[strongSwan] Nested IPsec Tunnels

Fred curious_freddy at gmsl.co.uk
Wed Mar 11 11:26:46 CET 2015


On 03/03/2015 00:48, Ryan Ruel wrote:
> I have an application scenario where I need to test Nested IPsec Tunnels.
>
> In other words,
>
> Linux Box <----->  IPsec GW 1  <------>  IPsec GW 2
>
> Outer IPsec Tunnel
> |<---------------->|
>
> Inner IPsec Tunnel
> |<-------------------------------------->|
>
> The Linux Box client cannot directly talk to IPsec GW 2.  It's unusual, I
> know.

I've done this before using SSH tunnels to connect my host to a remote 
host that's behind a couple of firewalls.

Could you not just have two ipsec tunnels ?

Linux Box <----->  IPsec GW 1  <------>  IPsec GW 2

Tunnel #1                    Tunnel #2
|<------------------>|     |<------------------>|

Fred



More information about the Users mailing list