Skip to main content
Establish the tunnel from the initiator and prove that protected traffic crosses the CHILD_SA.

Initiate IKEv2

Run on the initiator:
The output reports an established IKE_SA and an installed net CHILD_SA. The responder log reports successful authentication for both peer identities.
Run on the responder:

Prove protected traffic

From a host in the initiator protected subnet, send traffic to a host in the responder protected subnet:
Replace <RESPONDER_PROTECTED_HOST> with a reachable address covered by <RESPONDER_SUBNET>.
The ping receives three replies. Run sudo ip -s xfrm state on each gateway and confirm that the ESP packet counters increase.

Repeat after restart

Restart strongSwan on both gateways:
Initiate the tunnel again from the initiator, then repeat the ping and XFRM checks.
The second process set loads the token key, establishes a new CHILD_SA, and carries protected traffic.