[strongSwan] Matching Cisco "esp-3des esp-sha256-hmac" to strongswan config

Adam Cécile acecile at le-vert.net
Wed Jan 5 11:12:10 CET 2022


Hello,


I'm replacing a Cisco endpoint with Strongswan sadly all I tried ended 
up in NO_PROPOSAL_CHOSEN...

The relevant Cisco bits (which is connecting with peer just fine) is: 
crypto ipsec transform-set TunnelName esp-3des esp-sha256-hmac


Can someone help me converting this into Strongswan ike/esp config 
options (and I also would be very interested in understanding how to do 
such conversion...)


Thanks in advance,

Best regards, Adam.



More information about the Users mailing list