Answer the question
In order to leave comments, you need to log in
Site-to-Server IKEv2 IPsec?
Debian as vpn server. strongswan. Fixed white address.
Answer the question
In order to leave comments, you need to log in
IPSec does not require routing. The basis of IPSec is SPD (Security Policy Database) and SAD (Security Associations Database). SPD is built on the basis of policies that you set yourself (in Mikrotik) or build a shwan (in Linux). SAD is built automatically based on peer connections.
It is enough to describe the policies normally - and Mikrotik will figure out where to send packets to. The only point is that packets go through netfilter twice - in encrypted form and in decrypted form. And he must allow them in both cases.
There is a great picture showing the fullpackage path, including the places where they are encrypted/decrypted (xfrm encode/xfrm decode). I think it's worth looking at it - and it will immediately become clear why routing is not needed in IPSec.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question