[strongSwan] Single physical interface "roadwarrior" responder using DHCP/FARP

Michael .. mikey at usa.com
Wed Apr 11 18:56:28 CEST 2018

I'm trying to configure a responder for use in a "roadwarrior" scenario, albeit unsuccessfully.
-ip route
default via dev eth0 src metric 202 dev eth0 proto kernel scope link src metric 202
Default gateway @ provides internet access and also inbound NAT forwarding of ports 500/4500 from an internet IP.

conn %default
conn rw
-ip route show table 220 via dev eth0 proto static
I am able to establish a VPN connection from the internet to the responder and the client is assigned an IP from the DHCP pool.
The responder can ping the client's IP address assigned from DHCP - therefore 2-way communication over the tunnel.  The remote internet client can also send packets over the tunnel to the rest of the subnet which reach their destination (e.g. to  The responder then correctly replies to ARP on behalf of the clients address (e.g. and the return packet arrives to the responders interface.  However, the responder is replying with ICMP redirect to to the sender and therefore the return packet does not reach the client.
Any ideas?

