[Swan] Host-to-Host Transport Mode
Dtsveitel at smartronix.com
Fri Mar 27 05:24:31 EET 2015
I hope someone can help me with a problem I am having setting up IPsec transport mode between two CentOS 7 hosts. I have two hosts on the same subnet. Both are using the same ipsec.conf:
Then, in /etc/ipsec.d/nodes.conf on Host A:
And on Host B:
When I first start the two hosts, I cannot connect to Host B from Host A, or vice versa (I test using ssh). However, if I first try to connect from Host A to Host B (which fails), and then from Host B to Host A, the connection from B to A succeeds, and subsequent connections from A to B also work. Going in the opposite order produces the same result. The connections start working once I have initiated a connection from each host.
My understanding was that it would be sufficient to set auto=start to ensure the tunnels were up on startup.
These hosts are both in an AWS VPC, with a Security Group permitting UDP 500 and 4500.
I would appreciate any suggestions you could offer. Thanks! Dmitri
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Swan