[strongSwan] Design comments - site to site connection

2016-11-05 Thread Turbo Fredriksson
I want/need to create a site to site connection between my own VPN server and the work server I’ve setup. The work server runs StrongSWAN v5.3.5 and my own runs v5.2.1 and we both have our own, individual private CAs. So I have full control of both sides certificate generation. Should I use a P

[strongSwan] Why doesn't table 220 change forwarded packets source IP address?

2016-11-05 Thread Richard Chan
Hi, in the roadwarrior configuration, from a conceptual point of view, why doesn't table 220 change the source IP address of forwarded packets (say the roadwarrior has a subnet behind it)? # ip ro sho table 220 10.0.0.0/8 via 192.168.1.1 dev eth0 proto static src 10.2.0.3 # ip rule show 0: