I agree that 10s is too short a time when older Libreswan and openswan default to 20s first retry. But 60s sounds like a very long a time for me. Should that be something like 30 to 40 seconds instead? -- Tuomo Soini <tis at foobar.fi> Foobar Linux services +358 40 5240030 Foobar Oy <http://foobar.fi/>