Return to description.txt CVS log | Up to [ELWIX - Embedded LightWeight unIX -] / embedaddon / strongswan / testing / tests / ikev2 / protoport-route |
1.1 misho 1: Using the <b>left|rightprotoport</b> selectors, two IPsec tunnels 2: between the roadwarrior <b>carol</b> and the gateway <b>moon</b> are 3: defined. The first IPsec SA is restricted to ICMP packets and the second 4: covers TCP-based SSH connections. Using <b>add=route</b> %trap 5: eroutes for these IPsec SAs are prepared on <b>carol</b>. By sending 6: a ping to the client <b>alice</b> behind <b>moon</b>, the ICMP eroute 7: is triggered and the corresponding IPsec tunnel is set up. In the same 8: way an ssh session to <b>alice</b> over the second IPsec SA is established.