[strongSwan-dev] Load-tester issue

Tobias Brunner tobias at strongswan.org
Thu Feb 12 09:38:00 CET 2015

Hi Meenakshi,

>             request_virtual_ip = yes
>             ...
>             initiator_ts =

If you use `request_virtual_ip = yes` you don't have to specify the
initiator's traffic selector (`initiator_ts` is actually not a valid
option, the initiator's local TS would be set in `initiator_tsi`).

But to replace the default route and not only tunnel traffic to your
responder (i.e. you'll have to specify `initiator_tsr
=`, otherwise the responder, even when configured with
`leftsubnet =`, will narrow the remote TS to the single IP
address proposed by the client.

> Also I see that my ipsec statusall shows everything to be /32 but i
> have configured on the server for it to be /24.

The option `rightsourceip=` specifies an IP address pool for
virtual IP addresses assigned to clients, not a traffic selector.  In
your case the address is assigned to the client via
configuration payloads.


