Harald Dunkel
2018-07-23 13:44:53 UTC
Hi folks,
the documentation say for left|rightikeport
"If unspecified, port 500 is used with the port floating to 4500 if a
NAT is detected ..."
This sounds pretty vague. I would like to tell strongswan to use 443/udp
for NAT traversal and dead peer detection, and to use port 500/udp for
isakmp as usual. AFAICT this can be done with charon.port and charon.\
port_nat_t, so I wonder what is left|rightikeport good for?
Every insightful comment is highly appreciated
Harri
the documentation say for left|rightikeport
"If unspecified, port 500 is used with the port floating to 4500 if a
NAT is detected ..."
This sounds pretty vague. I would like to tell strongswan to use 443/udp
for NAT traversal and dead peer detection, and to use port 500/udp for
isakmp as usual. AFAICT this can be done with charon.port and charon.\
port_nat_t, so I wonder what is left|rightikeport good for?
Every insightful comment is highly appreciated
Harri