Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game. |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
12-09-2005, 10:01 AM
|
#1
|
Member
Registered: Feb 2005
Distribution: Arch, CentOS, Fedora, macOS, SLES, Ubuntu
Posts: 327
Rep:
|
Can I Route Specific Addresses Through an IPSec VPN Tunnel?
Good Morning, All,
I've set up an IPCop 1.4.10 box in both my home and office, trying to see if I can do this:
--Route all traffic for the SMTP server to go through the VPN tunnel to my office, through the IPCop box there on the local network.
--Route all traffic going to the server (which has a public address on the internet) to go through the VPN tunnel instead.
Is this possible? I've tried to manually add some "route add -net ..." and "route add -host ..." statements on the home IPCop box at the console, but no luck.
How would I go about doing this? Or is there a limit to the number of hops for IPSec traffic?
The VPN is functional, as I can access machines within the office's IPCop subnet (192.168.10.x) from the home IPCop network (192.168.1.x) and vice-versa. However, attempting to access the server results in it going through the home IPCop box routing to the local carrier--not over the VPN. Same for SMTP access...
If this can work then I look forward to deploying the same setup to our remote offices... the VPN tunnels in use at the present are overloaded and particularly slow and unreliable.
I sincerely appreciate any/all thoughts on this. Thanks in advance!
|
|
|
12-09-2005, 07:20 PM
|
#2
|
LQ Guru
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 11,097
|
VPN is special... it uses setkey rules, not route, on the box that is doing the work.
Start with the VPN HowTo of the Linux Documentation Project ...
Quote:
"Good luck, Jim..." --Bones
"Abandon all hope, ye who enter here." --The Inferno
"A-A-A-A-A-A-AU-G-G-G-G-HH!" --Linus (van Pelt)
|
|
|
|
12-09-2005, 08:15 PM
|
#3
|
Member
Registered: Feb 2005
Distribution: Arch, CentOS, Fedora, macOS, SLES, Ubuntu
Posts: 327
Original Poster
Rep:
|
Sundialsvcs,
Thanks for the reply. Going to your link now!
Strick1226
|
|
|
12-15-2005, 09:30 AM
|
#4
|
Member
Registered: Feb 2005
Distribution: Arch, CentOS, Fedora, macOS, SLES, Ubuntu
Posts: 327
Original Poster
Rep:
|
Hmm... even when I tried to setup a static route and assign to my ipsec0 interface, it doesn't fail--but doesn't seem to be encrypted, as ifconfig shows eth1 with all the traffic, not ipsec0.
Do I need to modify the metric assignments manually, in order to force traffic for a certain subnet to go over the ipsec0 interface?
|
|
|
All times are GMT -5. The time now is 08:35 AM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|