[Openswan Users] OpenSWAN to Cisco Concentrator 3005 ??

Svavar Örn Eysteinsson svavar at atom01.is
Thu Dec 15 09:10:16 CET 2005

Hi All.

I recently installed a Fedora Core 4 linux test machine.
My main goal was to configure a IPSec tunnel with OpenSwan to a remote 
connected to Cisco Concentrator 3005 box.

Well, I have the connection working but the problem is that I can only
communicate to 1 IPaddress. That is the LAN address of the remote VPNServer.

This is my setup.

(A) - Left Side (Cisco Concentrator 3005 / IP Address:

left= (Public IPaddress)
leftnexthop= (Router)
leftsubnet= (Local LAN)

(B) - Right Side (OpenSwan / IP Address :
right= (Public IPaddress)
rightnexthop= (Router)
rightsubnet= (Local LAN)

And here is my connection.conf profile :

conn cisco

And this is my ipsec.conf :

version 2.0
config setup

My OpenSwan box is configured with 2 interfaces. The Eth0(public) connected
straight to the internet and the Eth1(LAN) connected to a switch on the network.
The Default Gateway on the machine is trough eth0 interface.
So my routing table looks like :

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use 
Iface     *      U     0      0        0 eth0     *        U     0      0        0 eth1   UG    0      0        0 eth0     *          U     0      0        0 eth1
default         UG    0      0        0 eth0

So the problem is, I go to my workstation(running Windows XP) and add a 
static route with the following command :

route add mask metric 1
I can sucessfully ping from my Windows XP workstation, but
when I whant to ping for an example which i know exists and
serves as a server on the remote lan, I don't get any answers.

This problem is vice versa. That means, if I go to the Web Interface on the
Concentrator Box and ping it is successful. But if i ping serves as a server on the Remote LAN) I don't get any 

Any idea good people? Anyone out there sucessfully configured IPSec tunnel
with Free/OpenSWAN and Concentrator box?

Does it matter wich is Left/Right? e.g. OpenSWAN is Left and Cisco 
Right? Or Vice/versa

I'm really stuck.
Best regards,

Svavar Orn
svavar at atom01.is
Reykjavik - Iceland


More information about the Users mailing list