[strongSwan] establish secure connection without ike

Diego Woitasen diego at woitasen.com.ar
Sat Oct 1 21:03:54 CEST 2011


On Sat, Oct 1, 2011 at 2:30 PM, nima chavooshi <nima0102 at gmail.com> wrote:
> hi
> first of all excuse me for dummy question.
> When I started to reading about IPSsec, i have understand that ike is for
> generate and exchange of SA and other critical information for creating
> tuunel.
> Is it possible that I generate those needed information manually and put on
> endpoint tunnel in order to remove completely ike phases?in fact i want to
> remove ike phases and requirement information are hardcoded on endpoints.
>
> thanks for any help or guidance.
>
>
> _______________________________________________
> Users mailing list
> Users at lists.strongswan.org
> https://lists.strongswan.org/mailman/listinfo/users
>

Yes, it's possible. Not a good idea but possible. Have a look to the
"ip xfrm" command o use ipsec-tools (and the setkey command).

Regards,
 Diego

-- 
Diego Woitasen




More information about the Users mailing list