[Openswan Users] Should be a simple routing question

Greg Scott GregScott at InfraSupportEtc.com
Thu Aug 24 12:55:42 EDT 2006

Thanks guys.  Been buried the past two days.  I will try this when I get
back later this afternoon or tonight and report the results.  Does that
passthru conn do the same thing as the ip xfrm policy stuff?  Is there
any documentation anywhere on how to use ip xfrm policy?  


- Greg Scott

-----Original Message-----
From: users-bounces at openswan.org [mailto:users-bounces at openswan.org] On
Behalf Of Paul Wouters
Sent: Tuesday, August 22, 2006 1:48 PM
To: Andy Gay
Cc: users at openswan.org; Greg Scott
Subject: Re: [Openswan Users] Should be a simple routing question

On Tue, 22 Aug 2006, Andy Gay wrote:

> > Left <------> Right
> >      Site B                      Site A
> >
> > The tunnel works great - both sides see each ohter just fine, thanks

> > to lots of help from people in this list.
> >
> > Here's the issue.  When I traceroute from the siteB router at 
> > to anything else in SiteB, it tries to route via SiteA!  
> > Very strange indeed!
> >
> > Well, it kind of makes sense because my tunnel definition evidently 
> > told it to behave this way.  I was wondering if there is a way to 
> > make the local route happen before the tunnel route?
> I don't think this is a routing issue, it's to do with IPsec policy.
> Your policy says anything with source address and 
> destination should be sent through the tunnel.
> Try doing this on the siteB router:
> ip xfrm policy add dir in src dst ip xfrm 
> policy add dir out src dst
> That will add some more specific policies for local traffic.
> I believe there's a way to do that using a passthrough conn as well, 
> I'm not certain about the syntax for that.


conn pass-localstuff

Users at openswan.org
Building and Integrating Virtual Private Networks with Openswan: 

More information about the Users mailing list