IPsec / IKEv2 Interop
Ze as an IKE initiator against real strongSwan/charon, with FRR redistribute scenarios over the resulting tunnel.
A peer-isolated Docker lab runs Ze as an IKEv2 initiator against strongSwan/charon as the responder, with FRR available as a BGP peer for redistribute scenarios over the established tunnel.
The native Go runner owns Docker lifecycle, scenario discovery, and protocol checks. The checked-in lab tree supplies container definitions, PKI material, and scenario fixtures.
# all scenarios $ ./le integration interop-ipsec # a single named scenario $ IPSEC_INTEROP_SCENARIO=name ./le integration interop-ipsec
Docker with privileged containers (IKE/IPsec needs kernel XFRM access).