26.09.2026 10:24, Crystal Kolipe пишет:
On Fri, Sep 25, 2026 at 01:36:36PM +0300, kasak wrote:
When iked is off, lan network 192.168.0.0 can access 2.2.2.2 through wan.
And 10.0.0.0 can access 1.1.1.1 through wan.
But when iked is launched, only 1.1.1.1 and 2.2.2.2 can access
one-to-another, and 192.168.0.0 can no longer access 2.2.2.2 and 10.0.0.0
cat no longer access 1.1.1.1
What exactly did you _expect_ to happen?
I thought that ipsec is not a tunnel like wireguard is. (That send
encrypted traffic through some udp port)
I thought that ipsec is some magic. I don't really understand how it
send traffic.
It use 500 port to exchange key and after that how the link is working
is mystery.
You've created a point to point link between the two hosts, using their public
IPs.
To fix it, usually we need to create to additional rules in iked:
ikev2 esp from 192.168.0.0/24 to 2.2.2.2 peer 2.2.2.2
and
ikev2 esp from 10.0.0.0/24 to 1.1.1.1 peer 1.1.1.1
This does not revert to the previous behaviour. Now, traffic from the
192.168.0.0/24 and 10.0.0.0/24 subnets is going over the ipsec tunnel.
What do you want? Point to point between the hosts, but other traffic routed
normally, (without IPSEC), or do you want an IPSEC tunnel that carries all
traffic between those subnets?
yes, i wanted to make tunnel just between two hosts, but not at the cost
of breaking connectivity from lan network to both wan addresses.
connecting lan networks is not needed.
Have a look at ipsec(4), especially about the different between transport and
tunnel modes.
yes, i know that transport is encrypting only payload and tunnel is
encrypting full packet, but this does not help me
If you want all of the traffic to go between these hosts as IPSEC, then you've
already found the solution.
If you just want point to point between the hosts and other traffic routed
normally, then create a tunnel using a subnet from a private IP range just for
the IPSEC traffic.
That was real interesting idea and it works! Now I began to understand
what was wrong!
Not completely, but better than nothing :)
Thank you for your time! If you have something more, it will be great!
(Hint: the tunnel can be IPv6 even if you only have IPv4 between the hosts.)