Re: [strongSwan] AWS VPN to Cisco Unity

2020-04-30 Thread Narendra Joshi
tauth=psk > ike=aes256-sha1-modp1536! > esp=aes256-sha1! > ikelifetime=28800s > keylife=86400s > left=%defaultroute > leftsubnet=18.x.x.x/32 > right=68.x.x.x > rightsubnet=68.x.x.x/32 > keyingtries=999 > keyexchange=ikev1 > reauth=no > closeaction=restart > dpdaction=restart > dpddelay=60s > dpdtimeout=150s -- Narendra Joshi

Re: [strongSwan] NAT-T, SNAT/DNAT and TCP checksum incorrect on peer VPN gateway (site-to-site)

2020-04-22 Thread Narendra Joshi
be caused by RX and TX checksum offloading though. Check the > sizes first though and specifically, just getting google.com. That page is > quite small and should work fine. Loading a picture from Instagram probably > fails. PMTUD didn't work with Instagram's CDN last time I checked. >

Re: [strongSwan] NAT-T, SNAT/DNAT and TCP checksum incorrect on peer VPN gateway (site-to-site)

2020-04-21 Thread Narendra Joshi
(probably). Can MTU cause TCP checksum failures? My networking knowledge is definitely limited here. Kind regards Noel [1] https://wiki.strongswan.org/projects/strongswan/wiki/ForwardingAndSplitTunneling#MTUMSS-issues Am 21.04.20 um 20:38 schrieb Narendra Joshi: Hi, I have setup an IPSec

[strongSwan] NAT-T, SNAT/DNAT and TCP checksum incorrect on peer VPN gateway (site-to-site)

2020-04-21 Thread Narendra Joshi
is happening and how it can be avoided. Here is an image of the setup I have: Best regards, -- Narendra Joshi