Re: [strongSwan] generating IKE_AUTH response 1 [ N(AUTH_FAILED) ]

2017-10-16 Thread Tobias Brunner
Hi Jon, > charondebug="ike 1, knl 1, cfg 0" Why did you set the log level for cfg to 0? That's where you'd see why this error occurs. Regards, Tobias

[strongSwan] How to disable new connections?

2017-10-16 Thread Mike.Ettrich
Hallo! Is it possible to tell strongSwan (charon) that no more onnections should be opened, but the existing connections have to keep open? This behavior is required when mass connections occurs and system resources are short. May be there is a strongSwan command I didn't see or a known work a

[strongSwan] Windows ikev2 conn, eap_identity ignored

2017-10-16 Thread Giuseppe De Marco
Hi all, I'm using Debian GNU/Linux 9.2 (stretch) with standard strongswan package from stretch apt repository (5.5.1-4+deb9u1). The tunnel is a ikev2 with eap-radius authentication. I'm facing the problem that Windows 10 clients doesn't send their right identity. Linux and Android clients works

Re: [strongSwan] Windows ikev2 conn, eap_identity ignored

2017-10-16 Thread Noel Kuntze
Hi, What you want can't be done. Charon can not switch conns based on the eap identity. Configure your RADIUS server to issue the static lease. Implementing that feature is non trivial. Kind regards Noel On 16.10.2017 22:08, Giuseppe De Marco wrote: > Hi all, > > I'm using Debian GNU/Linux 9.2