I need to create a site-to-site VPN with a remote VPC (IKEv2 + IPSec). Both sides use some web resources of the other, those services hostnames are mapped to IPs using a DNS server (one on each side). Side A uses Fortigate, Side B uses…
I have a basic network setup with k8s cluster containing worker pods that have to read from meters contained within another network:
My question is, how to set up policy based ipsec tunnel from k8s network to on premise one in such a way that all…
I am on Fedora 31, I am trying to connect to a VPN that uses IKEv2 via strongswan. But I get [IKE] received NO_PROPOSAL_CHOSEN notify the error. I used the following tutorial…
We have an openstack cluster build with openstack ansible, we are very happy with it. Actually i am trying to set an VPN. We have activate all necessary thing and tried successfully between our openstack and a sonicwall. We are trying now with a…
I am new to Ipsec/Ikev2 concept.
I am trying to create a Ipsec/IKEv2 connection between Windows 10 and SUSE SELES 12 box using strong swan.
Right now i don't have ipsec configuration information of SUSE box. but i can tell you my observation and…
I have 2 strongswan connected, each can ping the other.
My problem comes when either of the subnets want to ping an ip on the other side, it doesn't happen.
I know i need to add some masquerading but i can't figure out how (i have added the routes…
I was exploring the IKEv2 StrongSwan client implementation for Android. What I fail to understand is that Android and Java do not support raw sockets, whilst the IKEv2 / IPSec works below Transport layer, which seems counter-intuitive. How exactly…
I am able to use python3-vici in the global namespace, suppose I want to route it through a particular namespace say, /var/run/x/x/vpn, how do I do that?
I have charon.ctl, charon.pid, ipsec.conf, ipsec.d, starter.charon.pid, …
I have a VPC and subnets in it.
I have an EC2 instance that works as VPC Gateway and routed all traffic inside VPC using Route Table.
So the requests from subnets to partners' network are reaching to the Gateway instance.
There on Gateway instance…
Trying to import open source StrongswanVPN project as library in my project (StrongSwanVPN is also an application on playstore), my application working fine with this library, but I can only install one application, either my application or…
We've authored a plugin for libcharon that makes calls to our code. This is creating some unwanted coupling between our application and strongswan, since we're compiling strongswan with this plugin.
Let's call this plugin MyPlugin.
It is configured…
We want to setup StrongSwan VPN with FreeRadius for authentication. In addition to that we want to assign different subnets to users based on AD-Groups. StrongSwan uses the class attribute in a access-accept reply for that…
with the new stongswan module we get the following log message every second.
Is there a possibility to turn off these messages in the strongswan log ?
What does this message mean?
2017-12-12 08:20:29 12[CFG] proposing traffic selectors for…