ROUTEa for
'---------------------------------------------------------------------------
root@UBNT:~# ip -4 ru
0: from all lookup local
210: from all fwmark 0x1 lookup 210
32766: from all lookup main
32767: from all lookup default
'---------------------------------------------------------------------------
root@UBNT:~# cat /etc/iproute2/rt_tables
reserved values
128 prelocal
255 local
254 main
253 default
0 unspec
local
#1 inr.ruhep
'---------------------------------------------------------------------------
root@UBNT:~# cat /etc/ipsec.conf
ipsec.conf - strongSwan IPsec configuration file
config setup
conn %default
left=%defaultroute
leftsubnet=192.168.1.0/27
ikelifetime=60m
keylife=20m
rekeymargin=3m
keyingtries=1
keyexchange=ikev2
ike=****
auto=start
conn b
leftcert=ubnt1.cer
leftid=ubnt@domain.ddnss.de
leftfirewall=yes
right=domain.ddnss.de
rightid=domain.ddnss.de
rightsubnet=192.168.100.0/28
mark=1
'---------------------------------------------------------------------------
root@UBNT:~# ll /etc/ipsec.d/*
/etc/ipsec.d/aacerts:
drwxr-xr-x 2 root root 160 Nov 17 23:31 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
/etc/ipsec.d/acerts:
drwxr-xr-x 2 root root 160 Nov 17 23:31 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
/etc/ipsec.d/cacerts:
drwxr-xr-x 2 root root 296 Jan 20 13:57 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
-rw-r--r-- 1 root root 761 Aug 28 22:49 ca.cer
-rw-r--r-- 1 root root 774 Jan 19 20:34 linkca.cer
/etc/ipsec.d/certs:
drwxr-xr-x 2 root root 304 Jan 20 13:58 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
-rw-r--r-- 1 root root 766 Sep 9 21:42 ubnt.cer
-rw-r--r-- 1 root root 874 Jan 19 20:34 ubnt1.cer
/etc/ipsec.d/crls:
drwxr-xr-x 2 root root 160 Nov 17 23:31 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
/etc/ipsec.d/ocspcerts:
drwxr-xr-x 2 root root 160 Nov 17 23:31 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
/etc/ipsec.d/private:
drwxr-xr-x 2 root root 312 Jan 20 13:58 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
-rw-r--r-- 1 root root 1192 Jan 19 20:33 domain_ubntkey.der
-rw-r--r-- 1 root root 1193 Sep 9 22:23 ubntkey.der
/etc/ipsec.d/reqs:
drwxr-xr-x 2 root root 160 Nov 17 23:31 ./
drwxr-xr-x 10 root root 680 Nov 27 19:34 ../
'---------------------------------------------------------------------------
root@UBNT:~# cat /etc/config/firewall
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option drop_invalid '1'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
option enabled '0'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config forwarding
option dest 'wan'
option src 'lan'
root@UBNT:~#
Thank you