[strongSwan] Right hosts

Andreas Steffen andreas.steffen at strongswan.org
Tue Jul 10 13:45:26 CEST 2012


Ok I see. Checkpoint gets the proposal

  rightsubnet=192.168.1.35/32,192.168.1.36/32

from strongSwan and narrows it down to

  rightsubnet=192.168.1.35/32

In this case the only alternative is to define two
separate CHILD_SAs as described in my earlier posting.

Regards

Andreas

On 07/10/2012 01:36 PM, Pedro José Bello Valiñas wrote:
> Hi Andreas,
> Yes, we are selecting IKEv2 protocol.
> 
> On the remote endpoint (Checkpoint) the same configuration is set.
> 
> Is it possible to be failing on interoperability?
> 
> Regards,
> Pedro.
> 
> -----Mensaje original-----
> De: Andreas Steffen [mailto:andreas.steffen at strongswan.org] 
> Enviado el: martes, 10 de julio de 2012 8:17
> Para: pedro.bello at tic.alten.es
> CC: users at lists.strongswan.org
> Asunto: Re: [strongSwan] Right hosts
> 
> Hi Pedro,
> 
> are you sure that you chose the IKEv2 protocol since IKEv1 does
> not support this concatenation of subnets.
> 
> Regards
> 
> Andreas
> 
> On 10.07.2012 08:29, Pedro José Bello Valiñas wrote:
>> De: Pedro José Bello Valiñas [mailto:pedro.bello at tic.alten.es] 

======================================================================
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==






More information about the Users mailing list