[strongSwan] EC2 > Cisco VPN 3000

Martin Willi martin at strongswan.org
Fri May 9 08:37:36 CEST 2014


> I am struggling to successfully connect to a Cisco VPN 3000
> Concentrator

> leftsubnet=xx.xx.xx.238/32,xx.xx.xx.255/32
> leftsourceip=%config

Is it your intention to request a virtual IP, even if you are doing
net-to-net tunneling? Usually virtual IPs are used by road-warriors,
clients that should be integrated to the local network.

> modeconfig=push

Please be aware that push mode has not been supported until 5.1.1.

> The security association is established however the connection doesn’t
> appear to get fully established, getting stuck on QUICK_MODE.

A log output would certainly help to see what is going on and why the
Quick Mode doesn't proceed.


More information about the Users mailing list