strongSwan KVM Tests / ikev1 / rw-cert-unity

Test ikev1/rw-cert-unity

Description

The roadwarrior carol sets up a connection to gateway moon. The authentication is based on X.509 certificates. carol requests a virtual IP using the vips = 0.0.0.0 parameter and indicates support for the Cisco Unity extension. Gateway moon responds with two Split-Include subnets configured in the local_ts definition and a global Local-LAN exclude option defined in strongswan.conf.

A ping from carol to alice successfully checks the established tunnel.

alice moon carol winnetou

moon

 

carol

 

tcpdump