[Openswan Users] leftsubnet 0.0.0.0/0
paul at xelerance.com
Thu Sep 1 12:33:25 EDT 2011
On Thu, 1 Sep 2011, James Taylor wrote:
> I am trying to implement the following configuration:
> 000 "LS-NET-PSK":
> unrouted; eroute owner: #0
> ... which means that my VPN server (188.8.131.52) is configured to
> accept connections from any client and that the left private subnet is
> the whole Internet.
> I want all client machines, once connected, to send all their traffic
> through VPN server.
> Configuration file looks as follows:
> conn LS-NET-PSK
Does this connection even load? how should this end know if it is "left" or "right"?
You say later these servers are on public ip. If that is static, just configure
that into you left/right options.
> Now I am configuring another server as a client to pass all the
> traffic through the VPN server.
> My second server has real Internet IP 184.108.40.206. It is not behind NAT.
> Second server configuration file below:
> conn LS-NET-PSK-CLIENT
> Now if I establish the connection, my second server starts sending ESP
> packets through the VPN server 220.127.116.11
> I can see it with tcpdump.
> The problem is that target server, which has the IP address
> 18.104.22.168 does not route response through the VPN server
> Instead target server tries to communicate directly to the 22.214.171.124
> over unencrypted channel
So you have chained them?
I am not sure what you are trying to do here.
clients--->vpn1---->vpn2----> internet ?
defaultroute/0.0.0.0 --> 0.0.0.0/0.0.0.0 -> 0.0.0.0/.0.0.0.0 -> internet ?
vpn1 cannot be both 0.0.0.0/0 for one side and the other side. How would it
know where to send a packet for 126.96.36.199 to?
More information about the Users