Re: reach a remote LAN through IPSEC from the router

2014-02-11 Thread andy
Hi, Reading this a bit late but something doesn't sound quite right. Just ignore me if I'm reading this wrong.. An IPSec tunnel policy defines both the local network *and* the remote network. So for a packet to be encrypted it must have both a source IP address within the local subnet and a

reach a remote LAN through IPSEC from the router

2014-02-10 Thread Aurelien Martin
Dear all, I'm linked to another LAN trough IPSEC. Everything is working except, if I try to reach the remote LAN from my OpenBSD router. In this case, the router use the default interface (wan) instead of the IPSEC tunneling. I would like to be able to reach the remote LAN due to a service on

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Aurelien Martin
through IPSEC from the router Dear all, I'm linked to another LAN trough IPSEC. Everything is working except, if I try to reach the remote LAN from my OpenBSD router. In this case, the router use the default interface (wan) instead of the IPSEC tunneling. I would like to be able to reach the remote

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Johan Mellberg
, February 10, 2014 3:59 PM To: misc@openbsd.org Subject: reach a remote LAN through IPSEC from the router Dear all, I'm linked to another LAN trough IPSEC. Everything is working except, if I try to reach the remote LAN from my OpenBSD router. In this case, the router use the default

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Aurelien Martin
:10 An: Mitja Muženič; misc@openbsd.org Betreff: Re: reach a remote LAN through IPSEC from the router Hi Mitja, When I add the route manually it's working like a charm. But after that, all machines of my LAN ping with this following form (Redirect Host). What does it mean ? For me the router

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Zach Leslie
Subject: reach a remote LAN through IPSEC from the router Dear all, I'm linked to another LAN trough IPSEC. Everything is working except, if I try to reach the remote LAN from my OpenBSD router. In this case, the router use the default interface (wan) instead of the IPSEC tunneling. I would

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Aurelien Martin
2014 16:10 An: Mitja Muženič; misc@openbsd.org Betreff: Re: reach a remote LAN through IPSEC from the router Hi Mitja, When I add the route manually it's working like a charm. But after that, all machines of my LAN ping with this following form (Redirect Host). What does it mean ? For me

Re: reach a remote LAN through IPSEC from the router

2014-02-10 Thread Zach Leslie
On Mon, Feb 10, 2014 at 07:58:39PM +0100, Aurelien Martin wrote: net.inet.icmp.rediraccept=1 # 1=Accept ICMP redirects Good to know this feature :) Are systems behind the firewall able to route to and reach the remote network? Yes all is working. we could route through the