Libreswan does not establish IKEv1 IPsec tunnel with XAUTH enabled but ModeCFG disabled
Issue
If libreswan is configured as an IKEv1 XAUTH client with xauthclient=yes, but ModeCFG for IP address assignment is disabled using modecfgclient=no in connection configuration, it does not fully establish the IKE SA and both IKE SA and consequent IPSec SA are torn down by exhausted EVENT_v1_RETRANSMITs within seconds.
Environment
- Red Hat Enterprise Linux 7
libreswan-3.20-3.el7and lower
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.