[Openswan Users] openswan with my w2k not work for now.

Jacco de Leeuw jacco2 at dds.nl
Wed Oct 19 13:31:13 CEST 2005


faf wrote:

>> virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!192.168.1.0/24 

So the Windows road warrior is behind NAT, right?

> # if i put this don't work! My subnet is 192.168.1.0/24 not viceversa.
> 
>         virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.1.0/24
> conn roadwarrior
>    left=192.168.1.99
>    right=MyPublicIP2
>    rightca="C=IT, ST=ITALY, L=Rome, O=test, CN=test2, E=test at email.it"
>    rightsubnet=192.168.1.0/24
>    network=auto
>    auto=start
>    pfs=yes 

You cannot use the same subnet in left= and rightsubnet=.
You will have to change either one. Probably the easiest would
be to move your home LAN to 192.168.0.0/24 or something like that.
There is no way around this. This is how IP routing works.

If you want your Windows road warrior to obtain an IP address from
the VPN server's 192.168.1.0/24 subnet, then you might have got to
look into switching to L2TP/IPsec.

Jacco
-- 
Jacco de Leeuw                         mailto:jacco2 at dds.nl
Zaandam, The Netherlands           http://www.jacco2.dds.nl
                     Mosquitos suck


More information about the Users mailing list