[strongSwan] forecast iptables commit failed: Invalid argument

Meduri Siva Prasad sivaprasad at freescale.com
Thu Jun 18 12:25:17 CEST 2015

Hi Martin,

Thanks for the reply. We are working on ARM platform with kernel 3.2. Kernel also supports udp/esp as match fields and MARK as target. Any inputs for debugging will be a great help.
BTW we are testing this in site-to-site deployment. But as per documentation, it talks only for client-to-site deployments. Does this work in site-to-site deployments? 


-----Original Message-----
From: Martin Willi [mailto:martin at strongswan.org] 
Sent: Thursday, June 18, 2015 1:48 PM
To: Meduri Siva Prasad-B51161
Cc: users at lists.strongswan.org; Chaitanya Sakinam-B36933; Pothuganti Sridhar-B38513
Subject: Re: [strongSwan] forecast iptables commit failed: Invalid argument


> OpenWrt daemon.info charon: 15[CFG] forecast iptables commit failed: 
> Invalid argument

Please check that your kernel supports the MARK target and the udp/esp matches.

What architecture is OpenWRT running on? Not unlikely that it is an alignment issue, I didn't test the plugin beyond x86/x64.


More information about the Users mailing list