Discussion:
[strongSwan-dev] Route lookup for IKE packets
pothuganti sridhar
2016-07-20 06:43:36 UTC
Permalink
Hi,

In my deployment I have multiple WAN interfaces and they are managed by
policy based routing (using mwan3 module). In this deployment I will be
having multiple default gateways with different metrics.

With the above deployment strongswan is picking the routes very randomly,
when left=%any.

In the wiki I read that strongswan will parse the routing table itself to
send out the IKE packets. Here I have few questions.

Does strongswan IKE route lookup support policy based routing? And even, if
it does not support policy based routing, the default route with lower
metric is also not picked up properly.

Can anyone please help in debugging this issue. Any pointer like where the
IKE route lookup code OR file containing this logic would be helpful.

Thanks in advance.

Regards,
Sridhar
Tobias Brunner
2016-07-20 09:18:54 UTC
Permalink
Hi Sridhar,
Post by pothuganti sridhar
Does strongswan IKE route lookup support policy based routing?
Depends on what you mean by that exactly and how you use it.
Post by pothuganti sridhar
And even,
if it does not support policy based routing, the default route with
lower metric is also not picked up properly.
You didn't mention the version you are using, so you might want to have
a look at [1], which was fixed with 5.5.0.
Post by pothuganti sridhar
Can anyone please help in debugging this issue. Any pointer like where
the IKE route lookup code OR file containing this logic would be helpful.
See [2].

Regards,
Tobias

[1] https://wiki.strongswan.org/issues/1416
[2]
https://git.strongswan.org/?p=strongswan.git;a=blob;f=src/libcharon/plugins/kernel_netlink/kernel_netlink_net.c;h=93c2ccccb65f8e269eeb11630e11f288319ab645;hb=HEAD#l1686
Continue reading on narkive:
Search results for '[strongSwan-dev] Route lookup for IKE packets' (Questions and Answers)
5
replies
What is the best router to use for sunrocket voip?
started 2006-05-17 19:50:00 UTC
computer networking
Loading...