mirror of
				https://github.com/strongswan/strongswan.git
				synced 2025-11-03 00:01:15 -05:00 
			
		
		
		
	
		
			
				
	
	
		
			11 lines
		
	
	
		
			636 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			11 lines
		
	
	
		
			636 B
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
The roadwarriors <b>carol</b> and <b>dave</b> set up a connection each 
 | 
						|
to gateway <b>moon</b>. The authentication is based on <b>X.509 certificates</b>.
 | 
						|
Instead of the certificates themselves, "Hash and URL" certificate payloads
 | 
						|
are transferred and the certificates are fetched via http from web server <b>winnetou</b>.
 | 
						|
<p>
 | 
						|
Upon the successful establishment of the IPsec tunnels, <b>leftfirewall=yes</b>
 | 
						|
automatically inserts iptables-based firewall rules that let pass the tunneled traffic.
 | 
						|
In order to test both tunnel and firewall, both <b>carol</b> and <b>dave</b> ping
 | 
						|
the client <b>alice</b> behind the gateway <b>moon</b>.
 | 
						|
</p>
 |