yes
I'm using Patricks conntrack zones. And Patrick helped me with a input chain
in the nat table. The other cases with e.g. a ip clash between local and
remote net already work.
So only the case with two remotes and same ips is missing.
I planned to avoid looking at the remote gateway ip (to even allow two
different remote gateways hiding natted behind the same ip) but that would be
a good fallback solution if my other ideas don't work out.
Didn't know that, very good.
I just contacted the strongswan maintainers about reqids and marks. Let's see
if this works out...
Kind regards,
Gerd
--
Address (better: trap) for people I really don't want to get mail from:
jonas@cactusamerica.com
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html