<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Strongswan: Where does it set the routes?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">where can I see and modify the routes (in my case ipv6 routes) which are automatically set by strongswan?  (preferably in the shell)</p>
<p dir="auto">Thanks a lot!</p>
<p dir="auto">Cheers,<br />
4920441</p>
]]></description><link>https://forum.netgate.com/topic/106459/strongswan-where-does-it-set-the-routes</link><generator>RSS for Node</generator><lastBuildDate>Wed, 11 Mar 2026 09:51:04 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/106459.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 10 Oct 2016 17:53:45 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Strongswan: Where does it set the routes? on Thu, 13 Oct 2016 05:20:32 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">thanks for that hint.</p>
<p dir="auto">Can I change them somehow?</p>
<p dir="auto">I think that solves my problem described here….</p>
<p dir="auto"><a href="https://forum.pfsense.org/index.php?topic=119347.0" target="_blank" rel="noopener noreferrer nofollow ugc">https://forum.pfsense.org/index.php?topic=119347.0</a></p>
<p dir="auto">But I cannot simply change the SADs the ::0/0 part because the it should be some kind of policy based routing.</p>
<p dir="auto">I got a LAN with (lets say) 2001:fat:babe::/64<br />
and a DMZ with (lets say) 2a01:face::/56 which "comes" with the IPSec Tunnel.</p>
<p dir="auto">Everything from the DMZ schould be routed via the IPSec Tunnel, thats why the SPDs are ::0/0 -&gt; 2a01:face::/56  and 2a01:face::/56 -&gt;  ::0/0.</p>
<p dir="auto">But If a packet arrives from the local Lan 2001:fat:babe::/64  it is not directly routed in the IPSec 2a01:face::/56 Network and never arrives there.</p>
<p dir="auto">I put up some static routes in the pfsense gui but that does not work - only in the moment the IPSec tunnel is stopped - then the local DMZ (without Uplink and set routes from Strongswan) it works…. but that does not really help:-)</p>
<p dir="auto">Would be nice if you got some further advice</p>
<p dir="auto">Thanks a lot!</p>
<p dir="auto">Cheers,</p>
<p dir="auto">4920441</p>
]]></description><link>https://forum.netgate.com/post/654741</link><guid isPermaLink="true">https://forum.netgate.com/post/654741</guid><dc:creator><![CDATA[4920441]]></dc:creator><pubDate>Thu, 13 Oct 2016 05:20:32 GMT</pubDate></item><item><title><![CDATA[Reply to Strongswan: Where does it set the routes? on Mon, 10 Oct 2016 20:29:21 GMT]]></title><description><![CDATA[<p dir="auto">strongSwan doesn't actually use "routes" on FreeBSD, there are SPD entries that define which traffic combinations are interesting for IPsec and the kernel grabs them directly.</p>
<p dir="auto">If you want to see these entries from the shell, look at "setkey -DP"</p>
<p dir="auto">From the GUI They are under Status &gt; IPsec on the SPD tab</p>
]]></description><link>https://forum.netgate.com/post/654371</link><guid isPermaLink="true">https://forum.netgate.com/post/654371</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Mon, 10 Oct 2016 20:29:21 GMT</pubDate></item></channel></rss>