blob: f9412611b4611654d9f2f615a49c800dd45bb162 (
plain)
1
2
3
4
5
6
7
8
9
10
|
The roadwarriors <b>carol</b> and <b>dave</b> set up an IPv6-in-IPv4 tunnel connection each
to gateway <b>moon</b>. The authentication is based on <b>X.509 certificates</b>.
Both <b>carol</b> and <b>dave</b> request a virtual IPv6 address from <b>moon</b> via
the IKEv1 mode config payload.
<p/>
Upon the successful establishment of the ESP tunnels, <b>leftfirewall=yes</b>
automatically inserts ip6tables-based firewall rules that let pass the tunneled traffic.
In order to test both tunnel and firewall, both <b>carol</b> and <b>dave</b> send
an IPv6 ICMP request to the client <b>alice</b> behind the gateway <b>moon</b>
using the ping6 command.
|