Strongswan

Strongswan can be considered as a standard ipsec service for linux.

Details for the ipsec scenario/design and strongswan can be found here

acx1100 ipsec common and policy configuration and more details can be found here

acx1100 ipsec tunnel to Strongswan

Strongswan (NEO4) ipsec tunnel to acx1100

NEO4 podman network, container and iptables rule related to podman nat and ipsec policy.

This is only informative configuration .. details are out of scope here

Strongswan configuration

Validation

NEO4 Strongswan / podman container

acx1100 / LRC

Wireshark – network switch between acx1100 and NEO4

NEO4(podman container) to acx1100(LRC)

acx1100(LRC) to NEO4(podman container)

Final check .. we should NOT see any not encrypted icmp

Вашият коментар