Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-07 Thread Sujoy
Hi Jafar,    Peer is also using strongswan 5.3.3. following is the configuration. We need tunnel because once it is connected in LAN we want to implement in WAN/Internet. Output of the 192.168.10.40 is bellow.     Config setup     charondebug="all"     uniqueids=yes    

Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-07 Thread Jafar Al-Gharaibeh
On 2/7/2018 9:22 AM, Sujoy wrote: Thanks Jafar, for the reply. But after removing subnet from the config also tunneling failed. Is there any issue with the version of strongswan 5.3.3. What means "TS_UNACCEPTABLE notify, no CHILD_SA built" "TS_UNACCEPTABLE notify"  means the peer didn't

Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-07 Thread Sujoy
Thanks Jafar, for the reply. But after removing subnet from the config also tunneling failed. Is there any issue with the version of strongswan 5.3.3. What means "TS_UNACCEPTABLE notify, no CHILD_SA built"    Config setup     charondebug="all"     uniqueids=yes    

Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-07 Thread Jafar Al-Gharaibeh
On 2/7/2018 9:01 AM, Jafar Al-Gharaibeh wrote: You can have the least significant octet set to zero with a 32-bit netmask Sorry, this should read: You can NOT have the least significant octet set to zero with a 32-bit netmask

Re: [strongSwan] received TS_UNACCEPTABLE notify, no CHILD_SA built

2018-02-07 Thread Jafar Al-Gharaibeh
Sujoy,   Are you sure about    rightsubnet=192.168.10.0/32  This subnet gets you nothing unless you know that it has a special meaning in the config that I'm not aware of. You can have the least significant octet set to zero with a 32-bit netmask. What is the rightsubnet that you are trying