Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Ccf Cloud
Hi Martin, Thanks for the quick reply. On Thu, Oct 24, 2013 at 12:45 PM, Martin Willi mar...@strongswan.orgwrote: Hi, I want to route all the traffic originating from android device to be tunneled through the gateway using the tun0 interface. The Android App does no narrowing itself,

Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Ccf Cloud
On Fri, Oct 25, 2013 at 11:27 AM, Ccf Cloud ccfcl...@gmail.com wrote: Hi Martin, Thanks for the quick reply. On Thu, Oct 24, 2013 at 12:45 PM, Martin Willi mar...@strongswan.orgwrote: Hi, I want to route all the traffic originating from android device to be tunneled through the

Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Martin Willi
Hi, With this when I run tcpdum on both tun0 and wlan0, I see all the ESP packets going through Wlan0 and not tun0. I'd say that's the idea; plain packets go over the virtual adapter, encrypted ones over your physical connection. What am I missing here? Why is the route added as 0.0.0.0/1?

Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Ccf Cloud
Hi Martin, Okay so that explains the presence of the routes. But what about all the ESP packets going through wlan0 interface. Shouldn't they go through the tun0? On Fri, Oct 25, 2013 at 1:09 PM, Martin Willi mar...@strongswan.org wrote: Hi, With this when I run tcpdum on both tun0 and

Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Mihai Maties
On Fri, Oct 25, 2013 at 8:58 AM, Ccf Cloud ccfcl...@gmail.com wrote: Okay so that explains the presence of the routes. But what about all the ESP packets going through wlan0 interface. Shouldn't they go through the tun0? Martin already mentioned that this is the correct behavior: With this

Re: [strongSwan] trouble with the traffic selector

2013-10-25 Thread Ccf Cloud
Hi, Okay that makes sense now. I've another question. Once the tunnel gets established between the Gateway and the Android device, I want to allow the internet access for the android device through the gateway. Currently after the tunnel establishment, my android device is able to reach the

Re: [strongSwan] trouble with the traffic selector

2013-10-24 Thread Martin Willi
Hi, I want to route all the traffic originating from android device to be tunneled through the gateway using the tun0 interface. The Android App does no narrowing itself, that happens on the responder only. To tunnel all traffic from the Android device, set leftsubnet=0.0.0.0/0 on the