[Openswan Users] multiple left/right subnet definition

Paul Wouters paul at xelerance.com
Wed Jul 26 17:26:25 CEST 2006


On Wed, 26 Jul 2006, Marco Berizzi wrote:

> Few days ago I have had a telephone call with a checkpoint
> admin. He told me that openswan doesn't support multiple
> left-right subnet definition: I must define for every single
> subnet a new tunnel section:
>
> conn first-subnet
>        left=ip_left
>        right=ip_right
>        leftsubnet=left_subnet
>        rightsubnet=first_right_subnet
>        leftid=left_id at domain
>        rightid=right_id at domain
>        auto=start
>
> conn second-subnet
>        left=ip_left
>        right=ip_right
>        leftsubnet=left_subnet
>        rightsubnet=second_right_subnet
>        leftid=left_id at domain
>        rightid=right_id at domain
>        auto=start

You can use this:

conn second-subnet
	rightsubnet=second_right_subnet
	also=base-conn
conn first-subnet
	rightsubnet=first_right_subnet
	also=base-conn
conn base-conn
        left=ip_left
        right=ip_right
        leftsubnet=left_subnet
        leftid=left_id at domain
        rightid=right_id at domain
        auto=start

Paul


More information about the Users mailing list