Re: [strongSwan] Resubmission as plaintext - Strongswan with ESP-NULL and ESP-NONE , NULL encryption and NONE integrity

2017-01-09 Thread Andreas Steffen
Hi, I did a test with strongswan-5.5.2dr4 and esp=null! and it surprisingly it works. Please be aware that such an ESP tunnel doesn't offer any security at all, i.e. neither confidentiality nor data integrity. Regards Andreas On 07.01.2017 21:59, ss admin wrote: Andreas, Thanks for the qui

Re: [strongSwan] OSPF == tons of security associations

2017-01-09 Thread Hose
What you say...Noel Kuntze (n...@familie-kuntze.de): > On 05.01.2017 20:31, Hose wrote: > > So from what I can tell each time it's doing an IKE re-key it's creating an > > additional set of SAs. Any idea why this is occurring? > Try disabling reauthentication and/or enabling make_before_break >