From: Christopher Barry (cbarry_at_infiniconsys.com)
Date: Tue Jan 14 2003 - 07:05:27 CET
OK. I'll just ridicule your ASCII art then, and well, your grammer could
use a bit of cleaning up as well. :^}
Correct me if I've misinterpreted: You want all traffic from OfficeNet
tunneled to the Linux network - with a *single NIC* - and all traffic
back to - or even straight to OfficeNet from the Internet - to come from
the Linux box back through the tunnel to OfficeNet.
Q: Do you have a tunnel setup from .41 to the linux host already? Have
you tried setting the default route of your OfficeNet boxen to the IP
you've given to your ipsec0 interface? I believe it must be different
than .41, and I'm seriously wondering about the single NIC in the Linux
host.
Good Luck,
-C
On Sun, 2003-01-12 at 09:34, AltDNS.net Support wrote:
> I am trying to do a fairly unusual IPsec tunnel (or at least it must be
> because I can't find any example even closely similar) using FreeS/WAN
> 1.99 and a Cisco 3620 router. An illustration is as follows:
>
>
> ----------------
> -------------------------
> | OfficeNET | -------------------------------- | Linux
> FreeS/WAN box |
> | 10.69.141.41 | | Cisco 3620 | |
> |
> | | |--| Internal 10.69.141.40 |-- Internet --|
> 10.69.140.62/23 |
> | 10.69.141.59 | | External Some Other PublicIP | |One Nic
> Card in Machine|-- Internet
> ---------------- --------------------------------
> -------------------------
>
>
> Please note that the 10.69.XXX addresses were modified for this example.
> They are publicly routable IP addresses in real life but for security
> reasons I change them to be 10.XXXXXX addresses. Essentially what I want
> is to have the IP's on the OfficeNET to travel over the tunnel to the
> Linux FreeS/WAN box and then from the access the internet at large. I
> also want incoming IP traffic to the OfficeNET IP's to travel over the
> tunnel to the respective machine. Please note I can not change the IP
> addresses used and neither can I modify anything related to the network
> / routing on the far right side beyond the Linux box. I reason behind
> this network setup won't make since to most, but please just help figure
> out how to do with instead of ridiculing the setup.
>
>
>
>
>
>
> _______________________________________________
> Users mailing list
> Users_at_lists.freeswan.org
> http://lists.freeswan.org/mailman/listinfo/users
_______________________________________________
Users mailing list
Users_at_lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
This archive was generated by hypermail 2.1.5 : Wed Jan 15 2003 - 20:11:39 CET