public inbox for documentation@lists.ipfire.org
 help / color / mirror / Atom feed
* Change in IPSec roadwarrior configuration for MacOSX 10.12
@ 2019-04-04 16:21 Carlo Fusco
  2019-04-04 16:24 ` Carlo Fusco
  2019-04-04 18:13 ` Tom Rymes
  0 siblings, 2 replies; 3+ messages in thread
From: Carlo Fusco @ 2019-04-04 16:21 UTC (permalink / raw)
  To: documentation

[-- Attachment #1: Type: text/plain, Size: 864 bytes --]

Hello,

I have MAC OS X Sierra as an IPSec client and when I configured IPSec
server on IPFire I found that it was being disconnected every 480 sec
due to a failed rekey attempt from Mac OS, which happened with the
configuration proposed in the text of the wiki.

According to the apple developers, a change in the ESP grouptype was
required ( http://www.openradar.appspot.com/29821241 ). When I tested
the IPSec suggested configuration everything worked well. Therefore I
changed the text of the wiki to reflect the issue. I also fixed a non
matching parenthesis.

Here is the diff:

https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions

Feel free to revert the change if you believe it is necessary or to
suggest a different wording/place.

Thank you for your time
--
Carlo Fusco

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Change in IPSec roadwarrior configuration for MacOSX 10.12
  2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
@ 2019-04-04 16:24 ` Carlo Fusco
  2019-04-04 18:13 ` Tom Rymes
  1 sibling, 0 replies; 3+ messages in thread
From: Carlo Fusco @ 2019-04-04 16:24 UTC (permalink / raw)
  To: documentation

[-- Attachment #1: Type: text/plain, Size: 1206 bytes --]

Sorry, wrong link:

https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=diff&rev2%5B0%5D=1544404073&rev2%5B1%5D=1554394022&difftype=sidebyside

On Thu, Apr 4, 2019 at 6:21 PM Carlo Fusco <fusco.carlo(a)gmail.com> wrote:
>
> Hello,
>
> I have MAC OS X Sierra as an IPSec client and when I configured IPSec
> server on IPFire I found that it was being disconnected every 480 sec
> due to a failed rekey attempt from Mac OS, which happened with the
> configuration proposed in the text of the wiki.
>
> According to the apple developers, a change in the ESP grouptype was
> required ( http://www.openradar.appspot.com/29821241 ). When I tested
> the IPSec suggested configuration everything worked well. Therefore I
> changed the text of the wiki to reflect the issue. I also fixed a non
> matching parenthesis.
>
> Here is the diff:
>
> https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
>
> Feel free to revert the change if you believe it is necessary or to
> suggest a different wording/place.
>
> Thank you for your time
> --
> Carlo Fusco



-- 
Carlo Fusco

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: Change in IPSec roadwarrior configuration for MacOSX 10.12
  2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
  2019-04-04 16:24 ` Carlo Fusco
@ 2019-04-04 18:13 ` Tom Rymes
  1 sibling, 0 replies; 3+ messages in thread
From: Tom Rymes @ 2019-04-04 18:13 UTC (permalink / raw)
  To: documentation

[-- Attachment #1: Type: text/plain, Size: 1478 bytes --]

Carlo,

Just to confirm, have you put this text into the ipsec.user.conf file 
and restarted IPSec?

conn CONNECTION_NAME
       leftsendcert=always
       leftallowany=yes
       rightdns=10.100.2.1
       rekey=no
       reauth=no

Specifically, the rekey and reauth portions.

I assume yes, but want to double-check.

Tom

On 04/04/2019 12:21 PM, Carlo Fusco wrote:
> Hello,
> 
> I have MAC OS X Sierra as an IPSec client and when I configured IPSec
> server on IPFire I found that it was being disconnected every 480 sec
> due to a failed rekey attempt from Mac OS, which happened with the
> configuration proposed in the text of the wiki.
> 
> According to the apple developers, a change in the ESP grouptype was
> required ( http://www.openradar.appspot.com/29821241 ). When I tested
> the IPSec suggested configuration everything worked well. Therefore I
> changed the text of the wiki to reflect the issue. I also fixed a non
> matching parenthesis.
> 
> Here is the diff:
> 
> https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
> 
> Feel free to revert the change if you believe it is necessary or to
> suggest a different wording/place.
> 
> Thank you for your time
> --
> Carlo Fusco
> _______________________________________________
> Documentation mailing list
> Documentation(a)lists.ipfire.org
> https://lists.ipfire.org/mailman/listinfo/documentation
> 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-04-04 18:13 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
2019-04-04 16:24 ` Carlo Fusco
2019-04-04 18:13 ` Tom Rymes

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox