[strongSwan] StrongSwan traffic accounting? is it possible?

Luke Pascoe Luke.Pascoe at gen-i.co.nz
Sun Oct 16 22:50:35 CEST 2011


I would have thought you could use iptables with something like ipac_ng (at least, that’s what I used to use for accounting “back in the day”)

I haven’t done accounting for VPN traffic myself, but I imagine you should be able to match by policy eg “-m policy -pol ipsec” to be sure you’re counting encapsulated traffic.

Luke.

From: users-bounces+luke.pascoe=gen-i.co.nz at lists.strongswan.org [mailto:users-bounces+luke.pascoe=gen-i.co.nz at lists.strongswan.org] On Behalf Of jacky_he
Sent: Monday, 17 October 2011 12:35 a.m.
To: users at lists.strongswan.org
Subject: [strongSwan] StrongSwan traffic accounting? is it possible?

Hi everyone,

Currently StrongSwan supports radius authenticate, but lack of accounting feature.
Is it possible to do traffic accounting on strongswan ipsec connection? Or to use iptables?
Please give me some hints.

Best Regards
Jacky

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20111017/ca99d428/attachment.html>
-------------- next part --------------
Mgate3.telecom.co.nz made the following annotations
---------------------------------------------------------------------
This communication, including any attachments, is confidential. If you are not
the intended recipient, you should not read it - please contact me immediately,
destroy it, and do not copy or use any part of this communication or disclose
anything about it. Thank you. Please note that this communication does not
designate an information system for the purposes of the Electronic Transactions
Act 2002.
---------------------------------------------------------------------



More information about the Users mailing list