Yeagley, Josiah jyeagley at harris.com
Sat Jan 30 21:55:45 CET 2016

So, my celebration was a bit short lived. Alice and Bob cannot ping each other. :-\ I've been trying to solve this on my own because I do not want to continue to bother everyone on this mailing list... but I have not been able to figure out what the problem is. 

Quick review of my setup. I have implemented the example located here: https://www.strongswan.org/uml/testresults/ikev2/net2net-psk/ using two Gateworks 5300s running OpenWRT Chaos Calmer (14.08). They have strongsawn U5.2.0/K3.14.16). Here is how my interfaces are configured http://paste.ubuntu.com/14769187/

With the previous fix the net-net connection comes up and the tunnel is established. As can be seen by the output of 'ipsec statusall' http://paste.ubuntu.com/14768915/

Alice ( can ping Moon ( & Sun ( but not Bob (
Bob ( can ping Sun ( & Moon ( but not Alice (

Since Alice ( can ping Sun ( but not Bob ( I am assuming what is happening is that the eth1 interface on Sun ( is not forwarding the packets from Alice ( on to Bob  (  After googling the issue some I added the following lines to /etc/firewall.user http://paste.ubuntu.com/14769548/

But this does not fix the problem. Alice cannot ping Bob :-\  The following is the output of 'iptables -L' http://paste.ubuntu.com/14769773/  So, I believe that means the firewall settings are working. After a bit more searching I added the following lines to my firewall.user

iptables -I FORWARD -i eth0 -s -d -m policy --dir in --pol ipsec -j ACCEPT
iptables -I FORWARD -s -d -m policy --dir out --pol ipsec -j ACCEPT

iptables -I FORWARD -i eth0 -s -d -m policy --dir in --pol ipsec -j ACCEPT
iptables -I FORWARD -s -d -m policy --dir out --pol ipsec -j ACCEPT

but this also did not fix the problem and Alice and Bob still cannot ping each other. 

When I type 'ip route list table 220' on moon the output I get is " via dev eth0  proto static  src" which I believe means it should route all traffic bound for 10.2.x.x through the tunnel.... I believe it is happening since Alice ( can ping eth1 on Sun ( 

I am at a loss as to why this isn't working... so I am hoping someone on this mailing list will be able to spot what I have misconfigured or what I am missing. Any help will be much appreciated! 

~Josiah s. Yeagley

