[Firehol-support] Opeswan route all traffic

Phil Whineray phil at sanewall.org
Sun Jun 8 10:15:35 BST 2014


Hi Aleksander
On Sun, Jun 08, 2014 at 11:49:40AM +0400, Aleksander Ol wrote:
> 
> Good afternoon.
> I can not send traffic as IPSEC .
> 
> configured so
> 1) Eth0 ( Internal Network .... 192.168.0.0/24 )
> 2) Eth1  ( Internet )
> 
> I setup Openswan IPsec .... use (netkey ) 
> Now All local traffic work fine ... but i neet route all traffic to VPN .... Internet also.
> I need that users went through a remote gateway with any established VPN connection
> If that does not work VPN Internet also should not work
> 
> The problem is that OpenSwan IPSEC  does not create a separate interface
> 
> If anyone knows how to config. Help please
> 
> Sorry for my english

Sorry - I don't think you have a firewall problem here. You need to get
the traffic directing correctly first with routes etc. Only once that is all
working you might want to revisit the firewall if it is blocking or
permitting something it should not.

I think you probably need to ask for help in an OpenSwan or IPSec forum,
however I did a quick search and this looks like the sort of thing you
would need to do:
  https://wiki.archlinux.org/index.php/L2TP/IPsec_VPN_client_setup#Routing_all_traffic_through_the_tunnel

The key is that (only) the IP of the remote VPN server is explicitly routed
via your normal internet. The original default is replaced with a new
one.

Hope that helps
Phil



More information about the Firehol-support mailing list