| 1234567891011121314151617 | A connection between the subnets behind the gateways <b>moon</b> and <b>sun</b>is set up using XFRM interfaces.<p/>The gateways use <b>route-based forwarding</b> with <b>XFRM interfaces</b>, withfirewall rules to allow traffic to pass. The IPsec traffic selector used is0.0.0.0/0, however, specific routing is achieved with routes on the XFRMinterfaces. The IKE daemon does not install routes for CHILD_SAs with outboundinterface ID, so static routes are installed for the target subnets.<p/>Both gateways use separate interfaces for in- and outbound traffic (which iscompletely optional and mainly for testing purposes, a single interface willusually be enough). Gateway <b>moon</b> creates them before initiating theconnection, while gateway <b>sun</b> dynamically creates the interfaces viaupdown script using the passed unique generated interface IDs.<p/>Client <b>alice</b> behind gateway <b>moon</b> pings client <b>bob</b> locatedbehind gateway <b>sun</b>.
 |