From bcf608c848923ab7e292941beca6dc69c5ff2634 Mon Sep 17 00:00:00 2001 From: Andreas Steffen Date: Fri, 9 Jul 2010 09:35:02 +0200 Subject: [PATCH] some changes to the ikev2/nat-two-rw-mark scenario --- testing/tests/ikev2/nat-two-rw-mark/description.txt | 6 ++++-- testing/tests/ikev2/nat-two-rw-mark/posttest.dat | 2 -- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/testing/tests/ikev2/nat-two-rw-mark/description.txt b/testing/tests/ikev2/nat-two-rw-mark/description.txt index 7e844a533..4b9f43404 100644 --- a/testing/tests/ikev2/nat-two-rw-mark/description.txt +++ b/testing/tests/ikev2/nat-two-rw-mark/description.txt @@ -5,8 +5,10 @@ after ESP decryption to map these subnets to 10.3.0.10 and 10.3.0.20, respective

In order to differentiate between the tunnels to alice and venus, respectively, XFRM marks are defined for both the inbound and outbound IPsec SAs and policies using -the mark= ipsec.conf parameter. iptables -t mangle rules are then used in the PREROUTING -chain to mark the traffic to and from alice and venus, respectively. +the mark parameter in ipsec.conf. +

+iptables -t mangle rules are then used in the PREROUTING chain to mark the traffic to +and from alice and venus, respectively.

leftfirewall=yes automatically inserts iptables-based firewall rules that let pass the tunneled traffic. In order to test the tunnel, the NAT-ed hosts alice and venus diff --git a/testing/tests/ikev2/nat-two-rw-mark/posttest.dat b/testing/tests/ikev2/nat-two-rw-mark/posttest.dat index 205f644a7..df49eb777 100644 --- a/testing/tests/ikev2/nat-two-rw-mark/posttest.dat +++ b/testing/tests/ikev2/nat-two-rw-mark/posttest.dat @@ -6,6 +6,4 @@ venus::/etc/init.d/iptables stop 2> /dev/null sun::/etc/init.d/iptables stop 2> /dev/null moon::iptables -t nat -F moon::conntrack -F -sun::iptables -t mangle -F -sun::iptables -t nat -F sun::conntrack -F