[strongSwan] Multiple Win10 roadwarrior clients on the same NATted network

Lorenzo Milesi lorenzo.milesi at yetopen.com
Tue Nov 23 10:09:27 CET 2021

I remember about the inability to have more than one IPSec roadwarrior client on the same NATted network. I've been searching for hours but couldn't find if this is "still" a thing.
The more explicit and recent article on the subject I found is this[1], which basically lowers the security of the VPN client, but should allow multiple clients in the same network to connect. I cannot make tests at the moment, I'm just investigating on possible solution, so I was wondering if someone knows more in detail how it works.


P.S. I have a network with a stable tunnel from a firewall to StrongSwan, I connected a Win10 client inside this network to the VPN and they both appeared to work fine (except for a quick reconnect of the firewall tunnel). But they're two different tunnels, the client was on the roadwarrior one while the firewall has a dedicated one.

[1] http://woshub.com/l2tp-ipsec-vpn-server-behind/
Lorenzo Milesi - lorenzo.milesi at yetopen.com 
CTO @ YetOpen Srl

YetOpen - https://www.yetopen.com/

Via Salerno 18 - 23900 Lecco - ITALY -      | 4801 Glenwood Avenue - Suite 200 - Raleigh, NC 27612 - USA -
Tel +39 0341 220 205 - info.it at yetopen.com  | Phone +1 919-817-8106 - info.us at yetopen.com

Think green - Non stampare questa e-mail se non necessario / Don't print this email unless necessary

-------- D.Lgs. 196/2003 e GDPR 679/2016 --------
Tutte le informazioni contenute in questo messaggio sono riservate ed a uso esclusivo del destinatario.
Tutte le informazioni ivi contenute, compresi eventuali allegati, sono da ritenere confidenziali e riservate secondo i termini
del vigente D.Lgs. 196/2003 in materia di privacy e del Regolamento europeo 679/2016 - GDPR - e quindi ne e' proibita l'utilizzazione ulteriore non autorizzata.
Nel caso in cui questo messaggio Le fosse pervenuto per errore, La invitiamo ad eliminarlo senza copiarlo, stamparlo, a non inoltrarlo a terzi e ad avvertirci non appena possibile.

Confidentiality notice: this email message including any attachment is for the sole use of the intended recipient and may contain confidential and privileged information;
pursuant to Legislative Decree 196/2003 and the European General Data Protection Regulation 679/2016 - GDPR - any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recepient please delete this message without copying, printing or forwarding it to others, and alert us as soon as possible.
Thank you.

More information about the Users mailing list