[strongSwan] Is there any way to specify/configure different initiator_tsr for each initiator?

Martin Willi martin at strongswan.org
Wed May 20 11:34:33 CEST 2015


> As per the implementation, an SPD entry would contain the destination
> IP as selector field and uses the same as a key to search the SPD
> table.

I don't think this will work; The remote selector does not have to be
unique per CHILD_SA/policy. Having multiple CHILD_SAs having the same
remote selector is perfectly fine, and is what load-tester establishes
even when it requests a virtual IP.

You should include the local address in the SPD lookup as well.

Regards
Martin




More information about the Users mailing list