[Swan] Libreswan 4.3 | Failing with dropping unexpected IKE_SA_INIT message containing NO_PROPOSAL_CHOSEN notification

Paul Wouters paul at nohats.ca
Wed Mar 24 19:36:56 UTC 2021

On Thu, 25 Mar 2021, Blue Aquan wrote:

> Server side
> conn MOBILE
>         left=europa.abc.com
>         leftsubnet=

>         right=%any
>         rightaddresspool=

add leftid=@europa.abc.com

> Client side
> conn EUROPA
>         left=%defaultroute
>         leftsubnet=
>         right=europa.abc.com
>         rightsubnet=
>         rightid=@europa.abc.com

I cannot tell whether you want a tunnel established from <->
Or that you want to hand out an addresspool to the client via rightaddresspool=

If you meant a subnet to subnet, then on the conn MOBILE replace the
addresspool line with rightsubnet=

If you meant giving it a single IP, then remote the
rightsubnet= and add rightsubnet= with narrowing=yes


More information about the Swan mailing list