mirror of
https://github.com/strongswan/strongswan.git
synced 2025-10-05 00:00:45 -04:00
While the alias is available after enabling the unit, we don't actually do that in our testing environment (adding a symlink manually would work too, then again, why not just use the proper name?).
18 lines
678 B
Plaintext
18 lines
678 B
Plaintext
moon::iptables-restore < /etc/iptables.rules
|
|
carol::iptables-restore < /etc/iptables.rules
|
|
dave::iptables-restore < /etc/iptables.rules
|
|
moon::ip tunnel add vti0 local PH_IP_MOON remote 0.0.0.0 mode vti key 42
|
|
moon::sysctl -w net.ipv4.conf.vti0.disable_policy=1
|
|
moon::ip link set vti0 up
|
|
moon::ip route add 10.3.0.0/28 dev vti0
|
|
moon::iptables -A FORWARD -i vti0 -j ACCEPT
|
|
moon::iptables -A FORWARD -o vti0 -j ACCEPT
|
|
moon::systemctl start strongswan
|
|
carol::systemctl start strongswan
|
|
dave::systemctl start strongswan
|
|
moon::expect-connection rw
|
|
carol::expect-connection home
|
|
carol::swanctl --initiate --child home
|
|
dave::expect-connection home
|
|
dave::swanctl --initiate --child home
|