Project

General

Profile

Issue #3089

Shrew Soft iked config

Added by Michael Ahrens 7 days ago. Updated 6 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
configuration
Affected version:
5.8.0
Resolution:
Invalid

Description

I would like to move from my very old Shrew Soft iked to Strongswan. Can somebody give me some help to convert the config ?

Here is my Shrew Soft iced Config:

n:version:4
n:network-ike-port:500
n:network-mtu-size:1380
n:client-addr-auto:1
n:network-natt-port:4500
n:network-natt-rate:15
n:network-frag-size:540
n:network-dpd-enable:1
n:client-banner-enable:1
n:network-notify-enable:1
n:client-wins-used:0
n:client-wins-auto:1
n:client-dns-used:1
n:client-dns-auto:0
n:client-splitdns-used:0
n:client-splitdns-auto:0
n:phase1-dhgroup:2
n:phase1-life-secs:28800
n:phase1-life-kbytes:0
n:vendor-chkpt-enable:0
n:phase2-life-secs:28800
n:phase2-life-kbytes:0
n:policy-nailed:1
n:policy-list-auto:0
b:auth-mutual-psk:PSK
n:phase2-pfsgroup:2
s:client-saved-username:MYUSER
n:client-dns-suffix-auto:0
n:phase1-keylen:0
n:phase2-keylen:0
s:network-host:VPN-SERVER
s:client-auto-mode:pull
s:client-iface:virtual
s:network-natt-mode:enable
s:network-frag-mode:enable
s:client-dns-addr:DNS-SERVER1,DNS-SERVER2
s:client-dns-suffix:DOMAIN.local
s:auth-method:mutual-psk-xauth
s:ident-client-type:ufqdn
s:ident-client-data:MYUSER@DOMAIN
s:ident-server-type:address
s:ident-server-data:VPN-SERVER
s:phase1-exchange:aggressive
s:phase1-cipher:3des
s:phase1-hash:sha1
s:phase2-transform:esp-3des
s:phase2-hmac:sha1
s:ipcomp-transform:disabled
s:policy-level:require
s:policy-list-include:192.168.0.0 / 255.255.0.0

History

#1 Updated by Tobias Brunner 6 days ago

  • Tracker changed from Feature to Issue
  • Status changed from New to Rejected
  • Start date deleted (11.06.2019)
  • Resolution set to Invalid
  • Affected version set to 5.8.0

Please ask on the users mailing list or in the IRC channel (even better, try it yourself).

Also available in: Atom PDF