Re: [strongSwan] Problem with 4in6 and 6in4 ipsec tunnel

2014-04-25 Thread rakesh bansod
/net2net-ip4-in-ip6-ikev2/ Best regards Andreas On 26.04.2014 07:43, rakesh bansod wrote: Hello, I am trying to configure a 4in6 ipsec tunnel in strongswan with ipv4 subnets and ipv6 end points. What changes or additions to be done in kernel to achieve this? Is there any documentation available

[strongSwan] Problem with 4in6 and 6in4 ipsec tunnel

2014-04-25 Thread rakesh bansod
Hello, I am trying to configure a 4in6 ipsec tunnel in strongswan with ipv4 subnets and ipv6 end points. What changes or additions to be done in kernel to achieve this? Is there any documentation available related to this?? Thank you. Regards, Rakesh Bansod

Re: [strongSwan] regarding starter when logging option is used

2013-10-16 Thread rakesh bansod
On 10/16/2013 04:13 PM, rakesh bansod wrote: > Hi, > whenever i try to use logging options in strongswan.conf. after > starting the charon, it automatically recieves a sigint signal and it > shows that it has stopped. > but when i see ipsec statusall it still works. > but

[strongSwan] regarding starter when logging option is used

2013-10-16 Thread rakesh bansod
Hi, whenever i try to use logging options in strongswan.conf. after starting the charon, it automatically recieves a sigint signal and it shows that it has stopped. but when i see ipsec statusall it still works. but as it has stopped in logs no further logs are recorded in file. this problem

[strongSwan] regarding adding connections

2013-10-11 Thread Rakesh Bansod
Hi I want to know how to add the connections when we use 'auto=ignore' if we use 'auto=ignore' it is not added. even stroke is not useful for adding connections in conf file. then how exactly it is added. or the only solution is to change ipsec.conf with auto=add. please answer. none of my q

[strongSwan] regarding adding connections when auto=ignore is used

2013-10-11 Thread rakesh bansod
Hi I want to know how to add the connections when we use 'auto=ignore' if we use 'auto=ignore' it is not added. even stroke is not useful for adding connections in conf file. then how exactly it is added. or the only solution is to change ipsec.conf with auto=add. please answer. none of my q

[strongSwan] disable ah4 module

2013-10-07 Thread rakesh bansod
hi, I want to use strongswan on kernel 2.6.39.4, and i dont want to use the ah feature. how to disable the the ah feature while installation. or it can be avoided by just commenting "modprobe -qv ah4" line in netkey.c please reply. thank you, Rakesh __

[strongSwan] ikev1 dynamic initiator test

2013-09-27 Thread rakesh bansod
Hi, I am trying test no. 22 on website i.e. ikev1/dynamic-initiator. As written there, it should make tunnel even if the ip is changed. but when I change my ip, it detects the change in ip and phase 1 is re-installed (IKE_SA) but it is not creating CHILD_SA at that time. CHILD_SA is creatin

[strongSwan] ikev1 not detecting domain name

2013-09-09 Thread rakesh bansod
Hi, I have defined a connection with right=rakesh.com, and ip for rakesh.com is stored in /etc/hosts. When i connect using ikev2 it gets connected easily but when i use ikev1 it shows following lines. initiating Main Mode IKE_SA testing[2] to 10.202.25.201 generating ID_PROT request 0 [ SA V V

[strongSwan] regarding dns resolution

2013-09-04 Thread Rakesh Bansod
hi, I want to know how the dns is resolved in strongswan. if i give right=rakesh.com and for this a particular ip is written in /etc/hosts, so the connection goes up easily. But in logs it shows the ip while connecting this means that somewhere inside the name is replaced by ip. what actually happe

Re: [strongSwan] regarding ipsec starter

2013-08-31 Thread rakesh bansod
is very limited at the moment, but > I think more will be added over time. > > Regards, > Noel Kuntze > > > On 30.08.2013 16:13, rakesh bansod wrote: >> On 08/30/2013 05:23 PM, Noel Kuntze wrote: >>> -BEGIN PGP SIGNED MESSAGE- >>> Hash: SHA256 &g

[strongSwan] [strongswan] regarding ipsec starter

2013-08-30 Thread rakesh bansod
hi all, i want to know is it possible to establish ipsec connection without entering connection details in ipsec.conf. As it possible in openswan by accessing directly through whack. similarly is there any possibility here with starter to skip writing into file and reading it which is a heav