[strongSwan] strongSwan site-to-site VPN on DMZ host with single interface

tom posturne at gmail.com
Fri Nov 23 09:50:03 CET 2018


Hello,

how it be possible to run a strongSwan site-to-site VPN placed in a
DMZ with only a single NIC?
The strongSwan server is placed in my DMZ  with a routable public IP
1.1.1.1 Public LAN 1.1.1.0/24.
My local IP, where all outgoing traffic through the tunnel should bei
NAT to is 10.0.0.1.

local site:
 leftsubnet=10.0.0.1/32

Remote site:
 rightsubnet=10.0.0.0/24
 right=2.2.2.2


Do I've to bind 10.0.0.1 as alias ip on the same NIC as 1.1.1.1?
How do I've to setup the NAT?

It would be very glad, if you can bring me on the right way.I hope I
made a clear explanation.

Kind regards
tom


More information about the Users mailing list