Re: [strongSwan] tunnel stuck, won’t seem to timeout and can’t manually delete either

2022-02-02 Thread FINLEY, DAVID BRIAN
391 (desk) (630) 740-5198 (mobile) -Original Message- From: Tobias Brunner Sent: Wednesday, February 02, 2022 12:07 PM To: FINLEY, DAVID BRIAN ; users@lists.strongswan.org Subject: Re: [strongSwan] tunnel stuck, won’t seem to timeout and can’t manually delete either Hi Dave, We need m

[strongSwan] tunnel stuck, won’t seem to timeout and can’t manually delete either

2022-02-02 Thread FINLEY, DAVID BRIAN
Hello, We’ve seen this issue a few times. A client connects to a our gateway (running strongswan 5.9.2), the client terminates the tunnel but the tunnel doesn’t get terminated or timeout on the gateway. The “client” is a driver so it may be that it just goes away without properly cleaning up, b

[strongSwan] charon appears to either crash and/or restart during HA takeover

2021-12-02 Thread FINLEY, DAVID BRIAN
Hello, Experiencing an issue with version 5.8.0. We have two gateways in an HA arrangement. When the current master goes down, the backup takes over ok but when the old master comes backup (as the back up) and attempts to the re-sync the tunnel list from the new master (took over for the old ma

Re: [strongSwan] FW: defining a connection profile using DNS name in the cert's alt subject name cert field

2021-06-03 Thread FINLEY, DAVID BRIAN
98 (mobile) -Original Message- From: Noel Kuntze Sent: Wednesday, June 02, 2021 4:24 PM To: FINLEY, DAVID BRIAN ; Users@lists.strongswan.org Subject: Re: [strongSwan] FW: defining a connection profile using DNS name in the cert's alt subject name cert field Hello Dave, Thank you for you

[strongSwan] FW: defining a connection profile using DNS name in the cert's alt subject name cert field

2021-06-02 Thread FINLEY, DAVID BRIAN
desk) (630) 740-5198 (mobile) -Original Message----- From: FINLEY, DAVID BRIAN Sent: Monday, May 10, 2021 10:20 AM To: Noel Kuntze Subject: RE: [strongSwan] defining a connection profile using DNS name in the cert's alt subject name cert field I set my charon-logging.conf file up to

Re: [strongSwan] defining a connection profile using DNS name in the cert's alt subject name cert field

2021-05-27 Thread FINLEY, DAVID BRIAN
Noel, please let me know if you've had any further thoughts on this. thx Dave Finley df1...@att.com (630) 719-4391 (desk) (630) 740-5198 (mobile) -Original Message- From: FINLEY, DAVID BRIAN Sent: Wednesday, May 19, 2021 11:02 AM To: Noel Kuntze Subject: RE: [strongSwan] defin

[strongSwan] defining a connection profile using DNS name in the cert's alt subject name cert field

2021-05-05 Thread FINLEY, DAVID BRIAN
Hello, I have ipsec clients using strongswan that are connecting to a strongswan server and want to setup connection profiles based on info in the subject Alt name string in each clients certificate. The subject Alt name in the client cert looks like this: X509v3 Subject Alternative Name: