[strongSwan] Site-to-Site with Cisco devices

Tom Rymes trymes at rymes.com
Sat Nov 28 17:00:31 CET 2015

Before I start digging through the logs (more than I have already), I thought I would ask if there are some obvious recommended settings for connecting Strongswan to Cisco routers.

I am running Strongswan 5.3.2 as part of the IPfire distribution. This box hosts a dozen or so tunnels to other IPFire/Strongswan boxen, but each and every time I have attempted to create a tunnel to a Cisco Device (ATA or router), all of the existing tunnels drop and will not come back up. Sometimes restarting Strongswan will bring it all back up, but only for a short while, when all of the non-Cisco tunnels drop again.

I'm more than happy to start pulling configurations and logs, but before I do, I thought I would ask if anyone has already invented this wheel and/or gotten past this stumbling block, as I have yet to encounter anything in the archives or out there on the web.

Many thanks,


