[prev in list] [next in list] [prev in thread] [next in thread] 

List:       strongswan-users
Subject:    Re: [strongSwan] [Strongswan] no config named 'client'
From:       <amysue.z () gmail ! com>
Date:       2014-08-19 7:18:31
Message-ID: CALDwwqK=wtwZv-ATYWBrFTrr8qCEa=KYPDvaspny4w6M4uKSig () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Hi Noel, Andreas

Now my strongswan is working well now.
Thank you verry much!



2014-08-19 13:28 GMT+08:00 Andreas Steffen <andreas.steffen@strongswan.org>:

> Hello Amysu,
>
> go into the strongswan source directory and execute
>
>   make clean
>  ./configure --sysconfdir=/etc  <any other options>
>  make
>  make install
>
> and the path pointing to the configuration files is changed from
>  /usr/local/etc to /etc. If you want you to clean up you can remove
> the old configuration files:
>
> cd /usr/local/etc
> rm -r ipsec.d swanctl ipsec.secrets ipsec.conf strongswan.conf
>
> Best regards
>
> Andreas
>
> On 08/19/2014 07:02 AM, amysue.z@gmail.com wrote:
> > Hello Andreas,
> >
> > I have installed strongswan, how can change the sysconfdir, should I
> > uninstall it first? I don't know how to uninstall strongswan?
> >
> > Thanks for your help
> >
> >
> > 2014-08-19 12:36 GMT+08:00 Andreas Steffen
> > <andreas.steffen@strongswan.org <mailto:andreas.steffen@strongswan.org
> >>:
> >
> >     Hello Amysue,
> >
> >     you have to build strongSwan with
> >
> >       ./configure --sysconfdir=/etc
> >
> >     Regards
> >
> >     Andreas
> >
> >     On 08/19/2014 05:18 AM, amysue.z@gmail.com
> >     <mailto:amysue.z@gmail.com> wrote:
> >     > Hi Noel,
> >     >
> >     > I have checked the strongswan logs at /var/log/messages, and I
> found
> >     > that it load the conf directory  /usr/loca/etc, while I put all my
> >     conf
> >     > files at /etc, which I think cause my problem.
> >     > Is there any way that I can change the conf directory to /etc.
> >     >
> >     > Thanks,
> >     >
> >     >
> >     > 2014-08-18 21:16 GMT+08:00 Noel Kuntze <noel@familie-kuntze.de
> >     <mailto:noel@familie-kuntze.de>
> >     > <mailto:noel@familie-kuntze.de <mailto:noel@familie-kuntze.de>>>:
> >     >
> >     > Hello Amysue
> >     >
> >     > Please refer to [2] for a how-to for installing strongSwan.
> >     > Please note that some modules that could be necessary for your
> setup
> >     > need to be compiled by giving the corresponding parameters to
> >     > ./configure.
> >     >
> >     > Regards,
> >     > Noel Kuntze
> >     >
> >     > GPG Key id: 0x63EC6658
> >     > Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658
> >     >
> >     > Am 18.08.2014 um 15:12 schrieb amysue.z@gmail.com
> >     <mailto:amysue.z@gmail.com>
> >     > <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>>:
> >     >> I also want to know are there any special configurations to
> >     > install strongswan for ikev2 mobike?
