[strongSwan] Setup site-to-site VPN via central server

Martin Sand dborn at gmx.net
Fri Jul 29 23:46:05 CEST 2016

Ok, I have installed strongswan on my laptop ( behind 
vpn-second ( and configured another subnet on 
the hub and assigned the virtual IP Established tunnel, 
sSeems to work. So now I simulate the other gateway 500km away.

When I now try to reach the desktop the connection gets 
refused by the vpn-second gateway.

Ping gives the following result:
PING arbeitszimmer ( 56(84) bytes of data.
 From router-second ( icmp_seq=1 Destination Port Unreachable

So I added leftfirewall=yes on the vpn-second gateway ipsec.conf. Now it 
works. I hope that solved the problem.

Best regards

More information about the Users mailing list