[strongSwan] [Strongswan] no config named 'client'

Noel Kuntze noel at familie-kuntze.de
Mon Aug 18 15:13:16 CEST 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Amysue,

How that is done is described in the document linked to by the link with the number [1].
Here it is again: https://wiki.strongswan.org/projects/strongswan/wiki/LoggerConfiguration

Regards,
Noel Kuntze

GPG Key id: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658

Am 18.08.2014 um 15:08 schrieb amysue.z at gmail.com:
> Hi Noel,
> The output of "ipsec statusall" is 
> /Status of IKE charon daemon (strongSwan 5.0.2, Linux 2.6.18-348.1.1.el5, i686):/
> /  uptime: 14 minutes, since Aug 18 18:21:46 2014/
> /  malloc: sbrk 135168, mmap 0, used 86616, free 48552/
> /  worker threads: 8 of 16 idle, 7/1/0/0 working, job queue: 0/0/0/0, scheduled: 0/
> /  loaded plugins: charon aes des sha1 sha2 md5 random nonce x509 revocation constraints pubkey pkcs1 pkcs8 pgp dnskey pem fips-prf gmp xcbc cmac hmac attr kernel-netlink resolve socket-default stroke updown eap-md5 eap-radius xauth-generic/
> /Listening IP addresses:/
> /  192.168.2.6/
> /  12.12.1.203/
> /Connections:/
> /Security Associations (0 up, 0 connecting):/
> /  none/
> 
> And, how do I  enable logging[1] ? I don't use strongswan much, So it feel difficult for me.
> Thank you again for your help
> 
> 
> 
> 2014-08-18 21:02 GMT+08:00 Noel Kuntze <noel at familie-kuntze.de <mailto:noel at familie-kuntze.de>>:
> 
> Hello,
> 
> Check your system log for errors and show us the output of "ipsec statusall".
> Sometimes, it takes a couple of seconds for the daemon to load the configuration. Waiting a bit can help in this case.
> The reason for this is, that all the ipsec commands are asynchronous.
> If the configuration isn't loaded for a couple of seconds, please enable logging[1].
> StrongSwan can handle Mobike. It's a daemon thing, not a kernel thing.
> 
> [1] https://wiki.strongswan.org/projects/strongswan/wiki/LoggerConfiguration
> 
> Regards,
> Noel Kuntze
> 
> GPG Key id: 0x63EC6658
> Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658
> 
> Am 18.08.2014 um 14:56 schrieb amysue.z at gmail.com <mailto:amysue.z at gmail.com>:
>> Hello,
> 
>> My OS is centos 5.9 and i have installed Linux strongSwan U5.0.2/K2.6.18-348.1.1.el5.
>> After installation,i start strongswan:
>> ipsec start
>> then i up an connection:
>> ipsec up client
>> then I get an error:*no config named 'client'*
>> Actually, I define an connection in /etc/ipsec.conf.
> 
>> Below is my /etc/ipsec.conf
> 
>> /config setup/
>> /    strictcrlpolicy=no/
>> /    charonstart=yes/
>> /
>> /
>> /conn %default/
>> /    ikelifetime=28800s/
>> /    keylife=28800s/
>> /    rekeymargin=3m/
>> /    keyingtries=3/
>> /    keyexchange=ikev2/
>> /    ike=3des-sha1-modp1024/
>> /    esp=3des-sha1/
>> /
>> /
>> /conn client/
>> /    left=12.12.1.203/ <http://12.12.1.203/>
>> /    leftsourceip=%config/
>> /    leftcert=client1_cert.pem/
>> /    leftid="/C=CN/ST=SH/O=CS/CN=IKEv2_Client1"/
>> /    right=11.11.11.200/ <http://11.11.11.200/>
>> /    rightid="/C=CN/ST=SH/O=CS/CN=11.11.11.200"/
>> /    rightsubnet=192.168.168.0/24 <http://192.168.168.0/24> <http://192.168.168.0/24>/
>> /    auto=add/
>> /
>> /
>> I have no idea what to do now, I really need your help, any one could help me?
>>  Thank you very much
> 
> 
> 
>> _______________________________________________
>> Users mailing list
>> Users at lists.strongswan.org <mailto:Users at lists.strongswan.org>
>> https://lists.strongswan.org/mailman/listinfo/users
> 
>     _______________________________________________
>     Users mailing list
>     Users at lists.strongswan.org <mailto:Users at lists.strongswan.org>
>     https://lists.strongswan.org/mailman/listinfo/users
> 
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBAgAGBQJT8fvrAAoJEDg5KY9j7GZYg74P/1+ven3ZXaOGM/Dpp5ZH9+OS
q0//RsyQSYYm+rlusss5FCAKwn5WSCnGx8rfuMqOp+nKq974XA8NP7PQx/p/63q2
aSQDRg+zsU7Ub5KPVu1lVoP2B2kwR3FsfoTP1Qkp1U3eMW7uj+Cfx6TPENhXjnXA
xg0jmH9OC23bDXXOzlsZNGmH6/21Z6d/lJiCRLkOUa26B0F59CaFqRzOepO3wmiq
Y2gdxmy4tPPvQewTdlW8rsnUmhEmoYX5qXxdOjZoHoNCDpZmXoqsm+Gja8dQciQu
QQVa0OZLaO8utEVUpd24djmKv7vTXom7JE3njCzVqgkJqeKkfZD6eddUwRx0pMsl
DvkUPLB5OChSOkarVHjdOK7uywHFM0JMpTSUZPC3FGEsriBBNGEuZzPDaHUfioMX
Qu2UujJ9c73uHM8dcv4dhqQL33cUf1s3q4+R+IwdsaY0R423ynsFdgZGkA113iuB
lH6Y1DxGMwrzTL4wBmkzPPvkOL7CuKSpbtrRYCfvwX84RgzGYlP67yPfwB5CbyaE
wj+Ltn3qJmpULPzc5GdfWwV2wW2W5EYCWwWNSsaW2WCH/rE7y9a2IS30/8P4GNmp
nrmqmJ4wwfugSVp5rIB4TAkE56+19K9B3psL55hibR4mgy+RdGTe/URdQbHkgPM1
r6R9vJ0JE7XXNSlyriDP
=edOF
-----END PGP SIGNATURE-----


More information about the Users mailing list