[Openswan Users] Routing over NAT

Tobias Hadem th at lt-ec.de
Mon Oct 23 09:28:17 EDT 2006

Hello List,

i have a working tunnel to an IPCop-Gateway, which is also running Openswan, 
but in a rather old version Openswan 1.0.10rc2. This is unfortunately not 
changeable and i don't think it is a problem, as my problem occurs also on 
other gateways with OS 2.4.6.

The tunnel comes up as said but routing is not working correctly.


Directly connected IPCop:

Nat-ted Openswan:

I think that is ok, as the Nat-ted Openswan has to be %any in the config and 
it inserts it private ip-space-address in the description.

the openswan has two network-cards, one with the to the 
nat-router with, the other one with the into the lan.

the routing comes up as this:

Openswan: dev eth1  proto kernel  scope link  src dev eth0  proto kernel  scope link  src dev eth1
default via dev eth1

IPCop: via dev ipsec0 dev eth0  proto kernel  scope link  src
default via dev ppp0

i think there misses some "src"-options on the routing on openswan, 
but if i insert it manually after the tunnel has been established with "ip r 
d dev eth1 && ip r a dev eth1 proto kernel scope 
link src", no ping is possible.

To make it even more stranger, pinging and working from the IPCop-Side is 
working flawlessly, i can connect to any host inside the

anybody an idea? 

my ipsec.conf:

version 2.0     # conforms to second version of ipsec.conf specification

# basic configuration
config setup
        # Debug-logging controls:  "none" for (almost) none, "all" for lots.
# Add connections here

conn net-to-net

Thanks for any pointer,

Tobias Hadem                            th at lt-ec.de
LT-ec service & solutions               http://www.lt-ec.de
fon +49 (0)911 97791355                 fax +49 (0)911 97791358
Benno-Strauss-Strasse 5                 D-90763 Fürth/Bay.

new thinking for a new era in Fürth - Berlin - Seattle
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 191 bytes
Desc: not available
Url : http://lists.openswan.org/pipermail/users/attachments/20061023/5d620141/attachment.bin 

More information about the Users mailing list