[strongSwan] Ping only goes 1 way
sergej5561 at yandex.com
Thu Jun 27 22:12:58 CEST 2013
I doing a classic RW-NAT-GW server scenario. By this 2 howtos:
The second one proved to be extremely useful because it would NOT work if the rightsubnetwithin= wouldn't be present in the Gateways configuration with:
"received TS_UNACCEPTABLE notify, no CHILD_SA built"
But I get to the point. This is the strangest thing I saw so far, the Roadwarrior can ping the gateway server while it's not possible to ping back from the gateway. How can that be???
<RW laptop with dynamic Virtual IP>192.168.0.22 --- 192.168.0.1 <WIRELESS ROUTER NAT> 126.96.36.199 --- INTERNET --- 188.8.131.52 <Strongswan GW> -- 10.5.0.0/16
GW Server config
rightsubnetwithin=0.0.0.0/0 << AS you can see this is exteremely useful because the RWs are moved between different wireless access points, both their external, both their internal lan ips frequently changing.
leftid=laptop14 at domain.server.com
dpddelay=1m # check connection every minute
dpdtimeout=3m # timeout after 5 minutes
dpdaction=clear # clear connection after timeout
#leftsourceip=192.168.0.22 << Now if I set the sourceip to the current virtual ip as the howto says it won't work with this error:
received INTERNAL_ADDRESS_FAILURE notify, no CHILD_SA built
Both this GW server and the RW have 1-1 single network interface (eth0 and wlan0). There is no firewall on any.
Therefore I configured ip aliases for them:
So again from the RW 10.5.0.2 I can ping the GW server or telnet to any open tcp port, it's working fine but from the server I cannot reac the road warrior, how can that be?
I tried to add all kinds of routes for the 10.5.x.x net on the GW nothing seems to work.
10.5.0.0 <ISPGATE> 255.255.0.0 UG 0 0 0 eth0
Thank you very much,
More information about the Users