Re: IPSEC Site-to-Site not routing packages - SOLVED

2012-02-23 Thread Morten Christensen
Hi All, The problem I experienced was indeed in a testbed between an Alix and Soekris (not part of the problem:-) And the reason was that none of the VPN endpoints had a default gw (they share a common wan subnet while I should trial an ipsec solution) I gave both of the a default GW IP that po

Re: IPSEC Site-to-Site not routing packages

2012-02-23 Thread Russell Garrison
I can confirm this. Spent way too much time in my VMWare lab on this until I thought to add a default route to the host-only interfaces I was running the tunnel on. All you need is default route and it will work. I have found that "fleshed out" config for networking on OpenBSD is a sure way to clea

Re: IPSEC Site-to-Site not routing packages

2012-02-23 Thread Aner Perez
See the thread titled "ipsec tunnel traffic getting icmp host unreachable" on this same list. In short, the answer is that you need a standard route (in addition to the encap route) to the destination networks. Any route that covers your destination network will do. In my case, instead of a

IPSEC Site-to-Site not routing packages

2012-02-22 Thread Morten Christensen
Dear fellow OpenBSD friends. I'm setting up 2 FW's that should form a VPN tunnel securing the net behind each FW - simple NET x -> FW x -> WAN -> FW y -> NET y I'm using ipsec.conf / ipsecctl. OpenBSD 5, pf is disabled. On FW x # cat /etc/ipsec.conf