strongSwan KVM Tests / ikev1 / net2net-esn

Test ikev1/net2net-esn

Description

A connection between the subnets behind the gateways moon and sun is set up. With esp=aes128gcm128-esn-noesn-x25519 gateway moon proposes the use of Extended Sequence Numbers but can also live without them. Gateway sun defines esp=aes128gcm128-esn-x25519 and thus decides on the use of ESN. The authentication is based on X.509 certificates.

Upon the successful establishment of the IPsec tunnel, the updown script automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test both tunnel and firewall, client alice behind gateway moon pings client bob located behind gateway sun.

alice moon winnetou sun bob

moon

 

sun

 

tcpdump