<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div class=""><a href="https://wiki.strongswan.org/issues/1098" class="">https://wiki.strongswan.org/issues/1098</a></div><div class=""><br class=""></div><div class=""><h4 style="font-family: "Trebuchet MS", Verdana, sans-serif; padding: 2px 10px 1px 0px; margin: 0px 0px 10px; color: rgb(85, 85, 85); font-size: 13px; border-bottom-width: 1px; border-bottom-style: dotted; border-bottom-color: rgb(187, 187, 187); font-variant-ligatures: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255);" class=""><a class="user active" href="https://wiki.strongswan.org/users/8" style="color: rgb(138, 0, 32); text-decoration: none;">Tobias Brunner</a> <a title="07.09.2015 11:09" href="https://wiki.strongswan.org/projects/strongswan/activity?from=2015-09-07" style="color: rgb(138, 0, 32); text-decoration: none;" class="">almost 3 years</a> ago<span id="journal-4350-private_notes" class=""></span></h4><ul class="details" style="color: rgb(149, 149, 149); margin-bottom: 1.5em; font-family: Verdana, sans-serif; font-size: 10.8px; font-variant-ligatures: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255);"><li class=""><strong class="">Status</strong> changed from <i class="">New</i> to <i class="">Feedback</i></li><li class=""><strong class="">Priority</strong> changed from <i class="">High</i> to <i class="">Normal</i></li></ul><div id="journal-4350-notes" class="wiki" style="color: rgb(54, 0, 12); font-family: Verdana, sans-serif; font-size: 10.8px; font-variant-ligatures: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255);"><p class="">There is a <a class="wiki-page" href="https://wiki.strongswan.org/projects/strongswan/wiki/DHCPPlugin" style="color: rgb(138, 0, 32); text-decoration: none; word-wrap: break-word; font-weight: bold;">DHCP plugin</a> to <u class="">assign virtual IPs and DNS servers to clients</u> that are requested by the strongSwan server via DHCP on behalf of the clients. If you are considering DHCP over IPsec there is a configuration attribute called <code style="font-family: Consolas, Menlo, "Liberation Mono", Courier, monospace; background-color: rgb(238, 238, 238); padding: 1px 2px;" class="">INTERNAL_IP4_DHCP</code> but strongSwan has no support for that as client (i.e. it won't request it). And as server you can only assign it globally via the <a class="wiki-page" href="https://wiki.strongswan.org/projects/strongswan/wiki/Attrplugin" style="color: rgb(138, 0, 32); text-decoration: none; word-wrap: break-word; font-weight: bold;">attr</a> or the <a class="wiki-page" href="https://wiki.strongswan.org/projects/strongswan/wiki/Attrsql" style="color: rgb(138, 0, 32); text-decoration: none; word-wrap: break-word; font-weight: bold;">attr-sql</a> plugins. Also </p><div class=""><br class=""></div></div></div><br class=""><div class="">
<div dir="auto" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="caret-color: rgb(0, 0, 0); letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div dir="auto" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">Kind regards,<br class=""><br class=""><b style="color: rgb(0, 0, 0);" class="">Christian Salway</b><br class="">IT Consultant - <b class=""><font color="#f05a28" class="">Naimuri</font></b><br class=""><br class=""><font color="#919191" class="">T: +44 7463 331432<br class="">E: <a href="mailto:christian.salway@naimuri.com" class="">christian.salway@naimuri.com</a><br class="">A: Naimuri Ltd, Chandlers Point, Manchester M50 2UW</font></div></div></div></div></div></div></div>
</div>
<div><br class=""><blockquote type="cite" class=""><div class="">On 9 Aug 2018, at 07:13, Noel Kuntze <<a href="mailto:noel.kuntze+strongswan-users-ml@thermi.consulting" class="">noel.kuntze+strongswan-users-ml@thermi.consulting</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">It's because you're doing it wrong. You must *not* use the dhcp plugin of strongSwan to request the IP. Have Windows do a DHCP request over the VPN (according to the article it should do that). The dhcp plugin does something completely different.<br class=""><br class="">On 09.08.2018 08:07, Christian Salway wrote:<br class=""><blockquote type="cite" class="">Perhaps the answer is to set the attr DHCP to the IP of the DHCP server inside the VPN but then still, how does the client know how to route to the IP address.<br class=""><br class="">There doesn’t seem to be a solution for this even though all the parts are there.<br class=""><br class=""><blockquote type="cite" class="">On 8 Aug 2018, at 15:15, Noel Kuntze <<a href="mailto:noel.kuntze+strongswan-users-ml@thermi.consulting" class="">noel.kuntze+strongswan-users-ml@thermi.consulting</a>> wrote:<br class=""><br class="">Hello Christian,<br class=""><br class="">I guess the native Mac OSX client just doesn't support being connected to more than one server, so this can't be solved with it.<br class=""><br class="">For Windows, you need to setup and run a DHCP server on the VPN server, which answers the DHCP requests that Windows (uniquely and only Windows!) sends over the VPN. You can use that to push routes to the client. Just use the same options as with "real" DHCP clients, requesting configuration from/on the LAN. This is described in the article about Windows interoperability[1].<br class=""><br class="">[1] <a href="https://wiki.strongswan.org/projects/strongswan/wiki/WindowsClients#Split-routing-on-Windows-10-and-Windows-10-Mobile" class="">https://wiki.strongswan.org/projects/strongswan/wiki/WindowsClients#Split-routing-on-Windows-10-and-Windows-10-Mobile</a><br class=""><br class="">Kind regards<br class=""><br class="">Noel<br class=""><br class=""><blockquote type="cite" class="">On 07.08.2018 09:07, Christian Salway wrote:<br class="">Hello all,<br class=""><br class="">After several months of using strongSwan, I still can't get the routing to work correctly on the clients. I have run out of pages to read on the strongswan website so I hope you can help me out.<br class=""><br class="">The problem is when I connect to strongSwan, the routing is not configured correctly on the clients (OSX and Windows) - using native (built-in) clients. All updated with the latest patches/updates.<br class=""><br class="">OSX will set up a route based on the local_ts but when I open a simultaneous connection to another strongSwan server, it removes the route from the first VPN connection and adds it's own based on the local_ts.<br class=""><br class="">WINDOWS doesnt add the route at all.<br class=""><br class="">In either cause, I normally have to manually add the routes in.<br class=""><br class="">Has anyone had any success? Can they please shed some light as to how they achieved it?<br class=""><br class=""><br class="">Kind regards,<br class=""><br class="">*Christian Salway*<br class="">IT Consultant - *Naimuri*<br class=""><br class="">T: +44 7463 331432<br class="">E: <a href="mailto:christian.salway@naimuri.com" class="">christian.salway@naimuri.com</a> <<a href="mailto:christian.salway@naimuri.com" class="">mailto:christian.salway@naimuri.com</a>><br class="">A: Naimuri Ltd, Chandlers Point, Manchester M50 2UW<br class=""><br class=""></blockquote><br class=""></blockquote></blockquote><br class=""></div></div></blockquote></div><br class=""></body></html>