[strongSwan] UDP source port in initiator's IKE_SA_INIT message

Mao, Zhiheng zmao at qti.qualcomm.com
Thu Mar 7 08:13:32 CET 2013


I am experiencing a case where the tcpdump shows that the initiator's IKE_SA_INIT message arrives at the eth0 interface, but the strongswan server's log does not show any receiving and processing activity. In this case, the initiator uses a random UDP port number instead of 500 as the source port. The destination port is 500.

Does strongswan server silently drop this UDP packet? Is server required to do so? Which log (CFG, NET, ENC, KNL, etc) should I turn higher in order to see a message being dropped by the server, if it is being dropped?

Thank you for the clarification!

Zhiheng Mao
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20130307/3e318d38/attachment.html>

More information about the Users mailing list