Please start off with an example configuration from the UsableExamples page.

If the connection times out during the IKE negotiation, either your firewall is configured incorrectly or something else on your side.
It could also be that you need to enable fragmentation for IKE. That's enabled for default for a couple of versions already.

Am 17.07.19 um 10:45 schrieb Old Kid:
> Hello all,
> My Windows 10 computer can connect to my strongswan server, though it has some weird behavoirs, it works at least. I need to share the VPN adapter's with Wifi, reset Wifi to DHCP, connect Wifi and VPN. Only after that I get a PPP adapter with default gateway . But on Linux there is no route at all,
> I use NetworkManager + strongswan plugin, after it connects I have:
> default via dev wlp3s0 proto dhcp metric 600 dev wlp3s0 proto dhcp scope link src metric 304 dev wlp3s0 proto kernel scope link src metric 600 dev wlp3s0 proto kernel scope link src metric 50 dev wlp3s0 proto kernel scope link src metric 600 avatar at archlinux:~$
> I don't understand what the first column means. I think it's supposed to be a subnet. And I don't think I can add a default route with this manually. In addtion, the strongswan android client can't connect at all, it says "giving up after 3 retransmits, establishing IKE_SA failed, peer not responding". Is there something with this configuration?
> conn ikev2-vpn
>        auto=route
>        compress=no
>        type=tunnel
>        keyexchange=ikev2
>        ike=aes256-aes128-sha256-sha1-modp3072-modp2048-modp1024
>        fragmentation=yes
>        forceencaps=yes
>        dpdaction=clear
>        dpddelay=300s
>        left=%any
>        leftid=@ipsecserver.com
>        leftcert=ipsecserver.pem
>        leftsendcert=always
>        leftsubnet=
>        right=%any
>        rightid=%any
>        rightauth=eap-mschapv2
>        leftsourceip=
>        rightsourceip=
>        rightdns=,
>        rightsendcert=never
>        eap_identity=%identity

