Subnet multiple in IPSEC

Una volta per tutte, NO, non si può fare usando OpenSwan o FreeSwan

conn alfa
        left=1.2.3.4
        leftsubnet=192.168.1.0/24
        leftnexthop=%defaultroute
        right=5.6.7.8
        rightsubnet=192.168.0.0/24, 172.16.0.0/16
        rightnexthop=%defaultroute
        auto=add

Workaround

Create N connessioni identiche, una per ogni subnet che volete pubblicare

conn alfa
left=1.2.3.4
leftsubnet=192.168.1.0/24
leftnexthop=%defaultroute
right=5.6.7.8
rightsubnet=192.168.0.0/24
rightnexthop=%defaultroute
auto=add

conn beta
left=1.2.3.4
leftsubnet=192.168.1.0/24
leftnexthop=%defaultroute
right=5.6.7.8
rightsubnet=172.16.0.0/16
rightnexthop=%defaultroute
auto=add

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*