[strongSwan] Linux routing issue

Noel Kuntze noel.kuntze+strongswan-users-ml at thermi.consulting
Mon Jan 24 20:24:00 CET 2022


Hello Carlos,

Either the mark didn't take, you're using an old version (some had a different behaviour in regards to marks and how routes are set when marks are set on the connection configuration).

If you do not require the setting of source IP addresses for the remote subnets, just disable installing of routes, and use XFRM interfaces so you can use routes to direct traffic instead of dealing with the XFRM policies.

Kind regards
Noel

Am 24.01.22 um 12:44 schrieb Carlos G Mendioroz:
> Hi,
> trying to set up a VPN on a lab system with many interfaces
> (Ubuntu 20.04, 2 uplinks, IPv6 tunnel, vlans, openvpn and IPIP tunnel).
> 
> It's been a while since I used strongswan, but it was easy to set up using ipsec command and ipsec.conf policies. ipsec route table (220) played fine with my own rules I use mainly to source route to Internet uplinks.
> 
> Now I want to setup a routed VPN (AWS transit gateway on the other end) and as soon as link comes up, all my traffic gets routed by main table.
> (I changed policy to any any and at first did not specifiy mark, and it even disconnected from the local net, not nice on a headless server)
> Now with mark it still makes all the traffic ignore rule priorities.
> 
> Any pointer to what to check ?
> TIA,
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20220124/828c8a19/attachment.sig>


More information about the Users mailing list