[strongSwan] Overlapping rightsubnets - Is it possible to determine on which tunnel packet arrived?

Bharath Kumar cbkumar at gmail.com
Fri Apr 5 00:24:30 CEST 2013

Hi All,

I have a question on this scenario.

Left --- Strongswan Gateway

Two connection profiles

conn cisco-asa-1
   right = <ip-of-cisco-asa-1>

conn cisco-asa-2
   right = <ip-of-cisco-asa-2>
   rightsubnet =

As you can see, the rightsubnet is same for both connection profiles. I
want to be able to determine which tunnels the packets came thru when I
receive packets from remote hosts, say

Is there any way to do that? Any help is greatly appreciated!

Bharath Kumar
