[strongSwan] Why doesn't table 220 change forwarded packets source IP address?

Richard Chan richard at treeboxsolutions.com
Sat Nov 5 18:01:57 CET 2016

Hi, in the roadwarrior configuration, from a conceptual point of view, why
doesn't table 220 change the source IP address of forwarded packets (say
the roadwarrior has a subnet behind it)?

# ip ro sho table 220 via dev eth0  proto static  src

# ip rule show
0:      from all lookup local
220:    from all lookup 220
32766:  from all lookup main
32767:  from all lookup default

roadwarrior has a separate subnet and is forwarding/NAT'ing
packets.  When  I ping a host on the central site LAN

- OUTPUT chain sees the source IP address as (table 220 is
-  FORWARD chain sees the source IP address as 192.168.2.X  (host cannot be
reached until these packets are SNAT'ed to

Richard Chan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20161106/ddf93a15/attachment.html>

More information about the Users mailing list