User Details
User Details
- User Since
- May 24 2016, 8:14 PM (412 w, 2 d)
May 26 2016
May 26 2016
abferm added a comment to T71: Add virtual IP and route installation policy options for IPsec.
I've found examples of people setting accept_unencrypted_mainmode_messages, cisco_unity, ikesa_table_segments, ikesa_table_size, and init_limit_half_open.
abferm added a comment to T71: Add virtual IP and route installation policy options for IPsec.
The full list of options is available here https://wiki.strongswan.org/projects/strongswan/wiki/StrongswanConf
May 24 2016
May 24 2016
abferm added a comment to T71: Add virtual IP and route installation policy options for IPsec.
install_routes sets a default route in table 220. If this happens on both ends of the tunnel you end up with a circular route.
install_virtual_ip attempts to install an address on the local interface for the ip used in the tunnel