L3VPN with strongswan IPSec and XFRM interface #17620
Unanswered
nitinraj92
asked this question in
Q&A
Replies: 1 comment
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi All,
I am trying to bringup a site-site L3VPN with strongswan ipsec using xfrm interface.
I am using the xfrm section in here as reference.
https://docs.strongswan.org/docs/5.9/features/routeBasedVpn.html
But instead of static routes, I want bgp routes installed via frr to have the xfrm interface( xfrm_wan0_17) as nexthop instead of physical interface(wan0).
Attaching the frr configuration as reference:
The routes currently installed using frr:
In these routes, if nexthop is present as xfrm_wan0_17, then the xfrm has policies installed to encrypt the traffic.
Let me know if we have some configuration if frr to modify the route nexthop interface. Let me know if there is some other way using PBR or route-maps I can achieve this.
Beta Was this translation helpful? Give feedback.
All reactions