[strongSwan] multiple peers with same certificate

SM K sacho.polo at gmail.com
Fri Sep 18 10:03:58 CEST 2015


Is it possible to have multiple firewalls connecting to a strongswan
instance with the same firewall. The certificate is used only for
authentication, and perhaps the ID is used identify each firewall. I
suspect the answer is no, because the ID is picked up from the certificate,
or has to be in the SAN of certifcate. I could not get this to work, but I
wanted to check in the forum once.

Maybe it is not possible with a strongswan initiator, but say a cisco
allows usage of an ID different from anything in the cert, would strongswan
as a responder have a problem?

