<p class="MsoPlainText">> Hi</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've installed Openswan on Ubuntu 10.04.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've one network interface: eth0 = 10.202.x.x.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've created another Virtual Network Interface:
eth0:0 = 192.168.y.y.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've Elastic IP: 50.17.z.z.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've done natting with following commands:</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> then used more commands like this:</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> iptables --flush</p>
<p class="MsoPlainText">> iptables -t nat --flush</p>
<p class="MsoPlainText">> iptables --delete-chain</p>
<p class="MsoPlainText">> iptables -t nat --delete-chain</p>
<p class="MsoPlainText">> iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A </p>
<p class="MsoPlainText">> FORWARD -i eth0:0 -j ACCEPT</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> I've configured my connection as under:</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> conn TEST</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> type=tunnel</p>
<p class="MsoPlainText">> authby=secret</p>
<p class="MsoPlainText">> ike=3des-md5-modp1024</p>
<p class="MsoPlainText">> ikelifetime=86400s</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> phase2=esp</p>
<p class="MsoPlainText">> phase2alg=3des-md5;modp1024</p>
<p class="MsoPlainText">> lifetime=28800s</p>
<p class="MsoPlainText">> forceencaps=yes</p>
<p class="MsoPlainText">> pfs=no</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> left=10.202.x.x</p>
<p class="MsoPlainText">> leftid=50.17.z.z</p>
<p class="MsoPlainText">> leftnexthop=%defaultroute</p>
<p class="MsoPlainText">> leftsubnet=192.168.y.y/32</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> right=202.125.a.a</p>
<p class="MsoPlainText">> rightid=202.125.a.a</p>
<p class="MsoPlainText">> rightsubnet=172.16.b.b/32</p>
<p class="MsoPlainText">> rightnexthop=%defaultroute</p>
<p class="MsoPlainText">> dpdaction=restart</p>
<p class="MsoPlainText">> dpddelay=30</p>
<p class="MsoPlainText">> dpdtimeout=45</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> auto=add</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> now when I try to start a tunnel with command: ipsec
auto --up TEST, </p>
<p class="MsoPlainText">> tunnel comes up successfully, but when i ping
172.16.b.b. I don't get </p>
<p class="MsoPlainText">> any reply.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> All ports opened for all IP Addresses, firewall
allow all. Still no </p>
<p class="MsoPlainText">> success.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> My routing table is as under:</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Destination Gateway Genmask Flags Metric Ref Use
Iface</p>
<p class="MsoPlainText">> 192.168.222.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0</p>
<p class="MsoPlainText">> 10.202.70.0 0.0.0.0 255.255.254.0 U 0 0 0 eth0</p>
<p class="MsoPlainText">> 0.0.0.0 10.202.70.1 0.0.0.0 UG 100 0 0 eth0</p>
<p class="MsoPlainText">> 0.0.0.0 10.202.70.1 0.0.0.0 UG 100 0 0 eth0</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> iptables -L show:</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Chain INPUT (policy ACCEPT)</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> target
prot opt source
destination</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Chain FORWARD (policy ACCEPT)</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> target
prot opt source
destination</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> ACCEPT
all -- anywhere anywhere</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Chain OUTPUT (policy ACCEPT)</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> target
prot opt source
destination</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> kindly guide me what i am missing, tunnel is being
established </p>
<p class="MsoPlainText">> successfully but cannot ping other side, and they
cannot ping me?</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> A I missing any route? Kindly do let me know what
route to add, if </p>
<p class="MsoPlainText">> missed any?</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Thank you very much. Waiting for any answer. Thank
you guys.</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Regards</p>
<p class="MsoPlainText">> </p>
<p class="MsoPlainText">> Imran</p>