[strongSwan] [Strongswan]Regarding Strongswan debugging logs

SaRaVanAn saravanan.nagarajan87 at gmail.com
Thu Oct 18 07:53:50 CEST 2012


Hi,
   I m trying to form a IKEv1 tunnel with strongswan from Netgear with NAT
device in between. But I am getting
hash mismatch in phase2 second message(Sent by strongswan) of quick mode.

Is there any logs in strongswan to debug/print, what are the values used
for  hash(2) computation in quick mode,
so that I just compare those values with incoming packet in Netgear and I
could find out what went wrong.?
Strongswan logs are showing the computed HASH value, but I want to see the
values for computation.

Topology
_________

Netgear --------------NAT device(Masquerading) ---- Strongswan
35.0.0.1    35.0.0.2               172.31.114.227      172.31.114.246
                                          (NAT-ed IP)

 I have an another question here, whether NAT plays any role
in HASH(2) computation in quick mode, because  IKE negotiation is success
without NAT device in between.
Please help me to solve this problem


Regards,
Saravanan N
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20121018/90bc0a2b/attachment.html>


More information about the Users mailing list