My Strongswan :

Local IP: 172.30.0.37
Elastic IP: 19.215.188.2
OS: Ubuntu
My WAN:
– Customer grade broadband Internet
– Public IP:28.77.250.17 – connect to my fiber optics
– Local gateway IP: 192.168.1.100
– we need to setup porftforwarding : UDP port 4500,500, to our router interface 192.16.1.108
My Cisco:
– Cisco 1841
– fa0/1 : 192.168.1.108  – connect to My WAN router local interface
– fa0/0: 172.16.8.254 – connect to my local switch / pc

My Strongswan config:

/etc/ipsec.conf

/etc/ipsec.secrets

 

This is my Cisco configuration:

Note:

In this setup, we can decide where is internet break out for our client ,
– via our remote site (strongswan)    ->  you must have the line in #note100       and remove line #note101
– via our local internet provide    -> keep the line #note101