Re: [strongSwan] length of TRAFFIC_SELECTOR_SUBSTRUCTURE substructure list invalid

2018-10-29 Thread Tobias Brunner
Hi Yogesh, > No it is not strongswan on peer end. I am using third party VPN. Which probably means the peer sends an invalid TS payload. > So is the IKE_AUTH packet size is fixed to 204 bytes for PSK mode and > anything exceeding that can be Invalid length. There are no fixed sizes for any

Re: [strongSwan] length of TRAFFIC_SELECTOR_SUBSTRUCTURE substructure list invalid

2018-10-29 Thread Yogesh Purohit
Hi Andreas, No it is not strongswan on peer end. I am using third party VPN. So is the IKE_AUTH packet size is fixed to 204 bytes for PSK mode and anything exceeding that can be Invalid length. Configuration on my side is: conn %default ikelifetime = 28800s type = tunnel

Re: [strongSwan] length of TRAFFIC_SELECTOR_SUBSTRUCTURE substructure list invalid

2018-10-29 Thread Andreas Steffen
Hi Yogesh, are you using an unmodified strongSwan peer on the other side or a third party VPN product? If it is strongSwan, which version are you using? Could you also send the configuration of the CHILD SA? Regards Andreas On 29.10.2018 06:43, Yogesh Purohit wrote: > Adding subject line to my