[Swan] Android VPN not passing any traffic, OSX does work

Paul Wouters paul at nohats.ca
Sun Mar 12 21:50:23 UTC 2017


On Sun, 12 Mar 2017, Viktor Keremedchiev wrote:

> Subject: Re: [Swan] Android VPN not passing any traffic, OSX does work
> 
> I weren’t but VPN under OSX and Windows (Shrew client) worked.
>
> Now I do exclude it (via Iptables policy match) and Android behaves same way - connects but no traffic

I'm confused then. Perhaps tcpdumo can show what's going on?

> On a separate note: can I do have ikev2 + xauth with libreswan 3.19?

XAUTH is a protocol extension to IKEv1 only. You can run IKEv2 with CP
to get the same functionality:

https://libreswan.org/wiki/VPN_server_for_remote_clients_using_IKEv2

For Android to use IKEv2, you will need to install the strongswan
client. It is known to properly interop with libreswan as a server,
provided you use IKEv2 Machine Certificates (as per above link)

Paul


More information about the Swan mailing list