Questions tagged [strongswan]

strongSwan is an open source, multi-platform IPsec-based VPN solution, with IKEv2 & IKEv1 support

strongSwan is an open source, multi-platform -based solution, with IKEv2 & IKEv1 support.

More information can be found on strongswan.org.

435 questions
0
votes
1 answer

strongSwan service will not start

Ubuntu 20.04 strongSwan 5.9.1 (swanctl) I have get the following error: /usr/sbin/charon-systemd: symbol lookup error: /usr/lib/ipsec/plugins/libstrongswan-stroke.so: undefined symbol: chunk_unmap_clear It was working before with no…
lk7777
  • 243
  • 2
  • 10
0
votes
1 answer

How to fix these xl2tpd errors?

How to fix these xl2tpd errors? How to fix these xl2tpd errors? l2tp/ipsec connection. I use xl2tpd along with strongswan. Strongswan is rising, everything is ok. I see myself connected to the gateway via ipsec. Further xl2tpd, I receive errors. Jan…
epx
  • 1
  • 1
0
votes
2 answers

Block websites for my VPN users

I have strongswan running fine, I need to block some bad websites by it's domains from being visiting by VPN users, I tried many methods but no luck as redirect traffic from vpn to proxy server like squid but I discovered that forwarded traffic to…
Realbitt
  • 101
  • 2
0
votes
0 answers

IPSec iptables rules for local service

I have a StrongSwan IPSec remote access server running on RHEL and a client all on the same local network. I have a Samba server running on the same RHEL host that I want to be available through the VPN but not outside the tunnel. I can get the…
joe_shmo
  • 1
  • 1
0
votes
1 answer

using strongswan with pkcs11 and yubikey

I am trying to deploy a new VPN configuration in my enterprise. I have successfully established a connection between my computer and my vpn ipsec server in certificate mode. I uploaded the p12 file in my yubikey which contains my private key, the…
rBeal
  • 1
  • 3
0
votes
1 answer

Failed to start the IKEv2 VPN connection to surfshark via NetworkManager

I try to connect to surfshark VPN provider through IKEv2 manually. Here are the logs charon-nm[5070]: 05[CFG] received initiate for NetworkManager connection Surfshark IKE2 charon-nm[5070]: 05[CFG] using gateway identity…
Morse
  • 103
  • 2
0
votes
1 answer

Strongswan swanctl.conf parameter syntax

I am looking for exact syntax for swanctl.conf parameter syntax. I read though the swanctl.conf documentation, but there does not seem to be any exact syntax for parameters. Mainly I am looking for the exact way to specify different "proposals" We…
Dave
  • 229
  • 2
  • 10
0
votes
2 answers

Strongswan IPSec Configuration on a VPS

Please assist. I'm trying to set up a site to Site IPSec tunnel with strongswan on my VPS but sadly my provider cannot enable the following kernel modules for…
0
votes
1 answer

EAP-MS-CHAPv2 verification failed Arch Linux (strongswan)

I cannot get Strongswan, networkmanager-strongswan (client) work on your Arch-PC. My vpn-strongswan server (hereinafter deb (server)) has been configured for a long time, any devices (such as android, windows), except for my arch linux (hereinafter…
0
votes
0 answers

IPSec site2site tunnel + vpn

In our research project, we needed to deploy a server "Molly" at another company. They made us set up a IPSec tunnel to their firewall/gateway and from there, the comms are forwarded to our server. I configured StrongSwan on our gateway machine…
0
votes
1 answer

Packets from xfrm interface won't route, but opposite works

I'm working on a site-to-site vpn, where one end us a UDM and the other is Strongswan. The goal is to provide bi-directional routing into a cloud environment. I'm completely baffled why this isn't working. The good news is Strongswan connects and…
0
votes
0 answers

Strongswan tunnel connected but the traffic is not going through it

I have 3 Virtual Machine cluster (platform1, platform2 and platform3) and I have enabled ipsec tunnel communication between them using strongswan (5.6.2). The tunnel looks fine and connected, but seems there is a problem routing the traffic through…
0
votes
1 answer

Mirror incoming traffic on specific port to another IP, using my IPSec strongswan tunnel

I want to internally publish an SMTP server (IP 10.0.0.10) that is behind a VPN tunnel on my internal server (192.168.0.12) using strongswan. My strongswan is running within a docker container. For this I want my internal server 192.168.0.12 to…
Theo
  • 153
  • 1
  • 11
0
votes
1 answer

IPsec/L2TP connection fails when two clients have the same local LAN address

We are having occasional trouble with an IPsec/L2TP remote access VPN, provided by strongSwan (charon). Today a user was unable to connect. I viewed the charon log, and noticed that another existing session was impacted. The common part was the…
rwfbc
  • 131
  • 4
0
votes
0 answers

Vpn . Nps . Active directory . Strongswan ikev2

please help me I configured a strongswan IKEV2 On Centos7 vps and NPS and Active Directory for my authentication and accounting(radius) on windows server 2016 vps when i want to connect to my ikev2 vpn on windows 10 i get this error: the remote…