Re: [strongSwan] Same config for strongSwan, different outcome between Android and iOS

2016-07-15 Thread Tobias Brunner
Hi Laurens, >> The latter is of course because it does not send any certificate >> requests, whereas 156 of them are sent by the Android app (each a 20 >> byte SHA-1 hash). As I mentioned before, you can avoid that by >> selecting your CA certificate in the VPN profile in the app. This >> should

Re: [strongSwan] AUTH FAIL but I cannot figure out the reason

2016-07-15 Thread Tobias Brunner
Hi Ariwa, > I see log. but I cannot figure out dubious point. > Is there someone have any hint for it? The log is pretty clear: > Thu Jul 14 21:51:35 2016 daemon.info syslog: 03 [CFG] looking for > peer configs matching 192.168.1.32[openwrt5server]...192.168.1.156[C=JP, > L=Tokyo, O=Dr

Re: [strongSwan] Setup site-to-site VPN via central server

2016-07-15 Thread Tobias Brunner
Hi Martin, > Should I document this setup somewhere on the Wiki? I've added some documentation [1]. As mentioned there, the hub-and-spoke setup is also demonstrated in an example scenario [2]. Even though its configuration is based on swanctl.conf the concept is the same when setting it up via i