[strongSwan] Setup client using main mode/draft-ietf-ipsec-nat-t-ike-02

Martin Willi martin at strongswan.org
Mon Jun 10 10:45:08 CEST 2013


Damien,

Please try to keep the discussion on the list.

> initiating Main Mode IKE_SA tst[4] to x.x.x.x
> generating ID_PROT request 0 [ SA V V V V ]
> sending packet: from y.y.y.y[500] to x.x.x.x[500] (220 bytes)
> received packet: from x.x.x.x[500] to y.y.y.y[500] (160 bytes)
> parsed INFORMATIONAL_V1 request 0 [ N(NO_PROP) ]
> received NO_PROPOSAL_CHOSEN error notify

Looks like the responder does not like the contents of the SA payload. 

> I can dump packets exchanged between the windows client
> and the server.

Try to get a little more details about the SA payload when using the
Windows client. That should give some hints if a different set of
algorithms or authentication methods have to be used.

Regards
Martin





More information about the Users mailing list