[ previous ] [ next ] [ threads ]
 From:  Michael <monowall at encambio dot com>
 To:  Chris Buechler <cbuechler at gmail dot com>
 Cc:  M0n0wall <m0n0wall at lists dot m0n0 dot ch>
 Subject:  Re: [m0n0wall] How to route OPT traffic to IPSec tunnel?
 Date:  Thu, 1 Apr 2010 20:21:59 +0200
Hello Chris,

On Thu., Apr  01, 2010, Chris Buechler wrote:
>On Thu, Apr 1, 2010 at 1:56 PM, Michael wrote:

>> The LANs of both routers are connected via a IPSec tunnel, so:

>> ...pinging works fine. The problem is trying to pass any traffic
>> from OPT to the VPN does not work:

>> What is the correct way to route any (not just ICMP) traffic
>> from the OPT interface to hosts through the tunnel? Thanks.
>Your IPsec config has to include the subnet of that OPT1 interface.
But how to do that without adding another tunnel? You see from the
LAN and OPT subnet numbers that they are not summarizable as
mentioned in the FAQ 15.26 (How can I route multiple subnets over
a site to site IPSec VPN.) And I don't want to set up new tunnels.

There must be a way to route traffic from to the
IPSec tunnel. Would it work to add a static route somehow involving
the LAN IP as gateway and destination