[strongSwan] no payload on android application

eyas barhouk eyas37 at hotmail.com
Tue Oct 30 15:39:13 CET 2018


hello dears,


i'm new to strongswan and trying to build a vpn between ubuntu  and android clients.

i followed this tutorial :

https://www.digitalocean.com/community/tutorials/how-to-set-up-an-ikev2-vpn-server-with-strongswan-on-ubuntu-18-04-2

and the connection up but there is no traffic pass from the application (android client) to the server,

and in the following you can find the statue of the tunnel:

# ipsec statusall
Status of IKE charon daemon (strongSwan 5.3.5, Linux 4.4.0-138-generic, x86_64):
  uptime: 32 minutes, since Oct 30 10:01:28 2018
  malloc: sbrk 3284992, mmap 532480, used 1078704, free 2206288
  worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 2
  loaded plugins: charon test-vectors unbound ldap pkcs11 aes rc2 sha1 sha2 md4 md5 random nonce x509 revocation constraints acert pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp dnskey sshkey dnscert ipseckey pem openssl gcrypt af-alg fips-prf gmp agent chapoly xcbc cmac hmac ctr ccm gcm ntru bliss curl soup mysql sqlite attr kernel-netlink resolve socket-default connmark farp stroke updown eap-identity eap-sim eap-sim-pcsc eap-aka eap-aka-3gpp2 eap-simaka-pseudonym eap-simaka-reauth eap-md5 eap-gtc eap-mschapv2 eap-dynamic eap-radius eap-tls eap-ttls eap-peap eap-tnc xauth-generic xauth-eap xauth-pam xauth-noauth tnc-tnccs tnccs-20 tnccs-11 tnccs-dynamic dhcp whitelist lookip error-notify certexpire led radattr addrblock unity
Virtual IP pools (size/online/offline):
  0.0.0.0/0: 2147483646/1/0
Listening IP addresses:
  10.192.129.171
  10.199.183.215
Connections:
   ikev2-vpn:  %any...%any  IKEv2, dpddelay=300s
   ikev2-vpn:   local:  [10.192.129.171] uses public key authentication
   ikev2-vpn:    cert:  "CN=10.192.129.171"
   ikev2-vpn:   remote: uses EAP_MSCHAPV2 authentication with EAP identity '%any'
   ikev2-vpn:   child:  0.0.0.0/0 === dynamic TUNNEL, dpdaction=clear
Security Associations (1 up, 0 connecting):
   ikev2-vpn[10]: ESTABLISHED 2 seconds ago, 10.192.129.171[10.192.129.171]...10.137.113.75[EYAS]
   ikev2-vpn[10]: IKEv2 SPIs: c3017f0ec4f1b443_i 07005129d36627b1_r*, rekeying disabled
   ikev2-vpn[10]: IKE proposal: AES_CBC_256/HMAC_SHA2_384_192/PRF_HMAC_SHA2_384/ECP_384
   ikev2-vpn{4}:  INSTALLED, TUNNEL, reqid 4, ESP in UDP SPIs: c15502dd_i be84cbab_o
   ikev2-vpn{4}:  AES_CBC_128/HMAC_SHA1_96, 0 bytes_i, 0 bytes_o, rekeying disabled
   ikev2-vpn{4}:   0.0.0.0/0 === 0.0.0.1/32


So has any one faced the same issue before (the VPN connection up on android client but there is no traffic pass from the client to the server after that), and how to solve it .

thanks in advance
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20181030/ec59d9cf/attachment.html>


More information about the Users mailing list