Skip to content

When the Windows client (10) connects to the StrongSwan server, the server's internet IP is lost #2200

Answered by tobiasbrunner
TelDragon asked this question in Q&A
Discussion options

You must be logged in to vote

You can only match multiple identities via wildcards (e.g. *@strongswan.org). And it will only work if clients actually send useful IKE identities (e.g. Windows doesn't if EAP authentication is used, it just sends the private IP address). Matching the server identity has a similar issue as some clients don't send a remote identity (again, Windows is one of them, strongSwan's Android client as well, by default). But either might be OK, if you want to use one of the connections only for very specific clients (that can send a proper local or remote IKE identity), and the other connection (that hasn't configured any specific local or remote identity) is the fallback for all other clients. And…

Replies: 1 comment 18 replies

Comment options

You must be logged in to vote
18 replies
@tobiasbrunner
Comment options

@TelDragon
Comment options

@TelDragon
Comment options

@tobiasbrunner
Comment options

Answer selected by TelDragon
@TelDragon
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants