File:  [ELWIX - Embedded LightWeight unIX -] / embedaddon / strongswan / testing / tests / ikev2 / trap-any / description.txt
Revision 1.1.1.1 (vendor branch): download - view: text, annotated - select for diffs - revision graph
Wed Jun 3 09:46:47 2020 UTC (4 years, 2 months ago) by misho
Branches: strongswan, MAIN
CVS tags: v5_9_2p0, v5_8_4p7, HEAD
Strongswan

The hosts <b>moon</b>, <b>sun</b> and <b>dave</b> install <b>transport-mode</b> trap
policies with <b>right=%any</b>.  The remote host is dynamically determined based on
the acquires received from the kernel.  Host <b>dave</b> additionally limits the remote
hosts to <b>moon</b> and <b>sun</b> with <b>rightsubnet</b>.  This is tested by
pinging <b>sun</b> and <b>carol</b> from <b>moon</b>, <b>carol</b> from <b>sun</b>, and
<b>sun</b> and <b>moon</b> from <b>dave</b>. The latter also pings <b>carol</b>, which
is not going to be encrypted as <b>carol</b> is not part of the configured <b>rightsubnet</b>.

FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>