Re: [strongSwan] Access to local subnet when tunnel up

2009-11-15 Thread Martin Willi
Hi, > Introduce another route table (e.g. 219), which has priority over the > table 220, and has the route for the local network. To setup that you > need to look at the "ip rule" commands. I agree, this is probably the best solution. This routing policy database is very powerful, just "man ip"

Re: [strongSwan] Access to local subnet when tunnel up

2009-11-15 Thread Dimitrios Siganos
I can think of another option might might make the whole setup cleaner. Introduce another route table (e.g. 219), which has priority over the table 220, and has the route for the local network. To setup that you need to look at the "ip rule" commands. This way, no matter what charon/pluto do, t

Re: [strongSwan] Access to local subnet when tunnel up

2009-11-15 Thread Graham Hudspith
Andreas, Thanks for the reply. I'm afraid I'm not an expert on xfrm policies. Could you please give an example of the add command you had in mind? However, as Daniel states, your diagnosis does not sound quite right to me. Just going via the ip routing tables (and ignoring xfrm), it seems that s