This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPSec Site 2 Site VPN XG 115

Hi,

I've setup one Site 2 Site VPN between two XG 115, link is up but I'm unable to ping host on site 1 from host/firewall on site 2 and viceversa, below the configuration:

 

SITE 1 (branch office):

 

 

SITE 2 (head office):

 

 

Site 1 XG115 has SFOS 17.0.0 GA firwmare

Site 2 XG115 had SFOS 16.05.5 MR-5 firmware

Thank you!

 



This thread was automatically locked due to age.
Parents Reply
  • Some time back in past when sha2 256 was pretty new with ipsec, the truncation length was not yet standardised. Thus there are some old implementations which do the truncation with SHA2 256 wrong. Since the IKE protocol cannot find out which truncation is used, the only way is to provide this checkbox to give the customer a chance to connect to such machines.

    Here is the upstream ticket Markus used to provide the patch to the strongswan project:

    wiki.strongswan.org/.../1353

Children
No Data