[Openswan Users] catchall connection

Jason Sigurdur jason.sigurdur at ASPENVIEW.ORG
Thu Jun 16 11:40:59 CEST 2005


Hi I have the following setup:

 

10 sites fully meshed using openswan I need to route any traffic that is not
destined to a 10/8 network to be sent to 10.1.0.1 (172.16.0.1) where it will
be nated out.

 

 

 

Ipsec.conf example  on 10.16.0.1 '172.16.31.16'

 

Left 172.16.31.1

Leftsubnet 10.1.0.0/8

Right 172.16.31.16

Rightsubnet 10.16.0.0/8

 

Left 172.16.31.2

Leftsubnet 10.2.0.0/8

Right 172.16.31.2

Rightsubnet 10.16.0.0/8

 

Could I add this on all vpn systems 'using their assigned right and
rightsubnet.

 

Left 172.16.31.1

Leftsubnet 0.0.0.0 << would this allow for any packed with a non 10/8 be
sent to 172.16.31.1 '10.1.0.1' ?

Right 172.16.31.16

Rightsubnet 10.16.0.0/8

 

 

How would this work on the 10.1.0.1 system  would it use the first or the
above connection ?

 

Thx jason

 

 

 

 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20050616/680cb298/attachment.htm


More information about the Users mailing list