[strongSwan] Using StrongSwan with VTI devices

Brad Johnson bjohnson at ecessa.com
Tue Sep 2 21:38:54 CEST 2014

We set a mark for the SA in ipsec.conf (e.g. 'mark=100') and create a 
vti link with the same key (e.g. 'key=100'). Then we just add routes to 
remote subnets over the vti device.


On 09/02/2014 01:37 PM, Andre Valentin wrote:
> Hello!
> I read your mails about VTI devices. I'am currently experimenting with 
> it, but without success.
> Here is the documentation I followed:
> https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/net/ipv4/ip_vti.c?h=linux-3.16.y&id=7263a5187f9e9de45fcb51349cf0e031142c19a1 
> But it does not work. Do you have a hint for me how you have 
> implemented it? I also added the mailinglist
> to document it for others.
> Kind regards,
> André

More information about the Users mailing list