aboutsummaryrefslogtreecommitdiffstats
path: root/testing/tests/ikev2/mobike
diff options
context:
space:
mode:
authorAndreas Steffen <andreas.steffen@strongswan.org>2008-11-25 08:11:14 +0000
committerAndreas Steffen <andreas.steffen@strongswan.org>2008-11-25 08:11:14 +0000
commit895a1156d582deac5a03e8a6d84578435fe9db0d (patch)
tree984f73e59215ee46a119f417ac88c2e3fe9db3e6 /testing/tests/ikev2/mobike
parentf1f09810fb89e2d6f2883edbd82822615ec015c4 (diff)
downloadstrongswan-895a1156d582deac5a03e8a6d84578435fe9db0d.tar.bz2
strongswan-895a1156d582deac5a03e8a6d84578435fe9db0d.tar.xz
use static IPsec policy iptables rule for alice in mobike scenario
Diffstat (limited to 'testing/tests/ikev2/mobike')
-rwxr-xr-xtesting/tests/ikev2/mobike/hosts/alice/etc/init.d/iptables4
-rwxr-xr-xtesting/tests/ikev2/mobike/hosts/alice/etc/ipsec.conf1
2 files changed, 4 insertions, 1 deletions
diff --git a/testing/tests/ikev2/mobike/hosts/alice/etc/init.d/iptables b/testing/tests/ikev2/mobike/hosts/alice/etc/init.d/iptables
index db18182a3..cf0d65c58 100755
--- a/testing/tests/ikev2/mobike/hosts/alice/etc/init.d/iptables
+++ b/testing/tests/ikev2/mobike/hosts/alice/etc/init.d/iptables
@@ -17,6 +17,10 @@ start() {
/sbin/iptables -P OUTPUT DROP
/sbin/iptables -P FORWARD DROP
+ # allow IPsec tunnel traffic
+ iptables -A INPUT -m policy --dir in --pol ipsec --proto esp -j ACCEPT
+ iptables -A OUTPUT -m policy --dir out --pol ipsec --proto esp -j ACCEPT
+
# allow esp
iptables -A INPUT -i eth0 -p 50 -j ACCEPT
iptables -A INPUT -i eth1 -p 50 -j ACCEPT
diff --git a/testing/tests/ikev2/mobike/hosts/alice/etc/ipsec.conf b/testing/tests/ikev2/mobike/hosts/alice/etc/ipsec.conf
index 37e92cf5b..6c87468bb 100755
--- a/testing/tests/ikev2/mobike/hosts/alice/etc/ipsec.conf
+++ b/testing/tests/ikev2/mobike/hosts/alice/etc/ipsec.conf
@@ -16,7 +16,6 @@ conn mobike
left=PH_IP_ALICE1
leftcert=aliceCert.pem
leftid=alice@strongswan.org
- leftfirewall=yes
right=PH_IP_SUN
rightid=@sun.strongswan.org
rightsubnet=10.2.0.0/16