[strongSwan] GMP/dh-group issue

Mohammadreza Ataei mrz.ataei at gmail.com
Fri Sep 16 21:43:21 CEST 2016


I am quite new to stongswan, and I was able to bring up IKEv1 tunnels with
version 5.0.1 using a linux box running CentOS (2.6.32-358).

When I did the exact same things (running the same binary from network, and
the same config files), on a different linux machine (running CentOS
3.10.0-229) I saw:

negotiated DH group not supported

which I believe is because I don't have any dh-group algorithms known to

("ipsec listalgs" shows dh-group algorithms on the linux working fine, but
it is empty on the linux not working)

I installed "gmp-devel" on the linux box, and yet I see nothing in dh-group

Would you please tell me how I can tell strongswan to use the installed
gmp? Or do I have to install another package? Is there any specific gmp
package that I have to install?

I am confused and stuck! Please help.

