[strongSwan] Restricting protocol and port numbers question

Tobias Brunner tobias at strongswan.org
Fri Sep 4 10:25:32 CEST 2020

Hi Makarand,

> All the same, the packets are not pushed into the tunnel:
> ping -I
> PING ( from : 56(84) bytes of data.
> ping: sendmsg: Network is unreachable
> ping: sendmsg: Network is unreachable
> The ip xfrm policy seems to be correct:
> src dst proto icmp 
> 	dir fwd priority 375167 ptype main 
> 	tmpl src dst
> 		proto esp reqid 1 mode tunnel
> Would highly appreciate if anyone can point the error in my configuration?

No routes are installed in table 220 for policies with port/protocol
restrictions.  So make sure you have routes installed that allow to
reach the remote networks.


