[Swan] L2TP/IPsec with certificates: INVALID_KEY_INFORMATION

Paul Wouters paul at nohats.ca
Mon May 2 03:36:18 UTC 2016


On Sun, 1 May 2016, Sergio Belkin wrote:

> 2016-05-01 16:37 GMT-03:00 Paul Wouters <paul at nohats.ca>:
>       ipsec whack --trafficstatus
> 
> No traffic :'-(
> 
> 000 
> 006 #2: "windows", type=ESP,  add_time=1462134295, inBytes=0, outBytes=0,
> id='CN=vpn.example.com'
> 000

sure, but the tunnel is up. You can test if it gets encrypted using
something like:

echo test | nc -s yourip windowsip -u -p 1701

then run ipsec whack --trafficstatus to check the outBytes counter.

Paul


More information about the Swan mailing list