Re: [strongSwan] make before break and default activation

2017-07-24 Thread Tobias Brunner
Hi Emeric, > Two peers try to renegotiate an IKE SA, they both use strongSwan >=5.3.0 > The first peer has the make-before-break authentication enabled > The second peer does not have the make-before-break authentication enabled > > What happens if the first peer initiates first? What's

Re: [strongSwan] make before break and default activation

2017-07-24 Thread Emeric POUPON
Hi, > Hi Emeric, > To be more specific: - what happens exactly if it is enabled only on one side? >>> >>> It only has an effect on the peer that initiates the reauthentication. >>> Enabling it on a host that's always responder has no effect at all. >> >> What happens on

Re: [strongSwan] make before break and default activation

2017-07-24 Thread Tobias Brunner
Hi Emeric, >>> To be more specific: >>> - what happens exactly if it is enabled only on one side? >> >> It only has an effect on the peer that initiates the reauthentication. >> Enabling it on a host that's always responder has no effect at all. > > What happens on strongSwan>=5.3.0 if the peer

[strongSwan] NAT-to-NAT

2017-07-24 Thread Anton
Hi. I would like to connect two machines both behind the NAT (both on 3g). I have read about this on strongswan documentation. There must be a "madiation server". Where can I find mediation server ? Are any open med.servers with anonimous or registrations ? -- Anton