echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -A FORWARD -i eth1 -j ACCEPT
ip link add ipsec0 type xfrm dev eth0 if_id 42
ip link set ipsec0 up
iptables -A FORWARD -i ipsec0 -j ACCEPT
ip xfrm policy
VIP=$(swanctl -l -i vpn -P | grep local-vips -A1 | tail -1 | tr -d ' ')
ip addr add $VIP/32 dev ipsec0
ip ro add 8.8.8.8 dev ipsec0 src $VIP
iptables -t nat -A POSTROUTING -o ipsec0 -j MASQUERADE
RIP=$(swanctl -l -i vpn -P | grep remote-host | egrep -o '[0-9.]+')
ip ro add $RIP dev eth0 src 192.168.1.2 via 192.168.1.1
ip ro add default dev ipsec0 src $VIP