[strongSwan] Strongswan Multiple right subnets with Cisco ASA

Robert Sander r.sander at heinlein-support.de
Thu Apr 1 09:51:46 CEST 2021


Am 01.04.21 um 09:42 schrieb David Irivbogbe:

> Please I am having issues with an IKEv2 vpn to a cisco ASA. It worked
> perfectly when I have just one right subnet, now our third party wants
> us to include another subnet but I can get this to work, Pings to the
> new subnet are unsuccessful. 

To work with Cisco you have to define multiple connections. Define your
first connection as usual and the others like this:

conn base
	…

conn base2
	also=base
	rightsubnet=10.10.2.0/24

conn base3
	also=base
	rightsubnet=10.10.1.0/24


Regards
-- 
Robert Sander
Heinlein Consulting GmbH
Schwedter Str. 8/9b, 10119 Berlin

http://www.heinlein-support.de

Tel: 030 / 405051-43
Fax: 030 / 405051-19

Zwangsangaben lt. §35a GmbHG:
HRB 93818 B / Amtsgericht Berlin-Charlottenburg,
Geschäftsführer: Peer Heinlein -- Sitz: Berlin

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20210401/49d9cd6d/attachment.sig>


More information about the Users mailing list