* Change in IPSec roadwarrior configuration for MacOSX 10.12
@ 2019-04-04 16:21 Carlo Fusco
2019-04-04 16:24 ` Carlo Fusco
2019-04-04 18:13 ` Tom Rymes
0 siblings, 2 replies; 3+ messages in thread
From: Carlo Fusco @ 2019-04-04 16:21 UTC (permalink / raw)
To: documentation
[-- Attachment #1: Type: text/plain, Size: 864 bytes --]
Hello,
I have MAC OS X Sierra as an IPSec client and when I configured IPSec
server on IPFire I found that it was being disconnected every 480 sec
due to a failed rekey attempt from Mac OS, which happened with the
configuration proposed in the text of the wiki.
According to the apple developers, a change in the ESP grouptype was
required ( http://www.openradar.appspot.com/29821241 ). When I tested
the IPSec suggested configuration everything worked well. Therefore I
changed the text of the wiki to reflect the issue. I also fixed a non
matching parenthesis.
Here is the diff:
https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
Feel free to revert the change if you believe it is necessary or to
suggest a different wording/place.
Thank you for your time
--
Carlo Fusco
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Change in IPSec roadwarrior configuration for MacOSX 10.12
2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
@ 2019-04-04 16:24 ` Carlo Fusco
2019-04-04 18:13 ` Tom Rymes
1 sibling, 0 replies; 3+ messages in thread
From: Carlo Fusco @ 2019-04-04 16:24 UTC (permalink / raw)
To: documentation
[-- Attachment #1: Type: text/plain, Size: 1206 bytes --]
Sorry, wrong link:
https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=diff&rev2%5B0%5D=1544404073&rev2%5B1%5D=1554394022&difftype=sidebyside
On Thu, Apr 4, 2019 at 6:21 PM Carlo Fusco <fusco.carlo(a)gmail.com> wrote:
>
> Hello,
>
> I have MAC OS X Sierra as an IPSec client and when I configured IPSec
> server on IPFire I found that it was being disconnected every 480 sec
> due to a failed rekey attempt from Mac OS, which happened with the
> configuration proposed in the text of the wiki.
>
> According to the apple developers, a change in the ESP grouptype was
> required ( http://www.openradar.appspot.com/29821241 ). When I tested
> the IPSec suggested configuration everything worked well. Therefore I
> changed the text of the wiki to reflect the issue. I also fixed a non
> matching parenthesis.
>
> Here is the diff:
>
> https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
>
> Feel free to revert the change if you believe it is necessary or to
> suggest a different wording/place.
>
> Thank you for your time
> --
> Carlo Fusco
--
Carlo Fusco
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Change in IPSec roadwarrior configuration for MacOSX 10.12
2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
2019-04-04 16:24 ` Carlo Fusco
@ 2019-04-04 18:13 ` Tom Rymes
1 sibling, 0 replies; 3+ messages in thread
From: Tom Rymes @ 2019-04-04 18:13 UTC (permalink / raw)
To: documentation
[-- Attachment #1: Type: text/plain, Size: 1478 bytes --]
Carlo,
Just to confirm, have you put this text into the ipsec.user.conf file
and restarted IPSec?
conn CONNECTION_NAME
leftsendcert=always
leftallowany=yes
rightdns=10.100.2.1
rekey=no
reauth=no
Specifically, the rekey and reauth portions.
I assume yes, but want to double-check.
Tom
On 04/04/2019 12:21 PM, Carlo Fusco wrote:
> Hello,
>
> I have MAC OS X Sierra as an IPSec client and when I configured IPSec
> server on IPFire I found that it was being disconnected every 480 sec
> due to a failed rekey attempt from Mac OS, which happened with the
> configuration proposed in the text of the wiki.
>
> According to the apple developers, a change in the ESP grouptype was
> required ( http://www.openradar.appspot.com/29821241 ). When I tested
> the IPSec suggested configuration everything worked well. Therefore I
> changed the text of the wiki to reflect the issue. I also fixed a non
> matching parenthesis.
>
> Here is the diff:
>
> https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-_roadwarrior_with_macos?do=revisions
>
> Feel free to revert the change if you believe it is necessary or to
> suggest a different wording/place.
>
> Thank you for your time
> --
> Carlo Fusco
> _______________________________________________
> Documentation mailing list
> Documentation(a)lists.ipfire.org
> https://lists.ipfire.org/mailman/listinfo/documentation
>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2019-04-04 18:13 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-04-04 16:21 Change in IPSec roadwarrior configuration for MacOSX 10.12 Carlo Fusco
2019-04-04 16:24 ` Carlo Fusco
2019-04-04 18:13 ` Tom Rymes
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox