[strongSwan] Proposal Logging

Andreas Steffen andreas.steffen at strongswan.org
Thu Oct 16 18:37:13 CEST 2014


Hi Brian,

the following line in ipsec.conf

  charondebug="cfg 2"

should do the job as the following example scenario shows:

http://www.strongswan.org/uml/testresults5dr/ikev2/alg-blowfish/

Oct  6 19:46:41 moon charon:
04[CFG] received proposals:
ESP:BLOWFISH_CBC_192/HMAC_SHA2_256_128/NO_EXT_SEQ
04[CFG] configured proposals:
ESP:BLOWFISH_CBC_192/HMAC_SHA2_256_128/NO_EXT_SEQ,
ESP:BLOWFISH_CBC_128/HMAC_SHA1_96/NO_EXT_SEQ
04[CFG] selected proposal: ESP:BLOWFISH_CBC_192/HMAC_SHA2_256_128/NO_EXT_SEQ

Best regards

Andreas

On 10/16/2014 05:31 PM, Brian Watson wrote:
> Hi,
>    I want to debug the following problem:
> 
> 1. ipsec.conf has esp=aes256
> 2. I try to establish a VPN connection initiated by my handset and
> StrongSwan responds with No Proposal Chosen
> 3. I would like to see what the problem is by seeing what the proposals are.
> 4. I set cfg, mgr, ike,esp,knl, etc to be equal to 4 in strongswan.conf
> for filelog in order to get more detailed information from the logs, but
> it still doesn't show the proposals.
> 
> Any ideas as to what I might be doing wrong?
> 
> Thanks,
>    Brian
> 
======================================================================
Andreas Steffen                         andreas.steffen at strongswan.org
strongSwan - the Open Source VPN Solution!          www.strongswan.org
Institute for Internet Technologies and Applications
University of Applied Sciences Rapperswil
CH-8640 Rapperswil (Switzerland)
===========================================================[ITA-HSR]==

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4255 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20141016/aa06779d/attachment.bin>


More information about the Users mailing list