[strongSwan] example ipv6 pool

2017-12-06 Thread Alex Sharaz
Anyone got an example of defining an ipv6 pool using ipsec pool .. ? Rgds Alex

Re: [strongSwan] Outgoing site-to-site packets not sent through tunnel

2017-12-06 Thread Isaac Sutherland
For the record, putting the changes in /etc/strongswan.conf works fine, but on a Ubuntu 16.04 system the recommended location is /etc/strongswan.d/charon.conf, where the install_routes directive is already populated but commented out. Further, for the kind of setup I'm doing, the strongswan RouteB

[strongSwan] Validating Local Host Own Certificate

2017-12-06 Thread Jafar Al-Gharaibeh
Hi,    I have noticed that when configuring the local certificate in a connection via :    leftcert=cert.pem   The certificate is loaded and trusted without validating it through CA/trust-chains. Is this behavior documented anywhere? digging through documentation I only found old email refe

Re: [strongSwan] Validating Local Host Own Certificate

2017-12-06 Thread Andreas Steffen
Hi Jafar, locally loaded certificates are always trusted. Regards Andreas On 07.12.2017 07:44, Jafar Al-Gharaibeh wrote: Hi, I have noticed that when configuring the local certificate in a connection via : leftcert=cert.pem The certificate is loaded and trusted without validatin