[strongSwan] ipsec.conf for tunnel+ah and transport+ah

Andreas Steffen andreas.steffen at strongswan.org
Mon Jul 30 06:18:43 CEST 2012

Hi Vincent,

strongSwan does not support AH. If you want authentication without
encryption then choose esp=null-sha1 or esp=aes128-gmac.



On 07/30/2012 04:43 AM, wenrongbupt wrote:
> Hi guys,
> I have configured Strongswan for tunnel+esp and transport+esp, but I do
> not know how to configure Strongswan for tunnel+ah and transport+ah.
> I have read this url:
> http://wiki.strongswan.org/projects/strongswan/wiki/ConnSection . It
> seems no configure for AH separately. I just want to configure AH in
> tunnel and transport mode. Could you please tell me how configure it?
> It's better to send a example ipsec.conf file to me. Thank you very much.
> Regards
> Vincent
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Linux VPN Solution!                www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)

More information about the Users mailing list