[strongSwan] Setting up kernel traps for a subnet

Thom Dixon dixon at cise.ufl.edu
Tue Nov 27 05:31:26 CET 2012


I was wondering if it was possible to configure kernel traps (via
auto=route) on a host Alice, such that whenever Alice attempts a
connection to an address within a specified subnet, say,, a host-to-host tunnel would be established to the
destination. For example, if Bob had the address,
and Alice pinged Bob, then Alice would automatically attempt to
establish a host-to-host tunnel to Bob.

I have tried, quite unsuccessfully, to configure this with
strongSwan 4.4. Should this be possible, an example conn entry
would be most appreciated.


