<div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif">Hello Tobias,</div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">I managed to pick <b>10.10.10.1</b> from the server, after restarting StrongSwan from the client. However, I cant telnet port 80, might be a port forwarding issue. One question, I would like to ask is, how come the VPN server never gets assigned a private IP?</div><div class="gmail_default" style="font-family:tahoma,sans-serif">What can I ping on the server from the client apart from the server's public IP that can be used to ascertain the VPN connection?</div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">As always, thanks a lot for your help.</div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">Moses K </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Feb 25, 2019 at 1:50 PM Tobias Brunner <<a href="mailto:tobias@strongswan.org">tobias@strongswan.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Moses,<br>
<br>
> Security Associations (1 up, 0 connecting):<br>
> ikev2-vpn[21]: ESTABLISHED 41 minutes ago, 102.1*9.2**.***[<br>
> 102.1*9.2**.***]... 185.135.*.** [remoteprivate]<br>
> ikev2-vpn[21]: IKEv2 SPIs: 0338f500edc84652_i 1ae30618408f64a4_r*,<br>
> rekeying disabled<br>
> ikev2-vpn[21]: IKE proposal:<br>
> AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_2048<br>
<br>
You don't have any CHILD_SAs established. Check the logs.<br>
<br>
Regards,<br>
Tobias<br>
</blockquote></div>