_updown_espmark is invoked by pluto when it has brought up a new connection. This script is used to insert the appropriate routing and iptables firewall entries for IPsec operation. The incoming ESP traffic must be marked by a static rule in the mangle table. The default value for the mark is 50. The interface to the script is documented in the pluto man page.

RELATED TO _updown_espmark…

ipsec(8), ipsec_pluto(8).


Man page written for the Linux strongSwan project <> by Andreas Steffen. Original program written by Henry Spencer.