[strongSwan] How to always enforce IPsec for all traffic using strongswan ?

Mahendra SP mahendra.sp at gmail.com
Wed Jan 6 08:06:46 CET 2016

I have one linux box with strongswan 5.3.5 and a windows 7 system.

Here is what I am doing:
1. On Linux, I enable IPsec.
2. On windows I enable IPsec.
3. Ping goes over IPsec in this case.
4. I disable IPsec only on windows. I am still able to ping the Linux from
windows even though IPsec policy is enabled on Linux.
4. I can even ping windows from linux.

I am assuming IPsec is not enforced by default for all traffic on linux
even though IPsec policy is enabled. Could you please help me how I can
enforce IPsec by default ?

