added ikev2/nat-two-rw-mark scenario

This commit is contained in:
Andreas Steffen
2010-07-03 13:25:09 +02:00
parent ee26c537d7
commit 342fc85e9e
11 changed files with 185 additions and 0 deletions
@@ -0,0 +1,13 @@
The roadwarriors <b>alice</b> and <b>venus</b> sitting behind the NAT router <b>moon</b> set up
tunnels to gateway <b>sun</b>. UDP encapsulation is used to traverse the NAT router.
Since both roadwarriors possess the same 10.1.0.0/25 subnet, gateway <b>sun</b> uses Source NAT
after ESP decryption to map these subnets to 10.3.0.10 and 10.3.0.20, respectively.
<p/>
In order to differentiate between the tunnels to <b>alice</b> and <b>venus</b>, respectively,
<b>XFRM marks</b> are defined for both the inbound and outbound IPsec SAs and policies using
the <b>mark=</b> ipsec.conf parameter. <b>iptables -t mangle</b> rules are then used in the PREROUTING
chain to mark the traffic to and from <b>alice</b> and <b>venus</b>, respectively.
<p/>
<b>leftfirewall=yes</b> automatically inserts iptables-based firewall rules that let pass
the tunneled traffic. In order to test the tunnel, the NAT-ed hosts <b>alice</b> and <b>venus</b>
ping the client <b>bob</b> behind the gateway <b>sun</b>.