> >     >
> >     >> For install strongswan to my pc, I just
> >     >> /./configure/
> >     >> /make/
> >     >> /make install/
> >     >> /
> >     >> /
> >     >> Thanks,
> >     >
> >     >
> >     >> 2014-08-18 21:08 GMT+08:00 <amysue.z@gmail.com
> >     <mailto:amysue.z@gmail.com>
> >     > <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>>
> >     <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>
> >     > <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>>>>:
> >     >
> >     >>     Hi Noel,
> >     >>     The output of "ipsec statusall" is
> >     >>     /Status of IKE charon daemon (strongSwan 5.0.2, Linux
> >     > 2.6.18-348.1.1.el5, i686):/
> >     >>     /  uptime: 14 minutes, since Aug 18 18:21:46 2014/
> >     >>     /  malloc: sbrk 135168, mmap 0, used 86616, free 48552/
> >     >>     /  worker threads: 8 of 16 idle, 7/1/0/0 working, job queue:
> >     > 0/0/0/0, scheduled: 0/
> >     >>     /  loaded plugins: charon aes des sha1 sha2 md5 random nonce
> >     > x509 revocation constraints pubkey pkcs1 pkcs8 pgp dnskey pem
> >     > fips-prf gmp xcbc cmac hmac attr kernel-netlink resolve
> >     > socket-default stroke updown eap-md5 eap-radius xauth-generic/
> >     >>     /Listening IP addresses:/
> >     >>     /  192.168.2.6/ <http://192.168.2.6/> <http://192.168.2.6/>
> >     >>     /  12.12.1.203/ <http://12.12.1.203/> <http://12.12.1.203/>
> >     >>     /Connections:/
> >     >>     /Security Associations (0 up, 0 connecting):/
> >     >>     /  none/
> >     >
> >     >>     AndŁ¬ how do I  enable logging[1] ? I don't use strongswan
> >     > much, So it feel difficult for me.
> >     >>     Thank you again for your help
> >     >
> >     >
> >     >
> >     >>     2014-08-18 21:02 GMT+08:00 Noel Kuntze
> >     <noel@familie-kuntze.de <mailto:noel@familie-kuntze.de>
> >     > <mailto:noel@familie-kuntze.de <mailto:noel@familie-kuntze.de>>
> >     <mailto:noel@familie-kuntze.de <mailto:noel@familie-kuntze.de>
> >     > <mailto:noel@familie-kuntze.de <mailto:noel@familie-kuntze.de>>>>:
> >     >
> >     >> Hello,
> >     >
> >     >> Check your system log for errors and show us the output of "ipsec
> >     > statusall".
> >     >> Sometimes, it takes a couple of seconds for the daemon to load the
> >     > configuration. Waiting a bit can help in this case.
> >     >> The reason for this is, that all the ipsec commands are
> asynchronous.
> >     >> If the configuration isn't loaded for a couple of seconds, please
> >     > enable logging[1].
> >     >> StrongSwan can handle Mobike. It's a daemon thing, not a kernel
> >     thing.
> >     >
> >     >> [1]
> >     >
> >
> https://wiki.strongswan.org/projects/strongswan/wiki/LoggerConfiguration
> >     >
> >     >> Regards,
> >     >> Noel Kuntze
> >     >
> >     >> GPG Key id: 0x63EC6658
> >     >> Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658
> >     >
> >     >> Am 18.08.2014 um 14:56 schrieb amysue.z@gmail.com
> >     <mailto:amysue.z@gmail.com>
> >     > <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>>
> >     <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>
> >     > <mailto:amysue.z@gmail.com <mailto:amysue.z@gmail.com>>>:
> >     >>> Hello,
> >     >
> >     >>> My OS is centos 5.9 and i have installed Linux strongSwan
> >     > U5.0.2/K2.6.18-348.1.1.el5.
> >     >>> After installation,i start strongswan:
> >     >>> ipsec start
> >     >>> then i up an connection:
> >     >>> ipsec up client
> >     >>> then I get an error:*no config named 'client'*
> >     >>> Actually, I define an connection in /etc/ipsec.conf.
> >     >
> >     >>> Below is my /etc/ipsec.conf
> >     >
> >     >>> /config setup/
> >     >>> /    strictcrlpolicy=no/
> >     >>> /    charonstart=yes/
> >     >>> /
> >     >>> /
> >     >>> /conn %default/
> >     >>> /    ikelifetime=28800s/
> >     >>> /    keylife=28800s/
> >     >>> /    rekeymargin=3m/
> >     >>> /    keyingtries=3/
> >     >>> /    keyexchange=ikev2/
> >     >>> /    ike=3des-sha1-modp1024/
> >     >>> /    esp=3des-sha1/
> >     >>> /
> >     >>> /
> >     >>> /conn client/
> >     >>> /    left=12.12.1.203/ <http://12.12.1.203/>
> >     <http://12.12.1.203/> <http://12.12.1.203/>
> >     >>> /    leftsourceip=%config/
> >     >>> /    leftcert=client1_cert.pem/
> >     >>> /    leftid="/C=CN/ST=SH/O=CS/CN=IKEv2_Client1"/
> >     >>> /    right=11.11.11.200/ <http://11.11.11.200/>
> >     <http://11.11.11.200/>
> >     > <http://11.11.11.200/>
> >     >>> /    rightid="/C=CN/ST=SH/O=CS/CN=11.11.11.200"/
> >     >>> /    rightsubnet=192.168.168.0/24 <http://192.168.168.0/24>
> >     <http://192.168.168.0/24>
> >     > <http://192.168.168.0/24> <http://192.168.168.0/24>/
> >     >>> /    auto=add/
> >     >>> /
> >     >>> /
> >     >>> I have no idea what to do now, I really need your help, any one
> >     > could help me?
> >     >>>  Thank you very much
> >     >
> >
> >
>  ======================================================================
> >     Andreas Steffen
> >      andreas.steffen@strongswan.org <mailto:
> andreas.steffen@strongswan.org>
> >     strongSwan - the Open Source VPN Solution!
> >     www.strongswan.org <http://www.strongswan.org>
> >     Institute for Internet Technologies and Applications
> >     University of Applied Sciences Rapperswil
> >     CH-8640 Rapperswil (Switzerland)
> >
>  ===========================================================[ITA-HSR]==
> >
> >
>
> --
> ======================================================================
> Andreas Steffen                         andreas.steffen@strongswan.org
> strongSwan - the Open Source VPN Solution!          www.strongswan.org
> Institute for Internet Technologies and Applications
> University of Applied Sciences Rapperswil
> CH-8640 Rapperswil (Switzerland)
> ===========================================================[ITA-HSR]==
>
>

[Attachment #5 (text/html)]

<div dir="ltr">Hi Noel, Andreas<div><br></div><div>Now my strongswan is working well \
now.</div><div>Thank you verry much!&nbsp;<br></div><div><br></div></div><div \
class="gmail_extra"><br><br><div class="gmail_quote">2014-08-19 13:28 GMT+08:00 \
Andreas Steffen <span dir="ltr">&lt;<a href="mailto:andreas.steffen@strongswan.org" \
target="_blank">andreas.steffen@strongswan.org</a>&gt;</span>:<br> <blockquote \
class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc \
solid;padding-left:1ex">Hello Amysu,<br> <br>
go into the strongswan source directory and execute<br>
<br>
&nbsp; make clean<br>
&nbsp;./configure --sysconfdir=/etc&nbsp; &lt;any other options&gt;<br>
&nbsp;make<br>
&nbsp;make install<br>
<br>
and the path pointing to the configuration files is changed from<br>
&nbsp;/usr/local/etc to /etc. If you want you to clean up you can remove<br>
the old configuration files:<br>
<br>
cd /usr/local/etc<br>
rm -r ipsec.d swanctl ipsec.secrets ipsec.conf strongswan.conf<br>
<br>
Best regards<br>
<br>
Andreas<br>
<div class=""><br>
On 08/19/2014 07:02 AM, <a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> \
wrote:<br> &gt; Hello Andreas,<br>
&gt;<br>
&gt; I have installed strongswan, how can change the sysconfdir, should I<br>
&gt; uninstall it first? I don&#39;t know how to uninstall strongswan?<br>
&gt;<br>
&gt; Thanks for your help<br>
&gt;<br>
&gt;<br>
&gt; 2014-08-19 12:36 GMT+08:00 Andreas Steffen<br>
</div>&gt; &lt;<a href="mailto:andreas.steffen@strongswan.org">andreas.steffen@strongswan.org</a> \
&lt;mailto:<a href="mailto:andreas.steffen@strongswan.org">andreas.steffen@strongswan.org</a>&gt;&gt;:<br>
 <div class="">&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;Hello Amysue,<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;you have to build strongSwan with<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp; &nbsp;./configure --sysconfdir=/etc<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;Regards<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;Andreas<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;On 08/19/2014 05:18 AM, <a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a><br> </div><div \
class="">&gt;&nbsp; &nbsp; &nbsp;&lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt; wrote:<br> &gt;&nbsp; \
&nbsp; &nbsp;&gt; Hi Noel,<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; I have checked the strongswan logs at /var/log/messages, \
and I found<br> &gt;&nbsp; &nbsp; &nbsp;&gt; that it load the conf directory&nbsp; \
/usr/loca/etc, while I put all my<br> &gt;&nbsp; &nbsp; &nbsp;conf<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; files at /etc, which I think cause my problem.<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Is there any way that I can change the conf directory to \
/etc.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Thanks,<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; 2014-08-18 21:16 GMT+08:00 Noel Kuntze &lt;<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a><br> &gt;&nbsp; &nbsp; \
&nbsp;&lt;mailto:<a href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;<br>
 </div>&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a> &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;&gt;&gt;:<br> <div \
