[Openswan Users] OpenSWAN leftsubnets / Cisco ASA problem

Madden, Joe Joe.Madden at mottmac.com
Tue Jul 15 10:00:22 EDT 2014


Hi All,

We have a IPsec VPN up using OpenSWAN using a Cisco ASA 5500. The VPN is working and connection. The OpenSWAN configuration looks like this:

conn ntisdevelopmentwmrcc
        authby=         secret
        auto=         start
        type=         tunnel
        #RRT
        left=          LocalIP
        leftsubnets= { 10.54.2.123/32, 10.56.2.123/32}
        #SAA
        right=          ExternalIP
        rightsubnet=          172.17.199.103/32
        keyexchange=     ike
        ike=     aes256-sha2_256;modp2048!
        sha2_truncbug=     yes
        phase2=     esp
        phase2alg=     aes256-sha1!
        salifetime=     3600s

The Cisco ASA is configured to connect to this system using the same right/left subnets, however on connection only the 10.54.2.123/32 ipsec tunnel comes up - The 10.56.2.123/32 stays down and does not attempt to connect.

Does anyone have any ideas?

Thanks

Joe
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openswan.org/pipermail/users/attachments/20140715/b71f82fc/attachment.html>


More information about the Users mailing list