[strongSwan] nfs across strongswan

Cindy Moore ctmoore at cs.ucsd.edu
Wed Sep 24 07:06:14 CEST 2014

Has anyone managed this?
Set up an export to a virtual ip.
Set up a strongswan conn to assign that virtual ip to a specific roadwarrior.
Have that roadwarrior successfully nfs mount the directory once
connected to the vpn.


I find no examples resembling this.  I'm stumped in this process
because all the roadwarriors, even though assigned virtual ip's
correctly according to their tun0 settings, are presenting themselves
as having the ip address of the vpn server, which I assume is because
it's natting everything.  I'm at a loss as to how to get around this,
so if someone has done this, I would LOVE to see your conf files and
your iptable setup, please, please?


