[strongSwan] Connect to a Cisco VPN Terminator

2022-01-28 Thread Rene Maurer
Hello I am trying to connect to a Cisco VPN Terminator. Unfortunately I do not have access to this point. I have obtained certificate and key and entered them in /etc/ipsec.d/certs, /etc/ipsec.d/cacerts and /etc/ipsec.d/private. But I get an AUTHENTICATION_FAILED notify error. I don't know w

Re: [strongSwan] Connect to a Cisco VPN Terminator

2022-01-28 Thread Rene Maurer
Done, so I answer to myself. rm...@mailc.net wrote: But I get an AUTHENTICATION_FAILED notify error. Changing left id from leftid="C=**, ST=**, L=***, O=***, OU=***, CN=***, E=***" to a very simple level leftid=CN-part (e.g. leftid=abc.xxx.ch) solved the problem (it was additionally nec

Re: [strongSwan] Having forwarding issue in a basic StrongSwan setup

2022-01-28 Thread MOHIT CHALLA (mochalla)
Hi Noel, Rajiv Many thanks for your prompt responses. Deeply appreciated! The issue turned out not to be a forwarding issue on linux, but incorrect ESP trailer encoding from the cloud service router due to which post-decryption check was failing on StrongSwan causing it to discard the packet.