On Fri, Sep 25, 2026 at 01:36:36PM +0300, kasak wrote:
> When iked is off, lan network 192.168.0.0 can access 2.2.2.2 through wan.
> And 10.0.0.0 can access 1.1.1.1 through wan.
> But when iked is launched, only 1.1.1.1 and 2.2.2.2 can access
> one-to-another, and 192.168.0.0 can no longer access 2.2.2.2 and 10.0.0.0
> cat no longer access 1.1.1.1

What exactly did you _expect_ to happen?

You've created a point to point link between the two hosts, using their public
IPs.

> To fix it, usually we need to create to additional rules in iked:
> 
> ikev2 esp from 192.168.0.0/24 to 2.2.2.2 peer 2.2.2.2
> and
> 
> ikev2 esp from 10.0.0.0/24 to 1.1.1.1 peer 1.1.1.1

This does not revert to the previous behaviour.  Now, traffic from the
192.168.0.0/24 and 10.0.0.0/24 subnets is going over the ipsec tunnel.

What do you want?  Point to point between the hosts, but other traffic routed
normally, (without IPSEC), or do you want an IPSEC tunnel that carries all
traffic between those subnets?

Have a look at ipsec(4), especially about the different between transport and
tunnel modes.

If you want all of the traffic to go between these hosts as IPSEC, then you've
already found the solution.

If you just want point to point between the hosts and other traffic routed
normally, then create a tunnel using a subnet from a private IP range just for
the IPSEC traffic.

(Hint: the tunnel can be IPv6 even if you only have IPv4 between the hosts.)

Reply via email to