While the alias is available after enabling the unit, we don't actually do that in our testing environment (adding a symlink manually would work too, then again, why not just use the proper name?).
22 lines
869 B
Plaintext
22 lines
869 B
Plaintext
moon::iptables-restore < /etc/iptables.rules
|
|
carol::iptables-restore < /etc/iptables.rules
|
|
dave::iptables-restore < /etc/iptables.rules
|
|
moon::ip6tables-restore < /etc/ip6tables.rules
|
|
carol::ip6tables-restore < /etc/ip6tables.rules
|
|
dave::ip6tables-restore < /etc/ip6tables.rules
|
|
alice::"ip route add fec3:\:/16 via fec1:\:1"
|
|
moon::ip tunnel add vti0 local PH_IP_MOON remote 0.0.0.0 mode vti key 42
|
|
moon::sysctl -w net.ipv4.conf.vti0.disable_policy=1
|
|
moon::ip link set vti0 up
|
|
moon::"ip route add fec3:\:/16 dev vti0"
|
|
moon::ip6tables -A FORWARD -i vti0 -j ACCEPT
|
|
moon::ip6tables -A FORWARD -o vti0 -j ACCEPT
|
|
moon::systemctl start strongswan
|
|
carol::systemctl start strongswan
|
|
dave::systemctl start strongswan
|
|
moon::expect-connection rw
|
|
carol::expect-connection home
|
|
carol::swanctl --initiate --child home
|
|
dave::expect-connection home
|
|
dave::swanctl --initiate --child home
|