The manager will allow charon-nm to create XFRM interfaces if supported by the kernel instead of creating an unused dummy TUN interface. The xfrmi tool is mostly obsolete nowadays as iproute2 supports creating XFRM interfaces since 5.1.0 (2019-05). Older Debians don't ship that and early versions didn't list the interface IDs. So there might still be some uses for this tool.
17 lines
629 B
Plaintext
17 lines
629 B
Plaintext
moon::iptables-restore < /etc/iptables.rules
|
|
carol::iptables-restore < /etc/iptables.rules
|
|
dave::iptables-restore < /etc/iptables.rules
|
|
moon::ip link add xfrm-moon type xfrm if_id 42 dev eth0
|
|
moon::ip link set xfrm-moon up
|
|
moon::ip route add 10.3.0.0/28 dev xfrm-moon
|
|
moon::iptables -A FORWARD -i xfrm-moon -j ACCEPT
|
|
moon::iptables -A FORWARD -o xfrm-moon -j ACCEPT
|
|
moon::systemctl start strongswan
|
|
carol::systemctl start strongswan
|
|
dave::systemctl start strongswan
|
|
moon::expect-connection rw
|
|
carol::expect-connection home
|
|
carol::swanctl --initiate --child home
|
|
dave::expect-connection home
|
|
dave::swanctl --initiate --child home
|