<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.E-MailFormatvorlage17
{mso-style-type:personal-compose;
font-family:"Arial","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span lang="DE">Hi,<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="DE"><o:p> </o:p></span></p>
<p class="MsoNormal">after adding “leftsourceip=54.93.190.54” to my /etc/ipsec.conf, I have now an advanced routing table<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">root@ip-172-31-6-249:~# netstat -rn<o:p></o:p></p>
<p class="MsoNormal">Kernel IP routing table<o:p></o:p></p>
<p class="MsoNormal">Destination Gateway Genmask Flags MSS Window irtt Iface<o:p></o:p></p>
<p class="MsoNormal">0.0.0.0 0.0.0.0 255.255.255.255 UH 0 0 0 lo<o:p></o:p></p>
<p class="MsoNormal">0.0.0.0 172.31.0.1 0.0.0.0 UG 0 0 0 eth0<o:p></o:p></p>
<p class="MsoNormal">10.161.62.59 0.0.0.0 255.255.255.255 UH 0 0 0 eth0<o:p></o:p></p>
<p class="MsoNormal">172.31.0.0 0.0.0.0 255.255.240.0 U 0 0 0 eth0<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">10.161.62.59 is my client and this line was added now<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Unfortunately the 2 issues are still there:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">000 "RWConn"[2]: 172.31.15.0/24===172.31.6.249<172.31.6.249>[@172.31.6.249,+XS+S=C]:17/1701...212.64.xxx.xxx[@,+MC+XC+S=C]:17/0===10.161.62.59/32; erouted; eroute owner: #2<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Ping Packets from server 172.31.15.27 are reaching the Openswan (172.31.6.249) but are not sent into the tunnel<o:p></o:p></p>
<p class="MsoNormal">Ping Packets from client 10.161.62.59 are tunneled thru the Internet-VPN to the OpenSwan (172.31.6.249) but are not forwarded to the server 172.31.15.27<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">openswan and the server are located at AWS. I disabled the “source/dest checking” for the OpenSwan and the Server and did the following settings on the OpenSwan:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">sysctl -p<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.ip_forward = 1<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.all.accept_redirects = 0<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.all.send_redirects = 0<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.default.rp_filter = 0<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.default.accept_source_route = 1<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.all.accept_source_route = 1<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.conf.default.send_redirects = 0<o:p></o:p></p>
<p class="MsoNormal">net.ipv4.icmp_ignore_bogus_error_responses = 1<o:p></o:p></p>
<p class="MsoNormal">root@ip-172-31-6-249:~#<o:p></o:p></p>
</div>
</body>
</html>