mirror of
https://github.com/strongswan/strongswan.git
synced 2025-10-18 00:00:22 -04:00
config-payload scenario fixes
This commit is contained in:
parent
9b1f4540c6
commit
671a54e9ab
@ -1,11 +1,11 @@
|
|||||||
carol::cat /var/log/daemon.log::installing new virtual IP PH_IP_CAROL1::YES
|
carol::cat /var/log/daemon.log::installing new virtual IP PH_IP_CAROL1::YES
|
||||||
carol::ip addr list dev eth0::PH_IP_CAROL1::YES
|
carol::ip addr list dev eth0::PH_IP_CAROL1::YES
|
||||||
carol::ip route list dev eth0::src PH_IP_CAROL1::YES
|
carol::ip route list dev eth0::10.1.0.0/16.*src PH_IP_CAROL1::YES
|
||||||
carol::ipsec status::home.*INSTALLED::YES
|
carol::ipsec status::home.*INSTALLED::YES
|
||||||
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
dave::cat /var/log/daemon.log::installing new virtual IP PH_IP_DAVE1::YES
|
dave::cat /var/log/daemon.log::installing new virtual IP PH_IP_DAVE1::YES
|
||||||
dave::ip addr list dev eth0::PH_IP_DAVE1::YES
|
dave::ip addr list dev eth0::PH_IP_DAVE1::YES
|
||||||
dave::ip route list dev eth0::src PH_IP_DAVE1::YES
|
dave::ip route list dev eth0::10.1.0.0/16.*src PH_IP_DAVE1::YES
|
||||||
dave::ipsec status::home.*INSTALLED::YES
|
dave::ipsec status::home.*INSTALLED::YES
|
||||||
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
moon::ipsec status::rw-carol.*INSTALLED::YES
|
moon::ipsec status::rw-carol.*INSTALLED::YES
|
||||||
|
@ -1,6 +1,6 @@
|
|||||||
The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each to gateway <b>moon</b>.
|
The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each to gateway <b>moon</b>.
|
||||||
Both <b>carol</b> and <b>dave</b> request a <b>virtual IP</b> via the IKE Mode Config protocol
|
Both <b>carol</b> and <b>dave</b> request a <b>virtual IP</b> via the IKEv2 configuration payload
|
||||||
by using the <b>leftsourceip=%modeconfig</b> parameter. <b>leftfirewall=yes</b> automatically
|
by using the <b>leftsourceip=%config</b> parameter. <b>leftfirewall=yes</b> automatically
|
||||||
inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the
|
inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the
|
||||||
tunnels, <b>carol</b> and <b>dave</b> then ping the client <b>alice</b> behind the gateway
|
tunnels, <b>carol</b> and <b>dave</b> then ping the client <b>alice</b> behind the gateway
|
||||||
<b>moon</b>. The source IP addresses of the two pings will be the virtual IPs <b>carol1</b>
|
<b>moon</b>. The source IP addresses of the two pings will be the virtual IPs <b>carol1</b>
|
||||||
|
@ -1,11 +1,11 @@
|
|||||||
carol::cat /var/log/daemon.log::installing new virtual IP PH_IP_CAROL1::YES
|
carol::cat /var/log/daemon.log::installing new virtual IP PH_IP_CAROL1::YES
|
||||||
carol::ip addr list dev eth0::PH_IP_CAROL1::YES
|
carol::ip addr list dev eth0::PH_IP_CAROL1::YES
|
||||||
carol::ip route list dev eth0::src PH_IP_CAROL1::YES
|
carol::ip route list dev eth0::10.1.0.0/16.*src PH_IP_CAROL1::YES
|
||||||
carol::ipsec status::home.*INSTALLED::YES
|
carol::ipsec status::home.*INSTALLED::YES
|
||||||
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
carol::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
dave::cat /var/log/daemon.log::installing new virtual IP PH_IP_DAVE1::YES
|
dave::cat /var/log/daemon.log::installing new virtual IP PH_IP_DAVE1::YES
|
||||||
dave::ip addr list dev eth0::PH_IP_DAVE1::YES
|
dave::ip addr list dev eth0::PH_IP_DAVE1::YES
|
||||||
dave::ip route list dev eth0::src PH_IP_DAVE1::YES
|
dave::ip route list dev eth0::10.1.0.0/16.*src PH_IP_DAVE1::YES
|
||||||
dave::ipsec status::home.*INSTALLED::YES
|
dave::ipsec status::home.*INSTALLED::YES
|
||||||
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
dave::ping -c 1 PH_IP_ALICE::64 bytes from PH_IP_ALICE: icmp_seq=1::YES
|
||||||
moon::ipsec status::rw-carol.*INSTALLED::YES
|
moon::ipsec status::rw-carol.*INSTALLED::YES
|
||||||
|
Loading…
x
Reference in New Issue
Block a user