Hi Florin, > What am I missing?
Read up on IPsec policies (what you call "magic" routing) e.g. on our wiki [1], [2] and [3]. Regards, Tobias [1] https://wiki.strongswan.org/projects/strongswan/wiki/IntroductionTostrongSwan [2] https://wiki.strongswan.org/projects/strongswan/wiki/SubnetsBehindMoreThanTwoGateways [3] https://wiki.strongswan.org/projects/strongswan/wiki/RouteBasedVPN
