From mboxrd@z Thu Jan 1 00:00:00 1970 From: Tom Rymes To: documentation@lists.ipfire.org Subject: Re: Change in IPSec roadwarrior configuration for MacOSX 10.12 Date: Thu, 04 Apr 2019 14:13:45 -0400 Message-ID: <796a1325-913e-a293-a3b1-7fd6b6be33a7@rymes.com> In-Reply-To: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2100960230556495835==" List-Id: --===============2100960230556495835== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Carlo, Just to confirm, have you put this text into the ipsec.user.conf file=20 and restarted IPSec? conn CONNECTION_NAME leftsendcert=3Dalways leftallowany=3Dyes rightdns=3D10.100.2.1 rekey=3Dno reauth=3Dno Specifically, the rekey and reauth portions. I assume yes, but want to double-check. Tom On 04/04/2019 12:21 PM, Carlo Fusco wrote: > Hello, >=20 > I have MAC OS X Sierra as an IPSec client and when I configured IPSec > server on IPFire I found that it was being disconnected every 480 sec > due to a failed rekey attempt from Mac OS, which happened with the > configuration proposed in the text of the wiki. >=20 > According to the apple developers, a change in the ESP grouptype was > required ( http://www.openradar.appspot.com/29821241 ). When I tested > the IPSec suggested configuration everything worked well. Therefore I > changed the text of the wiki to reflect the issue. I also fixed a non > matching parenthesis. >=20 > Here is the diff: >=20 > https://wiki.ipfire.org/configuration/services/ipsec/example_configuration-= _roadwarrior_with_macos?do=3Drevisions >=20 > Feel free to revert the change if you believe it is necessary or to > suggest a different wording/place. >=20 > Thank you for your time > -- > Carlo Fusco > _______________________________________________ > Documentation mailing list > Documentation(a)lists.ipfire.org > https://lists.ipfire.org/mailman/listinfo/documentation >=20 --===============2100960230556495835==--