<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
</head>
<body text="#000000" bgcolor="#ffffff">
Hello,<br>
<br>
i have a question about the openswan config.<br>
I am trying to build a tunnel between two gateways.<br>
gateway1's ike set to <big>AES256-SHA1-MODP768</big><br>
gateway2's ike set to <big>AES128-SHA1-MODP1536</big><br>
and finally the tunnel use ==> <big><big>IKE algorithm newest:
AES_CBC_256-SHA1-MODP768</big></big><br>
Is the behavior correct?<br>
If i want the connection connected when two gateway's ike configuration
is the same.<br>
Can Openswan achieve?<br>
<br>
=========================================<br>
conn site_192.168.1.0_24-192.168.123.0_24<br>
left=10.2.3.156<br>
leftsubnet=192.168.1.0/24<br>
right=10.29.3.225<br>
rightsubnet=192.168.123.0/24<br>
ike=AES256-SHA1-MODP768<br>
esp=AES256-SHA1-96<br>
dpddelay=10<br>
dpdtimeout=15<br>
keyingtries=%forever<br>
keylife=24h<br>
ikelifetime=8h<br>
rekey=no<br>
rekeymargin=9m<br>
pfs=yes<br>
pfsgroup=MODP1024<br>
auto=add<br>
<br>
=========================================<br>
<br>
conn site_192.168.123.0_24-192.168.1.0_24<br>
left=10.29.3.225<br>
leftsubnet=192.168.123.0/24<br>
right=10.2.3.156<br>
rightsubnet=192.168.1.0/24<br>
ike=AES128-SHA1-MODP1536<br>
esp=AES256-SHA1-96<br>
dpddelay=10<br>
dpdtimeout=15<br>
keyingtries=%forever<br>
keylife=24h<br>
ikelifetime=8h<br>
rekey=no<br>
rekeymargin=9m<br>
pfs=yes<br>
auto=add<br>
<br>
</body>
</html>