Re: [strongSwan] AH Transport AES-128 GMAC

2016-11-07 Thread Tobias Brunner
Hi Gyula, > Anybody have an idea what could be wrong? That's due to a recently fixed bug that mapped the aes*gmac keywords incorrectly for AH proposals. You may either update to 5.5.1, which includes the fix, or try to apply the patch at [1] (won't apply cleanly to any older version as it is bas

Re: [strongSwan] AH Transport AES-128 GMAC

2016-11-07 Thread Gyula Kovács
Hi Tobias, Thank you for the idea, but I'm using version 5.5.1 (see below). --- root@atm:~# ipsec version Linux strongSwan U5.5.1/K3.16.0-4-586 Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil, Switz

Re: [strongSwan] AH Transport AES-128 GMAC

2016-11-07 Thread Tobias Brunner
Hi Gyula, > Thank you for the idea, but I'm using version 5.5.1 (see below). I see. The other end might not, though. Regards, Tobias ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

Re: [strongSwan] ikev2 server without cert

2016-11-07 Thread robert k Wild
thanks, also its a good idea making your vpn into an apache server aswell so you can just log in and just grab the cert On 7 November 2016 at 00:47, Derek Cameron wrote: > Yes, you can use username and password. In this tutorial, the > strongSwan server authenticates with a certificate, and the

[strongSwan] nat ports for ikev2

2016-11-07 Thread robert k Wild
hi all, what ports do i need to nat to my vpn server on my firewall? many thanks, rob -- Regards, Robert K Wild. ___ Users mailing list Users@lists.strongswan.org https://lists.strongswan.org/mailman/listinfo/users

[strongSwan] Configure multiple transports between 2 machines

2016-11-07 Thread Manu S. Keshava
Hi Strongswan users, [Machine_A] <--> [Machine_B] 10.1.1.151/24 10.1.1.203/24 10.4.4.151/24 10.4.4.203/24 I have two machines connected to back-to-back using a single port NIC as above. I have configured and installed strongswan on both machines. The machines have an IP alias also