[strongSwan] Srongswan and Routes

2011-06-14 Thread Reinartz Ralf AII . Pforzheim
Hello all, I've to use a vpngate to connect some remote LANs. The gateway has no physical Adresses in some of these Lans. So there are IP routes needed to reach the target Network. Normally with Kernel 2.6.x Strongswan doesn not set, and it seems not need, any IP Rules. With ip xfrm policy I

[strongSwan] Help with fowarding an IP packet on a VPN connection

2011-06-14 Thread Lin, Clifton (US SSA)
I am trying to write code that does the following: 1) Intercept an outbound IP packet (e.g. from a local application) using iptables/netfilter_queue to read the packet into user-space. 2) Then, configure and start a strongSwan VPN connection to the packet destination. 3) Then, forward that

[strongSwan] Test framework not showing iptables rules in tables other than 'filter'

2011-06-14 Thread Daniel Mentz
I'm looking at the config example at http://www.strongswan.org/uml/testresults45/ikev2/nat-two-rw-mark/index.html and I'm wondering where I can find a complete list of all iptables rules that are in effect. iptables -L only displays the rules in the filter table. The rules from the nat and