[strongSwan] Problem observed during traffic selector narrowing

Martin Willi martin at strongswan.org
Tue Jun 11 12:10:13 CEST 2013


Hi,

>   rightprotoport=any
>   leftprotoport=any

That's not a valid configuration, and fails here with:

> # bad protocol: leftprotoport=any
> # bad protocol: rightprotoport=any

If you want to have any protocol/port combination in the traffic
selectors, use "%any", or omit the keyword completely. man ipsec.conf
for details.

Regards
Martin





More information about the Users mailing list