[strongSwan] Certificate authentication issue

Noel Kuntze noel at familie-kuntze.de
Fri Oct 28 17:08:53 CEST 2016


On 28.10.2016 10:28, Joe O wrote:
> “Deleting half open IKE_SA after timeout message”

I don't see that message in the log you posted. It generally means that the other peer did not respond
to an IKE message when it should have.

You should add "fragmentation=yes" to all conns (or add it to a conn that you include in all others)
to avoid problems with UDP fragmentation.

-- 

Mit freundlichen Grüßen/Kind Regards,
Noel Kuntze

GPG Key ID: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20161028/7cf83427/attachment.sig>


More information about the Users mailing list