[strongSwan] [EDIT] Traffic selection problems

Tobias Brunner tobias at strongswan.org
Thu Feb 28 10:03:49 CET 2019

Hi Brian,

VTI devices won't change anything.  You can't use transport mode with
any IPs other than those of the endpoints (i.e. it doesn't work with
virtual IPs or arbitrary subnets - you have to use tunnel mode for
that).  [1] might help to explain these modes to you.


[1] http://www.unixwiz.net/techtips/iguide-ipsec.html

