as netkey-vti-01 but now the IPsec SA is a host-to-host tunnel This test sets up a "routed vpn" with a 192.1.2.45/32 <-> 192.1.2.23/32 policy It is to confirm VTI works with host routes (reference with net-to-net) This testcase works on 4.0.4 (and prob 3.x as well) East shows hits in XfrmInTmplMismatch because it received plaintext packets during the first part of the test when road sends packets that are supposed to be encrypted in the clear. East's xfrm stack drops those packets.