[strongSwan] terminate connection that is in active: IKE_DPD

2017-04-19 Thread Modster, Anthony
Hello ? how do you terminate a connection that is in (active: IKE_DPD) * Connection was established * Removed the interface * The connection went into active: IKE_DPD * Issued swanctl -terminate -ike sgateway1-gldl * Note: swanctl reported the dpd

Re: [strongSwan] Unable to connect to the VPN server from ubuntu via nm-strongswan

2017-04-19 Thread Eugene Kabanov
Thanks for the help! Could you give an example? I tried to set up as it is written on: https://wiki.strongswan.org/projects/strongswan/wiki/Win7MultipleConfig https://wiki.strongswan.org/projects/strongswan/wiki/Win7EapMultipleConfig But I still can't connect via nm plugin :( Apr 19

[strongSwan] CRL check: how to fail over to local CRL if fetch fails

2017-04-19 Thread Zach Cutlip
Is there a way to make CRL verification fail over to a local CRL if fetching fails? My client certificates are configured with an embedded CRL URL. I'm finding that if charon is unable to fetch the CRL from the url provided by the cert for some reason, CRL checking fails and authentication

Re: [strongSwan] tcpdump/wireshark and Strongswan IPsec VPNs

2017-04-19 Thread Tobias Brunner
Hi Clovis, > I am looking for any help > from anyone who can get the right configuration for tcpdump/wireshark to > generate full bidirectional dump of traffic. https://wiki.strongswan.org/projects/strongswan/wiki/CorrectTrafficDump Regards, Tobias

[strongSwan] tcpdump/wireshark and Strongswan IPsec VPNs

2017-04-19 Thread Clovis Lacerda
Hi All, I have a strongswan server and need to be able to fully generate pcap output files for wireshark. The problem is that there is encryption with the traffic going through the IPsec tunnel. I am looking for any help from anyone who can get the right configuration for tcpdump/wireshark to