Your left and right subnets are the same so I don't know how that will work. Also there is nothing in your config to route the machine C subnet. Guessing but on B you probably want leftsubnets = {10.5.5.50,192.168.13.212} and something similar on A. Also is b .50 or .52?

On 05/10/2020 07:14, Mehboob Ansari wrote:
Hi Team,

Please help to provide information on requested query.

Thanks,

Regards,
Mehboob Ansari

From: "Mehboob Ansari" <[email protected]>
To: "swan" <[email protected]>
Sent: Tuesday, September 29, 2020 12:40:39 PM
Subject: ipsec

Hi Team,

Please help in below scenario:-

I have 3 machines :- machine A ( ip - 10.5.5.7, Client ), machine B(10.5.5.52, server ) and machine C(192.168.13.212 ).

Ipsec sec tunnel established between machine A and machine B. when i ping from A  to B , ipsec whack --trafficstatus in and out byte get increase.

Now machine C is connected with machine B and there is a route so that i can ping machine C through machine A, But when i ping machine C from machine A , ping get started but ipsec whack --trafficstatus is not increasing. packets are going through tunnel. 

Expected result - I want when i ping machine C through machine A , ipsec traffic should get increase. 

Note - Ipsec tunnel is only between A and B , where A is client and B is server.


Client ipsec.conf

conn ikesa
        authby=rsasig
        left=10.5.5.5
        #leftsourceip=10.5.5.5
        leftsubnet=10.5.5.5/24
        leftcert=10.5.5.5       # cert name
        leftid=%fromcert
        leftsendcert=always                           
        right=10.5.5.50                              
        #rightsourceip=10.5.5.50                       
        rightsubnet=10.5.5.50/24                       
        rightid=%fromcert                             
        #decap-dscp=yes
        also=profile
        auto=start


Server ipsec.conf

conn profile
        authby=rsasig
        left=10.5.5.50
        #leftsourceip=10.5.5.50
        leftsubnet=10.5.5.50/24
        leftcert=10.5.5.50
        leftid=%fromcert
        leftsendcert=always
        #leftsubnet=192.168.15.0/24
        #rightaddresspool=10.10.5.2-10.10.5.10
        right=10.5.5.5
        #rightsourceip=10.5.5.5
        rightsubnet=10.5.5.5/24
        rightid=%fromcert
        auto=start


Please help me out.

Thanks in advance,


Regards,
Mehboob Ansari


_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan



_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan

Reply via email to