Petite question,
Je me suis servis du poste de dsebire pour me faire un tunnel vpn ipsec entre mon serveur chez online et chez moi.
@home j'ai une vm avec une eth en dmz qui me sert de serveur vpn.
Le tunnel se monte bien mais ma vm perd l'accès au lan local oO du coup de mon serveur online je peux pas pinguer ni accéder à mon lan perso.
une idée du soucis?
Coté serveur ipsec.conf
[cpp]# /etc/ipsec.conf - Openswan IPsec configuration file
# This file: /usr/share/doc/openswan/ipsec.conf-sample
#
# Manual: ipsec.conf.5
version 2.0 # conforms to second version of ipsec.conf specification
# basic configuration
config setup
interfaces=%defaultroute
nat_traversal=yes
# exclude networks used on server side by adding %v4:!a.b.c.0/24
virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:!172.16.35.0/24
oe=off
protostack=netkey
plutoopts="--interface=eth0"
# Add connections here
conn NET-TO-NET
authby=secret
pfs=no
rekey=yes
auth=esp
esp=3des-sha1
ike=3des-sha1
ikev2=no
compress=no
keylife=24h
ikelifetime=8h
type=tunnel
left=@ipsrvonline # Local vitals IP locale a la machine = ip publiqe
leftsubnet=0.0.0.0/0 # 172.16.35.0/24
leftid=@ipsrvonline # on utilise l'IP publique comme ID
leftnexthop=%defaultroute
leftsourceip=172.16.35.1
right=@ipfbhome # Remote vitals IP publique distante
rightsubnet=192.168.0.0/24
rightid=@ipfbhome # on s'en fiche un peu, on prend l'IP publique distante
rightnexthop=%defaultroute
rightsourceip=192.168.0.13
auto=start
[/cpp]
mv @home ipsec.conf
[cpp]# /etc/ipsec.conf - Openswan IPsec configuration file
# This file: /usr/share/doc/openswan/ipsec.conf-sample
#
# Manual: ipsec.conf.5
version 2.0 # conforms to second version of ipsec.conf specification
# basic configuration
config setup
interfaces=%defaultroute
nat_traversal=yes
# exclude networks used on server side by adding %v4:!a.b.c.0/24
virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:!192.168.0.0/24
oe=off
protostack=netkey
plutoopts="--interface=eth1"
# Add connections here
conn NET-TO-NET
authby=secret
pfs=no
rekey=yes
auth=esp
esp=3des-sha1
ike=3des-sha1
ikev2=no
compress=no
keylife=24h
ikelifetime=8h
type=tunnel
left=192.168.0.13 # Local dmz vitals (IP de la machine, pas publique)
leftsubnet=192.168.0.0/24
leftid=@ipfbhome # on s'en fiche un peu, on met l'IP publique de la machine
leftnexthop=%defaultroute
leftsourceip=192.168.0.13
right=@ipsrvonline # Remote vitals (ici ip de la machine = ip locale
rightsubnet=0.0.0.0/0 # 172.16.35.0/24
rightid=@ipsrvonline
rightnexthop=%defaultroute
rightsourceip=172.16.35.1
auto=start
[/cpp]
merci
