[Openswan Users] How to offer multiple PFS ?

gal divx gal.divx at gmail.com
Thu Jul 5 11:27:38 EDT 2007


For phase 1 successfully define multiple DH to be used by specifying

ike="3des-sha1-modp1024,3des-sha1-modp2048"



However – for phase 2 , trying:



pfsgroup="modp1024,modp2048"

-failed when trying to add the connection with the error:

034 esp string error: Unknown

(Comment – I have tried with "" and without it, and the same error for both)

I also tried

esp="3des-sha1-modp1024,3des-sha1-modp2048"

-failed when trying to add the connection with the error:

034 esp string error: Non initial digit found for auth keylen, just after
"3des-sha1-" (old_state=ST_AA_END)



Does anyone has any idea how can I offer multiple PFS ?
Thanks from advance, Gal.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20070705/95f233e7/attachment.html 


More information about the Users mailing list