[strongSwan] vici initiator only or responder per connection

Tobias Brunner tobias at strongswan.org
Tue Apr 7 10:05:33 CEST 2020


Hi Naveen,

> I see that we have a global " *initiator_only = yes/no* " configuration
> in charon.conf, is it possible to configure this for per connection via
> vici, so that the initiator is only responsible for initiating the
> connection.

That option is global because it causes any initial IKE message to get
dropped very early.  But if you don't configure a single remote IP
address, a connection can't be used for initiation.

Regards,
Tobias


More information about the Users mailing list