[strongSwan] tcpdump of ping over ipsec transport

2020-03-23 Thread tal anker
Hi, I have two machines, with ipsec configured to encrypt every packet going between the two (transport esp), with pre-shared key. When I ping machine A from machine B, and I do 'tcpdump -i esp ‘ I dont see ESP packets going bi directional but rather only the replies from B to A. Is this the

Re: [strongSwan] Split Tunnel via Strongswan Networkmanager

2020-03-23 Thread Tobias Brunner
Hi, > Is it possible to setup a split tunnel while using Strongswan via the > NetworkManger plug-in (charon-nm)? See my response to a similar question at [1]. Regards, Tobias [1] https://superuser.com/a/1535002/98749

Re: [strongSwan] tcpdump of ping over ipsec transport

2020-03-23 Thread Tobias Brunner
Hi, > When I ping machine A from machine B, and I do 'tcpdump -i esp ‘ >  I dont see ESP packets going bi directional but rather only the replies > from B to A. Is this the expected behavior of tcpdump in that case? No. While you'll only see inbound plaintext packets (see [1]), you should see