[Openswan Users] Mac OS X - Openswan - L2TP - NAT-T problems

Paul Wouters paul at xelerance.com
Wed Nov 14 10:35:06 EST 2007


On Wed, 14 Nov 2007, Danilo Godec wrote:

> > conn rwmac-net
> >         #
> >         # Use a certificate. Disable Perfect Forward Secrecy.
> >         #
> >         authby=rsasig
> >         pfs=no
> >         auto=add
> >         rekey=no
> >         left=%defaultroute

You must specify your ip here. You cannot be 'dynamic' on both ends
of the connection.

> >         leftrsasigkey=%cert
> >         leftcert=fw.SERVER.DOMAIN-cert.pem
> >         leftupdown=/lib/ipsec/_updown_x509
> >         leftprotoport=udp/1701
> >         right=%any
> >         #rightca=%same
> >         rightrsasigkey=%cert
> >         rightprotoport=udp/%any

Use rightprotopoty=17/0

Paul


More information about the Users mailing list