Re: [strongSwan] roadwarrior client on macOS?

2017-04-25 Thread Zachary Cutlip
Apple Configurator 2 (https://itunes.apple.com/us/app/apple-configurator-2/id1037126344) works well for building IKEv2 VPN profiles for macOS and iOS. You can even edit the profile later (they’re just XML plist format) to configure options that aren’t exposed in the GUI, such as on-demand conne

[strongSwan] Site to site VPN initiated from a NAT router

2018-03-12 Thread Zachary Cutlip
Hello, I’m trying to set up an IPSec VPN that’s a little different from most projects I’ve seen documented. I’m building a NAT router on Debian that I plan to travel with. I guess you might say my strongswan use case is sort of a hybrid between road warrior & site-to-site. I’m confused on how

Re: [strongSwan] Site to site VPN initiated from a NAT router

2018-03-13 Thread Zachary Cutlip
out pol ipsec MASQUERADE all -- 10.88.88.0/24anywhere > On Mar 12, 2018, at 7:36 PM, Zachary Cutlip wrote: > > Hello, > > I’m trying to set up an IPSec VPN that’s a little different from most > projects I’ve seen documented. > > I’m building a NAT router

Re: [strongSwan] Site to site VPN initiated from a NAT router

2018-03-13 Thread Zachary Cutlip
at `iptables -L` and use `iptables-save` instead. It > is a much better tool for it, in any regard. > > Please provide the output of `ipsec statusall`, `iptables-save -c`, `ip a`, > `ip r show table all` and `ip ru`. > > Kind regards > > Noel > > On 13.03.2018 08