[strongSwan] left|rightikeport obsolete?

Harald Dunkel harald.dunkel at aixigo.de
Mon Jul 23 15:44:53 CEST 2018


Hi folks,

the documentation say for left|rightikeport

"If unspecified, port 500 is used with the port floating to 4500 if a
NAT is detected ..."

This sounds pretty vague. I would like to tell strongswan to use 443/udp
for NAT traversal and dead peer detection, and to use port 500/udp for
isakmp as usual. AFAICT this can be done with charon.port and charon.\
port_nat_t, so I wonder what is left|rightikeport good for?


Every insightful comment is highly appreciated
Harri


More information about the Users mailing list