class="">&gt;&nbsp; &nbsp; &nbsp;&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt; Hello \
Amysue<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Please refer to [2] for a how-to for installing \
strongSwan.<br> &gt;&nbsp; &nbsp; &nbsp;&gt; Please note that some modules that could \
be necessary for your setup<br> &gt;&nbsp; &nbsp; &nbsp;&gt; need to be compiled by \
giving the corresponding parameters to<br> &gt;&nbsp; &nbsp; &nbsp;&gt; \
./configure.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Regards,<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Noel Kuntze<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; GPG Key id: 0x63EC6658<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F \
63EC 6658<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt; Am 18.08.2014 um 15:12 schrieb <a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a><br> &gt;&nbsp; &nbsp; \
&nbsp;&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;<br> \
</div>&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;&gt;:<br> <div \
class="">&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; I also want to know are there any special \
configurations to<br> &gt;&nbsp; &nbsp; &nbsp;&gt; install strongswan for ikev2 \
mobike?<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; For install strongswan to my pc, I just<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; /./configure/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; /make/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; /make install/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Thanks,<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; 2014-08-18 21:08 GMT+08:00 &lt;<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a><br> &gt;&nbsp; &nbsp; \
&nbsp;&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;&gt;<br> &gt;&nbsp; &nbsp; \
&nbsp;&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> \
&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;<br> \
</div>&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;&gt;&gt;&gt;:<br> <div \
class="">&gt;&nbsp; &nbsp; &nbsp;&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; \
&nbsp; &nbsp;Hi Noel,<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;The \
output of &quot;ipsec statusall&quot; is<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; \
&nbsp; &nbsp;/Status of IKE charon daemon (strongSwan 5.0.2, Linux<br> &gt;&nbsp; \
&nbsp; &nbsp;&gt; 2.6.18-348.1.1.el5, i686):/<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; uptime: 14 minutes, since Aug 18 18:21:46 \
2014/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; malloc: sbrk \
135168, mmap 0, used 86616, free 48552/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; \
&nbsp; &nbsp;/&nbsp; worker threads: 8 of 16 idle, 7/1/0/0 working, job queue:<br> \
&gt;&nbsp; &nbsp; &nbsp;&gt; 0/0/0/0, scheduled: 0/<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; loaded plugins: charon aes des sha1 sha2 \
md5 random nonce<br> &gt;&nbsp; &nbsp; &nbsp;&gt; x509 revocation constraints pubkey \
pkcs1 pkcs8 pgp dnskey pem<br> &gt;&nbsp; &nbsp; &nbsp;&gt; fips-prf gmp xcbc cmac \
hmac attr kernel-netlink resolve<br> &gt;&nbsp; &nbsp; &nbsp;&gt; socket-default \
stroke updown eap-md5 eap-radius xauth-generic/<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/Listening IP addresses:/<br> </div>&gt;&nbsp; \
&nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; <a href="http://192.168.2.6/" \
target="_blank">192.168.2.6/</a> &lt;<a href="http://192.168.2.6/" \
target="_blank">http://192.168.2.6/</a>&gt; &lt;<a href="http://192.168.2.6/" \
target="_blank">http://192.168.2.6/</a>&gt;<br>

&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; <a \
href="http://12.12.1.203/" target="_blank">12.12.1.203/</a> &lt;<a \
href="http://12.12.1.203/" target="_blank">http://12.12.1.203/</a>&gt; &lt;<a \
href="http://12.12.1.203/" target="_blank">http://12.12.1.203/</a>&gt;<br>

<div class="">&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/Connections:/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/Security Associations (0 up, 0 \
connecting):/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;/&nbsp; \
none/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;AndŁ¬ how do I&nbsp; enable \
logging[1] ? I don&#39;t use strongswan<br> &gt;&nbsp; &nbsp; &nbsp;&gt; much, So it \
