[strongSwan] Qn - Strongswan IKEv2 + Transport mode + NAT

Anoop V A (anova) anova at cisco.com
Mon Oct 8 07:13:13 CEST 2012


Hi Experts,

      I  am facing a problem while configuring strong swan IKEv2 with Transport mode and Nat in b/w.  What I can see from the logs is strong swan is not sending the USE_TRANSPORT_MODE notify, and looks like its proposing the Tunnel mode. Because of this, the server is saying "NO PROPOSAL CHOOSEN".

My IPSec config:
(Example)
  conn host-host
        left=10.0.0.1
        right=20.0.0.2
        type=transport
        auto=add

I would like to know, is it done purpose fully, or am I  doing something wrong with the configuration? Or is it like TRANSPORT Mode + NAT is not supported by IKEv2? Because I saw some thread saying, if NAT is involved, strong swan IKEv2 automatically switches to Tunnel Mode(Thread from 2010 - so just to confirm this).

Thanks in advance

Regards
Anoop
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20121008/e13a1544/attachment.html>


More information about the Users mailing list