IPSEC_EROUTE(8)					  IPSEC_EROUTE(8)


NAME
       ipsec eroute - manipulate IPSEC extended routing tables

SYNOPSIS
       ipsec eroute

       ipsec  eroute  --add  --eraf (inet | inet6) --src src/src-
       maskbits|srcmask --dst dst/dstmaskbits|dstmask <SAID>

       ipsec  eroute  --replace	 --eraf	 (inet	|  inet6)   --src
       src/srcmaskbits|srcmask	  --dst	  dst/dstmaskbits|dstmask
       <SAID>

       ipsec eroute --del --eraf (inet |  inet6)  --src	 src/src-
       maskbits|srcmask --dst dst/dstmaskbits|dstmask

       ipsec eroute --clear

       ipsec eroute --help

       ipsec eroute --version

       Where  <SAID> is --af (inet | inet6) --edst edst --spi spi
       --proto proto OR --said said  OR	 --said	 (%passthrough	|
       %passthrough4 | %passthrough6)

DESCRIPTION
       Eroute  manages	the  IPSEC extended routing tables, which
       control what  (if  any)	processing  is	applied	 to  non-
       encrypted  packets  arriving for IPSEC processing and for-
       warding.	 The form with no additional arguments lists  the
       contents of /proc/net/ipsec_eroute.  The --add form adds a
       table entry, the --replace form replaces	 a  table  entry,
       while  the  --del  form	deletes	 one.	The  --clear form
       deletes the entire table.

       A table entry consists of:

       +  source  and  destination  addresses,	with  masks,  for
	  selection of packets

       +  Security Association IDentifier, comprised of:

       +     address family (af),

       +     effective	 destination  (edst),  where  the  packet
	     should be forwarded after processing  (normally  the
	     other security gateway)

       +     Security	 Parameters   Index   (spi),   indicating
	     (together with the effective destination and  proto-
	     col)  which  Security  Association should be used to
	     process the packet




			   21 Jun 2000				1





IPSEC_EROUTE(8)					  IPSEC_EROUTE(8)


       +     protocol  (proto),	 indicating  (together	with  the
	     effective	destination  and  the security parameters
	     index) which Security Association should be used  to
	     process the packet

       +  OR

       +     SAID  (said),  indicating which Security Association
	     should be used to process the packet

       Addresses are written as IPv4 dotted quads or IPv6 coloned
       hex,  protocol  is one of "ah", "esp", "comp" or "tun" and
       SPIs are prefixed hexadecimal numbers where '.' represents
       IPv4 and ':' stands for IPv6.

       SAIDs are written as "protoafSPI@address".

       The   format   of   /proc/net/ipsec_eroute  is  listed  in
       ipsec_eroute(5).

EXAMPLES
       ipsec eroute --add --eraf inet --src 192.168.0.1/32 \
	  --dst 192.168.2.0/24 --af inet --edst 192.168.0.2 \
	  --spi 0x135 --proto tun

       sets up an eroute on a Security Gateway to protect traffic
       between	the  host  192.168.0.1 and the subnet 192.168.2.0
       with  24	 bits  of  subnet  mask	 via   Security	  Gateway
       192.168.0.2  using  the	Security Association with address
       192.168.0.2, Security Parameters Index 0x135 and	 protocol
       tun (50, IPPROTO_ESP).

       ipsec eroute --add --eraf inet6 --src 3049:1::1/128 \
	  --dst 3049:2::/64 --af inet6 --edst 3049:1::2 \
	  --spi 0x145 --proto tun

       sets up an eroute on a Security Gateway to protect traffic
       between the host 3049:1::1 and the subnet 3049:2:: with 64
       bits  of	 subnet mask via Security Gateway 3049:1::2 using
       the Security Association with address 3049:1::2,	 Security
       Parameters Index 0x145 and protocol tun (50, IPPROTO_ESP).

       ipsec eroute --replace --eraf inet --src company.com/24 \
	  --dst ftp.ngo.org/32 --said tun.135@gw.ngo.org

       replaces an eroute on a Security Gateway to protect  traf-
       fic  between the subnet company.com with 24 bits of subnet
       mask  and  the  host  ftp.ngo.org  via  Security	  Gateway
       gw.ngo.org  using  the  Security Association with Security
       Association ID tun0x135@gw.ngo.org

       ipsec eroute --del --eraf inet --src company.com/24 \
	  --dst www.ietf.org/32 --said %passthrough4




			   21 Jun 2000				2





IPSEC_EROUTE(8)					  IPSEC_EROUTE(8)


       deletes an eroute on a Security Gateway that allowed traf-
       fic  between the subnet company.com with 24 bits of subnet
       mask and the host  www.ietf.org	to  pass  in  the  clear,
       unprocessed.

FILES
       /proc/net/ipsec_eroute, /usr/local/bin/ipsec

SEE ALSO
       ipsec(8),  ipsec_manual(8),  ipsec_tncfg(8), ipsec_spi(8),
       ipsec_spigrp(8), ipsec_klipsdebug(8), ipsec_eroute(5)

HISTORY
       Written	  for	  the	  Linux	    FreeS/WAN	  project
       <http://www.freeswan.org/> by Richard Guy Briggs.










































			   21 Jun 2000				3


