Привет. Прошу помощь к подключению, всё настроил ключи сгенерил в том числе и под винды, но не хочет. /etc/strongswan/ipsec.conf
config setup
uniqueids=never
charondebug="ike 2, knl 2, cfg 2, net 2, esp 2, dmn 2, mgr 2"
conn %default
keyexchange=ikev2
ike=aes128gcm16-sha2_256-prfsha256-ecp256!
esp=aes128gcm16-sha2_256-ecp256!
fragmentation=yes
rekey=no
compress=yes
dpdaction=clear
left=%any
leftauth=pubkey
leftsourceip=server_vps
leftid=server_vps
leftcert=server-cert.pem
leftsendcert=always
leftsubnet=0.0.0.0/0
right=%any
rightauth=pubkey
rightsourceip=10.10.10.0/24
rightdns=8.8.8.8,8.8.4.4
conn ikev2-pubkey
auto=add
Лог:
[root@localhost strongswan]# swanctl --log
plugin 'sqlite': failed to load - sqlite_plugin_create not found and no plugin file available
08[NET] received packet: from home_ip[500] to server_vps[500] (1104 bytes)
08[ENC] parsed IKE_SA_INIT request 0 [ SA KE No N(FRAG_SUP) N(NATD_S_IP) N(NATD_D_IP) V V V V ]
08[IKE] received MS NT5 ISAKMPOAKLEY v9 vendor ID
08[IKE] received MS-Negotiation Discovery Capable vendor ID
08[IKE] received Vid-Initial-Contact vendor ID
08[ENC] received unknown vendor ID: 01:52:8b:bb:c0:06:96:12:18:49:ab:9a:1c:5b:2a:51:00:00:00:02
08[IKE] home_ip is initiating an IKE_SA
08[CFG] received proposals: IKE:3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:3DES_CBC/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:3DES_CBC/HMAC_SHA2_384_192/PRF_HMAC_SHA2_384/MODP_1024, IKE:AES_CBC_128/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_128/HMAC_SHA2_384_192/PRF_HMAC_SHA2_384/MODP_1024, IKE:AES_CBC_192/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_192/HMAC_SHA2_384_192/PRF_HMAC_SHA2_384/MODP_1024, IKE:AES_CBC_256/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024, IKE:AES_CBC_256/HMAC_SHA2_256_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_CBC_256/HMAC_SHA2_384_192/PRF_HMAC_SHA2_384/MODP_1024, IKE:AES_GCM_16_128/PRF_HMAC_SHA1/MODP_1024, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_GCM_16_128/PRF_HMAC_SHA2_384/MODP_1024, IKE:AES_GCM_16_256/PRF_HMAC_SHA1/MODP_1024, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_256/MODP_1024, IKE:AES_GCM_16_256/PRF_HMAC_SHA2_384/MODP_1024
08[CFG] configured proposals: IKE:AES_GCM_16_128/PRF_HMAC_SHA2_256/ECP_256
08[IKE] remote host is behind NAT
08[IKE] received proposals unacceptable
08[ENC] generating IKE_SA_INIT response 0 [ N(NO_PROP) ]
08[NET] sending packet: from server_vps[500] to home_ip[500] (36 bytes)
11[NET] received packet: from home_ip[500] to server_vps[500] (408 bytes)
11[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V ]
11[IKE] no IKE config found for server_vps...home_ip, sending NO_PROPOSAL_CHOSEN
11[ENC] generating INFORMATIONAL_V1 request 1880878183 [ N(NO_PROP) ]
11[NET] sending packet: from server_vps[500] to home_ip[500] (40 bytes)
12[NET] received packet: from home_ip[500] to server_vps[500] (408 bytes)
12[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V ]
12[IKE] no IKE config found for server_vps...home_ip, sending NO_PROPOSAL_CHOSEN
12[ENC] generating INFORMATIONAL_V1 request 2664976946 [ N(NO_PROP) ]
12[NET] sending packet: from server_vps[500] to home_ip[500] (40 bytes)
09[NET] received packet: from home_ip[500] to server_vps[500] (408 bytes)
09[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V ]
09[IKE] no IKE config found for server_vps...home_ip, sending NO_PROPOSAL_CHOSEN
09[ENC] generating INFORMATIONAL_V1 request 1675694728 [ N(NO_PROP) ]
09[NET] sending packet: from server_vps[500] to home_ip[500] (40 bytes)
03[NET] received packet: from home_ip[500] to server_vps[500] (408 bytes)
03[ENC] parsed ID_PROT request 0 [ SA V V V V V V V V ]
03[IKE] no IKE config found for server_vps...home_ip, sending NO_PROPOSAL_CHOSEN
03[ENC] generating INFORMATIONAL_V1 request 1502460016 [ N(NO_PROP) ]
03[NET] sending packet: from server_vps[500] to home_ip[500] (40 bytes)