Re: [Users] A simple network-to-network VPN

From: Whit Blauvelt (whit_at_transpect.com)
Date: Tue Aug 27 2002 - 19:41:24 CEST


On Tue, Aug 27, 2002 at 05:27:39PM +0200, Nejc Skoberne wrote:
> Hi.
>
> I have a problem setting up a net-to-net VPN tunnel. I read
> documentation which is included in the latest FreeS/WAN source
> distribution. I have set up config files as shown in docs, but with no
> luck. I have two Linux Slackware 8.0 and 8.1 machines, running 2.4.18
> and 2.4.19 kernels, FreeS/WAN 1.98b with x509 patch.
>
> The tunnel is established, but I cannot ping from one network to another.
> I cannot ping even from GATEWAY 1 to GATEWAY 2 (local IP addresses) or
> vice versa, but I can ping from GATEWAY 1 to GATEWAY 2 or vice-versa
> Internet addresses. So IPSec tunnel works fine.
> Firewalling is not a problem since I disabled it during testing.

Do the initial negotiations to bring up the tunnel report success?

Are you trying to ping from the gateways, or from and two machines behind
the gateways? To ping from and to the gateways requires either additional
tunnels for that purpose, or iproute2 routing with the gateways' internal
net IPs specified as the src address for ipsec routing (if you have the
iproute2 tools installed, my note to the list yesterday on modifying the
_updown script might help you).

> I was also trying to reach www.freeswan.org page, but it's been down
> for 2 days not. So I couldn't help with it.

www.freeswan.ca is not a mirror of the org site, but you might find it
useful.

Whit
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users



This archive was generated by hypermail 2.1.4 : Tue Aug 27 2002 - 22:20:22 CEST