feel difficult for me.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;Thank \
you again for your help<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&nbsp; &nbsp; &nbsp;2014-08-18 21:02 GMT+08:00 Noel \
Kuntze<br> &gt;&nbsp; &nbsp; &nbsp;&lt;<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a> &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;<br> &gt;&nbsp; \
&nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a> &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a> &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;<br> \
</div>&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a> &lt;mailto:<a \
href="mailto:noel@familie-kuntze.de">noel@familie-kuntze.de</a>&gt;&gt;&gt;&gt;:<br> \
<div class="">&gt;&nbsp; &nbsp; &nbsp;&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt; \
Hello,<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Check your system log for errors and show us the \
output of &quot;ipsec<br> &gt;&nbsp; &nbsp; &nbsp;&gt; statusall&quot;.<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Sometimes, it takes a couple of seconds for the \
daemon to load the<br> &gt;&nbsp; &nbsp; &nbsp;&gt; configuration. Waiting a bit can \
help in this case.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt; The reason for this is, that \
all the ipsec commands are asynchronous.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt; If the \
configuration isn&#39;t loaded for a couple of seconds, please<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt; enable logging[1].<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt; StrongSwan can \
handle Mobike. It&#39;s a daemon thing, not a kernel<br> &gt;&nbsp; &nbsp; \
&nbsp;thing.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; [1]<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;<a \
href="https://wiki.strongswan.org/projects/strongswan/wiki/LoggerConfiguration" \
target="_blank">https://wiki.strongswan.org/projects/strongswan/wiki/LoggerConfiguration</a><br>
 &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Regards,<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Noel Kuntze<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; GPG Key id: 0x63EC6658<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F \
63EC 6658<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt; Am 18.08.2014 um 14:56 schrieb <a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a><br> &gt;&nbsp; &nbsp; \
&nbsp;&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;&gt;<br> </div>&gt;&nbsp; \
&nbsp; &nbsp;&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> \
&lt;mailto:<a href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a> &lt;mailto:<a \
href="mailto:amysue.z@gmail.com">amysue.z@gmail.com</a>&gt;&gt;&gt;:<br> <div><div \
class="h5">&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; Hello,<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; My OS is centos 5.9 and i have \
installed Linux strongSwan<br> &gt;&nbsp; &nbsp; &nbsp;&gt; \
U5.0.2/K2.6.18-348.1.1.el5.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; After \
installation,i start strongswan:<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; ipsec \
start<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; then i up an connection:<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; ipsec up client<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; then I get an error:*no config named \
&#39;client&#39;*<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; Actually, I define an \
connection in /etc/ipsec.conf.<br> &gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; Below is my /etc/ipsec.conf<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /config setup/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; strictcrlpolicy=no/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; charonstart=yes/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /conn %default/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; ikelifetime=28800s/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; keylife=28800s/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; rekeymargin=3m/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; keyingtries=3/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; keyexchange=ikev2/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; ike=3des-sha1-modp1024/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; esp=3des-sha1/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /conn client/<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; left=<a \
