possible to configure strongswan not to add the below default policy rules. I am running strong swan in TEST namespace on linux and i don't see the arp working from the root name space to namespace interface. I would like to know why ARP between the root namespace and Test namespace