File:  [ELWIX - Embedded LightWeight unIX -] / embedaddon / strongswan / testing / tests / route-based / rw-shared-xfrmi / description.txt
Revision 1.1.1.1 (vendor branch): download - view: text, annotated - select for diffs - revision graph
Wed Jun 3 09:46:46 2020 UTC (4 years, 2 months ago) by misho
Branches: strongswan, MAIN
CVS tags: v5_9_2p0, v5_8_4p7, HEAD
Strongswan

The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each to
gateway <b>moon</b>. Both <b>carol</b> and <b>dave</b> request a <b>virtual
IP</b> via IKEv2 configuration payload.
<p/>
The gateway <b>moon</b> uses <b>route-based forwarding</b> with an <b>XFRM
interface</b>, with firewall rules to allow traffic to pass. The IKE daemon
does not install routes for CHILD_SAs with outbound interface ID, so a static
route is installed for the virtual IP subnet via XFRM interface.
<p/>
Both <b>carol</b> and <b>dave</b> ping the client <b>alice</b> behind the
gateway <b>moon</b>. The source IP addresses of the two pings will be the
virtual IPs <b>carol1</b> and <b>dave1</b>, respectively.

FreeBSD-CVSweb <freebsd-cvsweb@FreeBSD.org>