[strongSwan] Right hosts

Andreas Steffen andreas.steffen at strongswan.org
Tue Jul 10 13:45:26 CEST 2012

Ok I see. Checkpoint gets the proposal


from strongSwan and narrows it down to


In this case the only alternative is to define two
separate CHILD_SAs as described in my earlier posting.



On 07/10/2012 01:36 PM, Pedro José Bello Valiñas wrote:
> Hi Andreas,
> Yes, we are selecting IKEv2 protocol.
> On the remote endpoint (Checkpoint) the same configuration is set.
> Is it possible to be failing on interoperability?
> Regards,
> Pedro.
> -----Mensaje original-----
> De: Andreas Steffen [mailto:andreas.steffen at strongswan.org] 
> Enviado el: martes, 10 de julio de 2012 8:17
> Para: pedro.bello at tic.alten.es
> CC: users at lists.strongswan.org
> Asunto: Re: [strongSwan] Right hosts
> Hi Pedro,
> are you sure that you chose the IKEv2 protocol since IKEv1 does
> not support this concatenation of subnets.
> Regards
> Andreas
> On 10.07.2012 08:29, Pedro José Bello Valiñas wrote:
>> De: Pedro José Bello Valiñas [mailto:pedro.bello at tic.alten.es] 

Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)

More information about the Users mailing list