[strongSwan] Windows 7 seems to drop connection when rekeying main mode SA's

Martin Willi martin at strongswan.org
Wed Jan 11 12:53:51 CET 2012


>   activating IKE_REKEY task
> initiating IKE_SA rw-win-7[4] to
> received DELETE for IKE_SA rw-win-7[3]

Your log level configuration doesn't show any messages, but it seems
that Windows is not happy about the rekeying and deletes the SA.

> I also tried with and without reauth and it did not change the results.

Reauth is not possible, it can't be initiated by the gateway (as we are
using EAP) and Windows does not support the reauthentication lifetime

> conn rw-win-7
>         leftsubnet=
>         right=%any
>         rightsourceip=
>         rightid="[...]"
>         auto=add
>         esp=aes256-sha1
>         ikelifetime=90m
>         reauth=no

I don't see an ike= proposal definition, strongSwan will default to
modp2048. Windows does not support that, try it with modp1024.


