Noel Kuntze noel at familie-kuntze.de
Thu Feb 9 18:41:38 CET 2017

Am 09.02.2017 um 18:39 schrieb Alexander Hill:
> I get connections apparently up, I see them in the output of ipsec status and ipsec leases, but no traffic across the link. Set compress=no on the server and issue ipsec reload, and the clients connect and communicate fine.

Read the part in the FAQ about IPsec and iptables/nftables[1].
Quote: "Packets that are compressed using the ipcomp option pass through some chains three times. 
Once as encapsulated packet, then as IP-in-IP packet and then as the actual packet. 
The protocol number depends on the encapsulated protocol. You need to allow the protocols in iptables and 
ip6tables depending on your tunnel configuration."

[1] https://wiki.strongswan.org/projects/strongswan/wiki/FAQ#IPsec-and-iptablesnftables


