Re: [strongSwan] left ID, right ID and no matching peer config

2017-04-24 Thread Piyush Agarwal
Ah, had a typo in the configs. Here they are again. Hi, I am trying to establish strongswan between two ubuntu 14.04 machines. I can get things to work if I specify both the leftID and the rightID on both server and client. What I need though is the following: 1) I will be copying the server

[strongSwan] left ID, right ID and no matching peer config

2017-04-24 Thread Piyush Agarwal
Hi, I am trying to establish strongswan between two ubuntu 14.04 machines. I can get things to work if I specify both the leftID and the rightID on both server and client. What I need though is the following: 1) I will be copying the server self-signed certificate directly to the client machine

Re: [strongSwan] Tunnels with dynamic IP and another route issue

2017-04-24 Thread Dusan Ilic
No one? Den 2017-04-21 kl. 10:16, skrev Dusan Ilic: Hi! I have some issues, please read on. 1. I have one side of the IP-sec tunnel with dynamic IP (associated with a dynamic hostname), I would like not need to change the "left"-parameter in both ipsec.conf and ipsec.secrets whenever the

[strongSwan] roadwarrior client on macOS?

2017-04-24 Thread Paul Harrison
Hi all, We have a Strongswan IKEv2 (client cert) based service that works extremely well on our Windows laptop clients. But I've now been tasked with getting our MacBooks connecting to it and have very little experience of Apple kit I'm afraid I'm struggling with the wiki documentation and

Re: [strongSwan] CRL check: how to fail over to local CRL if fetch fails

2017-04-24 Thread Tobias Brunner
Hi Zach, > I do wish I could figure out the file:/// problem though. > /usr/bin/curl has no problem fetching the CRL via the file URI, so I > don't suspect libcurl is the problem. Besides it's a default Debian > installation. Debian's libcurl should be pretty typical. Is there a > way to coax