[strongSwan] Setup site-to-site VPN via central server

Martin Sand dborn at gmx.net
Mon Jul 18 22:33:23 CEST 2016

Thanks a lot, Tobias! Really appreciated.

> I've added some documentation [1].
I read through the hub-and-spoke setup on the internet. Is my setup 
actually a hub-and-spoke type? I connect from the gateways directly to 
the internet and only the traffic to is routed through 
VPN. Also the text in [1] mentions A-C whereas the diagram shows A-D. Is 
this on purpose?

>> Out of curiosity, how would you configure the server and client if I
>> would like to add vpn-third subnet with
> You'd just add that subnet to the list of remote traffic selectors on
> the clients and as local traffic selector on the server and the client
So this would (or could) result in the following traffic selectors?

## IPs:
Server IP =
First GW =
Second GW =
Third GW =

## Server.conf
conn vpn-first
         rightsubnet =
         leftsubnet =

## First-Gateway.conf
conn vpn-first
         rightsubnet =
         leftsubnet =

Best regards


