strongSwan KVM Tests / ikev2 / trap-any

Test ikev2/trap-any

Description

The hosts moon, sun and dave install transport-mode trap policies with remote_addrs=%any. The remote host is dynamically determined based on the acquires received from the kernel. Host dave additionally limits the remote hosts to moon and sun with remote_ts. This is tested by pinging sun and carol from moon, carol from sun, and sun and moon from dave. The latter also pings carol, which is not going to be encrypted as carol is not part of the configured remote_ts. moon winnetou sun carol dave

moon

 

sun

 

carol

 

dave

 

tcpdump