[strongSwan] Isolate clients and force local network traffic to an interface

Loc Nguyen ncore at nic.fi
Tue Nov 28 20:37:12 CET 2017


Hi,

I create an IPsec network 10.11.0.0/16 and using dnsmasq to assign IP addresses.

I able to route all 10.11.0.0/16 network traffic to an interface. I would like also route local network 10.11.0.0/16 between client to client to that interface too. 

I can use iptables FORWARD to block client to client. Instead of blocking I want the traffic to the interface.

Thanks,
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20171128/71006810/attachment.html>


More information about the Users mailing list