[strongSwan] configuring gcm mode on android

Tobias Brunner tobias at strongswan.org
Thu Jan 12 18:53:28 CET 2012


Hi Bill,

> Jan 12 12:11:24 14[CFG] received proposals:
> ESP:AES_CBC_128/AES_CBC_192/AES_CBC_256/3DES_CBC/BLOWFISH_CBC_256/HMAC_SHA1_96/AES_XCBC_96/HMAC_MD5_96/NO_EXT_SEQ
> Jan 12 12:11:24 14[CFG] configured proposals: ESP:AES_GCM_16_128/NO_EXT_SEQ
> Jan 12 12:11:24 14[IKE] no acceptable proposal found

You configured esp=aes128cgm16-sha256! on the gateway but did not do so
on the client.  Therefore, the client sends its default proposal which
does not include AES-GCM.  Hence, no matching proposal is found.

Regards,
Tobias




More information about the Users mailing list