[strongSwan] Traffic in a Hub and Spoke setup not forwarded

Martin Sand dborn at gmx.net
Fri Feb 24 23:49:31 CET 2017

Hi all

After some time I began to investigate again.
I think the problem is that my strongSwan router is behind a modem 
(another router) which I cannot set to bridge modus.
The modem is NATing the traffic.

Routing table 220 shows the problem.
The traffic is sent to the modem (, connected to the 
internet and my strongSwan vpn router (
The modem is also the default gateway.

root at OpenWrt:~# ip route show table 220 via dev eth0  proto static  src via dev eth0  proto static  src

I tried to get around the problem by setting the via route to the 
external IP of my modem (
But this does not work:

root at OpenWrt:~# ip r c table 220 via dev 
eth0 proto static src
RTNETLINK answers: Network is unreachable

Any ideas on how to solve the issue?

Best regards

On 11/08/2016 08:46 PM, Martin Sand wrote:
> Hi all
> I have a Hub and Spoke setup:
> * Central server
> * Router 1:
> * Router 2:
> I cannot reach the computers on the other side of the network although 
> tunnel is established.
> Do I miss an iptable or route information?
> Output from when trying to reach a computer on the other 
> network (
> [user at workstation ~]$ tracepath
>  1?: [LOCALHOST]                                         pmtu 1500
>  1:  router-1                                     0.475ms
>  1:  router-1                                     0.445ms
>  2:  no reply
> Output of route on Router 1 (
> via dev eth0  proto static  src
> Output of route on Router 2 (
> via dev eth0  proto static  src
> Any ideas on what is going wrong? Maybe because one router shows the 
> external IP of the Hub instead of the internal one?
> Best regards
> Martin
> _______________________________________________
> Users mailing list
> Users at lists.strongswan.org
> https://lists.strongswan.org/mailman/listinfo/users

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20170224/88099cb6/attachment.html>

More information about the Users mailing list