[strongSwan] ipsec connection fails: no matching peer config found

Michael Schwartzkopff ms at sys4.de
Fri Oct 18 11:37:46 CEST 2019


On 18.10.19 10:53, Tobias Brunner wrote:
> Hi Michael,
>
>> found the reason. I had rightid="muc.XXX.de" in my client config. The
>> logs do not show that the gateway ID is quoted. After removing the
>> quotes the connection came up.
> The quotes do not matter, unless they are some kind of typographic
> quotes like “ = U+201C or ” = U+201D (i.e. not " = U+0022).  However,
> you'd see that in the log (as ???).  So it's more likely you had a typo
> in the XXX part of that identity.
>
now it works with the quotes. Strange.

I checked the logs, but no visible difference in the XXX between these
two entries:

Oct 17 18:37:04 muc charon: 15[CFG] <108> looking for peer configs
matching 192.168.178.8[muc.XXX.de]...46.81.179.210[ms at XXX.de]

Oct 17 18:37:04 muc charon: 15[CFG] <108> no matching peer config found


and

Oct 18 10:06:01 muc charon: 09[CFG] <124> looking for peer configs
matching 192.168.178.8[muc.XXX.de]...217.111.91.203[ms at XXX.de]

Oct 18 10:06:01 muc charon: 09[CFG] <con-mobile|124> selected peer
config 'con-mobile'


Mit freundlichen Grüßen,

-- 

[*] sys4 AG
 
https://sys4.de, +49 (89) 30 90 46 64
Schleißheimer Straße 26/MG,80333 München
 
Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer, Wolfgang Stief
Aufsichtsratsvorsitzender: Florian Kirstein



More information about the Users mailing list