While the alias is available after enabling the unit, we don't actually do that in our testing environment (adding a symlink manually would work too, then again, why not just use the proper name?).
15 lines
615 B
Plaintext
15 lines
615 B
Plaintext
moon::iptables-restore < /etc/iptables.rules
|
|
sun::iptables-restore < /etc/iptables.rules
|
|
moon::/usr/local/libexec/ipsec/xfrmi -n xfrm-moon-out -d eth0 -i 1337
|
|
moon::/usr/local/libexec/ipsec/xfrmi -n xfrm-moon-in -d eth0 -i 42
|
|
moon::ip link set xfrm-moon-out up
|
|
moon::ip link set xfrm-moon-in up
|
|
moon::ip route add 10.2.0.0/16 dev xfrm-moon-out
|
|
moon::iptables -A FORWARD -o xfrm-moon-out -j ACCEPT
|
|
moon::iptables -A FORWARD -i xfrm-moon-in -j ACCEPT
|
|
moon::systemctl start strongswan
|
|
sun::systemctl start strongswan
|
|
moon::expect-connection gw-gw
|
|
sun::expect-connection gw-gw
|
|
moon::swanctl --initiate --child net-net
|