IPSec (OpenSWAN)

Trever L. Adams trever.adams at gmail.com
Fri Dec 3 20:39:18 UTC 2010


Hello Everyone,

I have been struggling to get OpenSWAN to work. I am trying to get a
setup going with the following:

Router <--> Router, IPSec only, Pre-shared keys or certs (ESP, tunnel or
not)
Router <--> Android Phones, IPSec/L2TP, Pre-shared keys (the certs is a
lot of messing around that I am not comfortable doing yet with other
people's phones

I haven't yet tried Router to Router as I have seen it said that it is
best to get the PSK w/ L2TP working first. The error I get (sorry, don't
have the phone to test with and I can't find it in the logs at the
moment) says something about not finding a valid pair and ignoring the
connection on port 500.

The Router is common in both setups.

Has anyone successfully done this? Does anyone know a good trick to get
your own CA onto Android Phones without a lot of risk?

Thank you for any help, configuration is available if needed.

Trever
-- 
"It does not take a majority to prevail. What it takes is an irate,
tireless minority, keen on setting brushfires of freedom in the minds of
men." -- Samuel Adams


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 261 bytes
Desc: OpenPGP digital signature
Url : http://lists.fedoraproject.org/pipermail/users/attachments/20101203/285506d9/attachment-0001.bin 


More information about the users mailing list