diff --git a/testing/tests/ikev2/nat-two-rw-mark/description.txt b/testing/tests/ikev2/nat-two-rw-mark/description.txt index 7e844a533..4b9f43404 100644 --- a/testing/tests/ikev2/nat-two-rw-mark/description.txt +++ b/testing/tests/ikev2/nat-two-rw-mark/description.txt @@ -5,8 +5,10 @@ after ESP decryption to map these subnets to 10.3.0.10 and 10.3.0.20, respective
In order to differentiate between the tunnels to alice and venus, respectively, XFRM marks are defined for both the inbound and outbound IPsec SAs and policies using -the mark= ipsec.conf parameter. iptables -t mangle rules are then used in the PREROUTING -chain to mark the traffic to and from alice and venus, respectively. +the mark parameter in ipsec.conf. + +iptables -t mangle rules are then used in the PREROUTING chain to mark the traffic to +and from alice and venus, respectively. leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the tunnel, the NAT-ed hosts alice and venus diff --git a/testing/tests/ikev2/nat-two-rw-mark/posttest.dat b/testing/tests/ikev2/nat-two-rw-mark/posttest.dat index 205f644a7..df49eb777 100644 --- a/testing/tests/ikev2/nat-two-rw-mark/posttest.dat +++ b/testing/tests/ikev2/nat-two-rw-mark/posttest.dat @@ -6,6 +6,4 @@ venus::/etc/init.d/iptables stop 2> /dev/null sun::/etc/init.d/iptables stop 2> /dev/null moon::iptables -t nat -F moon::conntrack -F -sun::iptables -t mangle -F -sun::iptables -t nat -F sun::conntrack -F