Re: IKEV2 two devices can connect but only one can make traffic

2022-04-12 Thread Ettore Tagarelli
Issue solved updating my linux strongswan client!!! Sorry for the trouble... Thanks to everybody 😊

Re: IKEV2 two devices can connect but only one can make traffic

2022-04-12 Thread Ettore Tagarelli
Updated to 7.0 ...same problem 🙁

Fwd: IKEV2 two devices can connect but only one can make traffic

2022-04-11 Thread Ettore Tagarelli
-- Forwarded message - Da: Ettore Tagarelli Date: mar 12 apr 2022 alle ore 01:03 Subject: Re: IKEV2 two devices can connect but only one can make traffic To: If I use the "dynamic keyword I get this error: "no IP address found for dynamic" though "config add

IKEV2 two devices can connect but only one can make traffic

2022-04-11 Thread Ettore Tagarelli
If I use the "dynamic keyword I get this error: "no IP address found for dynamic" though "config address 192.168.98.1/24" is there. Using 0.0.0.0/32 instead of 0.0.0.0/0 causes that traffic is not routed ('cause /32 restrict the only address possible to 0.0.0.0) though connection happens correctly.

Re: IKEV2 two devices can connect but only one can make traffic

2022-04-11 Thread Ettore Tagarelli
this is my iked.conf as far as I know the "somename" Stuart wrote about is automatically added by iked. user "cash" "password1" user "phosh" "password2" ikev2 passive esp \ from 0.0.0.0/0 to 192.168.98.1/24 \ local 192.168.99.3 peer any \ eap "mschap-v2" \

IKEV2 two devices can connect but only one can make traffic

2022-04-11 Thread Ettore Tagarelli
Hello, I've an Openbsd 6.6 machine with IKEV2. I always used it with only one client connected and it always worked. Trying to connect with two clients (behind the same NAT) I found out that the connection seems established but only one client works. Can anybody help me? Thanks 😊

ikev2 configuration on per-user basis with different policies

2022-04-10 Thread Ettore Tagarelli
Hello, I configured an Openbsd system as a VPN server with IKEV2. It works great but I'd like to use a configuration with different policies on per-user basis. The clients connect from dynamic ip. Does anybody have any hint or alternative? thanks 😊