public inbox for documentation@lists.ipfire.org
 help / color / mirror / Atom feed
From: Tom Rymes <trymes@rymes.com>
To: documentation@lists.ipfire.org
Subject: Re: Change in IPSec roadwarrior configuration for MacOSX 10.12
Date: Thu, 04 Apr 2019 14:13:45 -0400	[thread overview]
Message-ID: <796a1325-913e-a293-a3b1-7fd6b6be33a7@rymes.com> (raw)
In-Reply-To: <CAK9whhxM_kB+mxoRyY-o00Si=aUV=kqUWCfeDoFcRqjH3QwV3A@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 1478 bytes --]

Carlo,

Just to confirm, have you put this text into the ipsec.user.conf file 
and restarted IPSec?

conn CONNECTION_NAME
       leftsendcert=always
       leftallowany=yes
       rightdns=10.100.2.1
       rekey=no
       reauth=no

Specifically, the rekey and reauth portions.

I assume yes, but want to double-check.

Tom

On 04/04/2019 12:21 PM, Carlo Fusco wrote:
> Hello,
> 
> I have MAC OS X Sierra as an IPSec client and when I configured IPSec
> server on IPFire I found that it was being disconnected every 480 sec
> due to a failed rekey attempt from Mac OS, which happened with the
> configuration proposed in the text of the wiki.
> 
> According to the apple developers, a change in the ESP grouptype was
> required ( http://www.openradar.appspot.com/29821241 ). When I tested
> the IPSec suggested configuration everything worked well. Therefore I
> changed the text of the wiki to reflect the issue. I also fixed a non
> matching parenthesis.
> 
> Here is the diff:
> 
> https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
> 
> Feel free to revert the change if you believe it is necessary or to
> suggest a different wording/place.
> 
> Thank you for your time
> --
> Carlo Fusco
> _______________________________________________
> Documentation mailing list
> Documentation(a)lists.ipfire.org
> https://lists.ipfire.org/mailman/listinfo/documentation
> 

      parent reply	other threads:[~2019-04-04 18:13 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-04-04 16:21 Carlo Fusco
2019-04-04 16:24 ` Carlo Fusco
2019-04-04 18:13 ` Tom Rymes [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=796a1325-913e-a293-a3b1-7fd6b6be33a7@rymes.com \
    --to=trymes@rymes.com \
    --cc=documentation@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox