[Openswan Users] Two tunnels and the same remote subnet
diego at woitasen.com.ar
Mon Sep 5 17:00:41 EDT 2011
On Fri, Sep 2, 2011 at 7:49 PM, Diego Woitasen <diego at woitasen.com.ar> wrote:
> We've been using for years the following escenario.
> - Two Openswan VPN concentrators.
> - 260 Openswan endpoints.
> - tunnel, subnet-to-subnet.
> - The same subnet behind the concentrators. 10.0.0.0/8
> - Two subnets behind the endpoints: for example: 10.12.160.0/24 and
> - Two tunnels simultaneously from every endpoint to every concentrator.
> - A fragment to the configuration of every endpoint is:
> conn gw1
> conn gw2
> This doesn't work anymore with Openswan 2.6.35 using KLIPS or NETKEY
> (Debian Squeeze, kernel 2.6.32). Openswan complains with "cannot route
> -- route already in use for...". We keep the tunnels running all the
> time to switch from one tunnel to another in case of failure and
> sometimes we send traffic via one tunnel or another. The switch is
> done with source nat (using Iptables NETMAP).
> Why this doesn't work anymore? Is this intentional?
> Diego Woitasen
I reported a bug for this because works with Strongswan so is a
More information about the Users