While the alias is available after enabling the unit, we don't actually do that in our testing environment (adding a symlink manually would work too, then again, why not just use the proper name?).
13 lines
492 B
Plaintext
13 lines
492 B
Plaintext
moon::iptables-restore < /etc/iptables.rules
|
|
sun::iptables-restore < /etc/iptables.rules
|
|
moon::/usr/local/libexec/ipsec/xfrmi -n xfrm-moon -i 42 -d eth0
|
|
moon::ip link set xfrm-moon up
|
|
moon::ip route add 10.2.0.0/16 dev xfrm-moon
|
|
moon::iptables -A FORWARD -i xfrm-moon -j ACCEPT
|
|
moon::iptables -A FORWARD -o xfrm-moon -j ACCEPT
|
|
moon::systemctl start strongswan
|
|
sun::systemctl start strongswan
|
|
moon::expect-connection gw-gw
|
|
sun::expect-connection gw-gw
|
|
moon::swanctl --initiate --child net-net
|