站点到站点VPN - Openswan和CISCO A2A


1

下面是Openswan服务器和CISCO A2A之间的VPN连接图。

在此输入图像描述

客户端A和B是具有静态ips的远程主机。客户端X和Y位于思科防火墙之后。

我可以看到STATE_QUICK_I2:在日志中发送了QI2,IPsec SA建立的隧道模式。因此,openswan和cisco之间的隧道已启动并运行。但我甚至无法从VPN1 ping客户端X.

  1. 如何配置客户端A通过VPN1将流量路由到客户端X?
  2. VPN1 iptable规则来捕获来自客户端A然后转发到CICSO的流量?

这是我的ipsec.conf

conn Linux-to-CISCO
    type= tunnel
    authby= secret
    left= <Openswan IP>
    leftsubnets= { client A/32 client B/32}
    right= <CisCo IP>
    rightsubnets= { client X/32 client Y/32 }
    esp= aes256-sha1
    keyexchange= ike
    pfs= no
    auto= start
By using our site, you acknowledge that you have read and understand our Cookie Policy and Privacy Policy.
Licensed under cc by-sa 3.0 with attribution required.