#6 Overlapping Subnets

setkey
closed
5
2005-02-10
2004-06-23
Anonymous
No

Hi
I have a Company with a star-net-vpn.
Headquarter Local Subnet: 172.21.21.0/24
Branch-Offices Local Subnets 172.21.1.0/24,
172.21.2.0/24 ...
Using FreeSwan is was possible to define Connections
with overlapping Subnets like that:
leftsubnet: 172.21.0.0/18
rightsubnet: 172.21.1.0/24

With racoon i defined the SPDs:
spdadd 172.21.1.0/24 172.21.0.0/18 any -P out ipsec
esp/tunnel/194.208.xxx.xxx-
194.208.xxx.xxx/require ;
spdadd 172.21.0.0/18 172.21.1.0/24 any -P in ipsec

Now, the Gateway 172.21.1.1 is unreachable from the
Local Net. I think its because the packets for
172.21.1.0/24 are going out through the Tunnel to the
Headquarter an not to the LAN.

Is ther any workaround ?
Thanks in advance

Ludwig

l.hinteregger@luis.at

Discussion

  • Aidas Kasparas

    Aidas Kasparas - 2004-06-25

    Logged In: YES
    user_id=39627

    Insert two rules:
    spdadd 172.17.1.0/24 172.17.1.0 any -P in none;
    spdadd 172.17.1.0/24 172.17.1.0 any -P out none;

    These should be inserted *BEFORE* your rules or with higher
    priority to take effect.

     
  • Aidas Kasparas

    Aidas Kasparas - 2005-02-10
    • assigned_to: nobody --> monas
    • status: open --> closed
     

Log in to post a comment.

Get latest updates about Open Source Projects, Conferences and News.

Sign up for the SourceForge newsletter:

JavaScript is required for this form.





No, thanks