<div dir="ltr"><span class="Apple-style-span" style="font-family: Helvetica; font-size: 12px; "><blockquote type="cite">Guys,<br><br>I'm peering with a Cisco device whose peering address is in the same subnet as their "right subnet". See the below config. On the Cisco side it's very easy to exclude an address from an encrypted subnet with an access list but there doesn't seem to be the same facilities in OpenSWAN. How do I go about excluding a specific /32 out of a right subnet?<br>
<br>conn telcentris-3<br></blockquote><blockquote type="cite"> auto = start<br></blockquote><blockquote type="cite"> ike = 3des-md5<br></blockquote><blockquote type="cite"> esp = 3des-md5<br>
</blockquote><blockquote type="cite"> ikelifetime = 86400s<br></blockquote><blockquote type="cite"> keylife = 3600s<br></blockquote><blockquote type="cite"> pfs = no<br></blockquote>
<blockquote type="cite"> leftsubnet = <a href="http://63.175.30.89/32">63.175.30.89/32</a><br></blockquote><blockquote type="cite"> right = <a href="http://208.90.33.250">208.90.33.250</a><br></blockquote>
<blockquote type="cite"> rightsubnet = <a href="http://208.90.33.0/24">208.90.33.0/24</a><br></blockquote><div><br></div><div>-Daniel</div><div><br></div></span></div>