href="http://12.12.1.203/" target="_blank">12.12.1.203/</a> &lt;<a \
href="http://12.12.1.203/" target="_blank">http://12.12.1.203/</a>&gt;<br> &gt;&nbsp; \
&nbsp; &nbsp;&lt;<a href="http://12.12.1.203/" \
target="_blank">http://12.12.1.203/</a>&gt; &lt;<a href="http://12.12.1.203/" \
target="_blank">http://12.12.1.203/</a>&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; \
/&nbsp; &nbsp; leftsourceip=%config/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; \
&nbsp; leftcert=client1_cert.pem/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; \
&nbsp; leftid=&quot;/C=CN/ST=SH/O=CS/CN=IKEv2_Client1&quot;/<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; right=<a href="http://11.11.11.200/" \
target="_blank">11.11.11.200/</a> &lt;<a href="http://11.11.11.200/" \
target="_blank">http://11.11.11.200/</a>&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&lt;<a \
href="http://11.11.11.200/" target="_blank">http://11.11.11.200/</a>&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&gt; &lt;<a href="http://11.11.11.200/" \
target="_blank">http://11.11.11.200/</a>&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; \
/&nbsp; &nbsp; rightid=&quot;/C=CN/ST=SH/O=CS/CN=11.11.11.200&quot;/<br> &gt;&nbsp; \
&nbsp; &nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; rightsubnet=<a \
href="http://192.168.168.0/24" target="_blank">192.168.168.0/24</a> &lt;<a \
href="http://192.168.168.0/24" target="_blank">http://192.168.168.0/24</a>&gt;<br> \
&gt;&nbsp; &nbsp; &nbsp;&lt;<a href="http://192.168.168.0/24" \
target="_blank">http://192.168.168.0/24</a>&gt;<br> &gt;&nbsp; &nbsp; &nbsp;&gt; \
&lt;<a href="http://192.168.168.0/24" target="_blank">http://192.168.168.0/24</a>&gt; \
&lt;<a href="http://192.168.168.0/24" \
target="_blank">http://192.168.168.0/24</a>&gt;/<br> &gt;&nbsp; &nbsp; \
&nbsp;&gt;&gt;&gt; /&nbsp; &nbsp; auto=add/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; \
/<br> &gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; /<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt; I have no idea what to do now, I really need \
your help, any one<br> &gt;&nbsp; &nbsp; &nbsp;&gt; could help me?<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;&gt;&gt;&nbsp; Thank you very much<br>
&gt;&nbsp; &nbsp; &nbsp;&gt;<br>
&gt;<br>
&gt;&nbsp; &nbsp; &nbsp;======================================================================<br>
 &gt;&nbsp; &nbsp; &nbsp;Andreas Steffen<br>
</div></div>&gt;&nbsp; &nbsp; &nbsp; <a \
href="mailto:andreas.steffen@strongswan.org">andreas.steffen@strongswan.org</a> \
&lt;mailto:<a href="mailto:andreas.steffen@strongswan.org">andreas.steffen@strongswan.org</a>&gt;<br>
 <div class="">&gt;&nbsp; &nbsp; &nbsp;strongSwan - the Open Source VPN Solution!<br>
</div>&gt;&nbsp; &nbsp; &nbsp;<a href="http://www.strongswan.org" \
target="_blank">www.strongswan.org</a> &lt;<a href="http://www.strongswan.org" \
target="_blank">http://www.strongswan.org</a>&gt;<br> <div class="">&gt;&nbsp; &nbsp; \
&nbsp;Institute for Internet Technologies and Applications<br> &gt;&nbsp; &nbsp; \
&nbsp;University of Applied Sciences Rapperswil<br> &gt;&nbsp; &nbsp; &nbsp;CH-8640 \
Rapperswil (Switzerland)<br> &gt;&nbsp; &nbsp; \
&nbsp;===========================================================[ITA-HSR]==<br> \
&gt;<br> &gt;<br>
<br>
</div>--<br>
<div class="HOEnZb"><div \
class="h5">======================================================================<br> \
Andreas Steffen&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \
&nbsp; &nbsp; &nbsp;<a \
href="mailto:andreas.steffen@strongswan.org">andreas.steffen@strongswan.org</a><br> \
strongSwan - the Open Source VPN Solution!&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; <a \
href="http://www.strongswan.org" target="_blank">www.strongswan.org</a><br> Institute \
for Internet Technologies and Applications<br> University of Applied Sciences \
Rapperswil<br> CH-8640 Rapperswil (Switzerland)<br>
===========================================================[ITA-HSR]==<br>
<br>
</div></div></blockquote></div><br></div>



_______________________________________________
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic