On Fri, Sep 25, 2026 at 01:36:36PM +0300, kasak wrote: > When iked is off, lan network 192.168.0.0 can access 2.2.2.2 through wan. > And 10.0.0.0 can access 1.1.1.1 through wan. > But when iked is launched, only 1.1.1.1 and 2.2.2.2 can access > one-to-another, and 192.168.0.0 can no longer access 2.2.2.2 and 10.0.0.0 > cat no longer access 1.1.1.1
What exactly did you _expect_ to happen? You've created a point to point link between the two hosts, using their public IPs. > To fix it, usually we need to create to additional rules in iked: > > ikev2 esp from 192.168.0.0/24 to 2.2.2.2 peer 2.2.2.2 > and > > ikev2 esp from 10.0.0.0/24 to 1.1.1.1 peer 1.1.1.1 This does not revert to the previous behaviour. Now, traffic from the 192.168.0.0/24 and 10.0.0.0/24 subnets is going over the ipsec tunnel. What do you want? Point to point between the hosts, but other traffic routed normally, (without IPSEC), or do you want an IPSEC tunnel that carries all traffic between those subnets? Have a look at ipsec(4), especially about the different between transport and tunnel modes. If you want all of the traffic to go between these hosts as IPSEC, then you've already found the solution. If you just want point to point between the hosts and other traffic routed normally, then create a tunnel using a subnet from a private IP range just for the IPSEC traffic. (Hint: the tunnel can be IPv6 even if you only have IPv4 between the hosts.)

