Demonstration #2 - VPN Tunnels Encapsulation routing tables before the tunnel is brought up [samba] etc $ netstat -rn -f encap Routing tables Encap: Source Port Destination Port Proto SA(Address/Proto/Type/Direction) [fw01] etc $ netstat -rn -f encap Routing tables Encap: Source Port Destination Port Proto SA(Address/Proto/Type/Direction) Encapsulation routing tables after the tunnel is brought up [samba] etc $ netstat -rn -f encap Routing tables Encap: Source Port Destination Port Proto SA(Address/Proto/Type/Direction) 10.1.1.1/32 0 10.1.1.254/32 0 0 10.1.1.1/50/use/in 192.168.1/24 0 10.1.1.254/32 0 0 10.1.1.1/50/use/in 10.1.1.254/32 0 10.1.1.1/32 0 0 10.1.1.1/50/require/out 10.1.1.254/32 0 192.168.1/24 0 0 10.1.1.1/50/require/out