Portál AbcLinuxu, 5. května 2025 15:08
[admin@ipsec-gw] > ip ipsec mode-config print ... 1 R name="client1" system-dns=no static-dns="" address=172.10.0.17 address-prefix-length=32 split-include=192.168.1.0/24,192.168.16.0/20,172.20.3.0/24 split-dns=""Problem je, ze jedine systemy, kde to funguje OOTB, su Mikrotik a Windows (nativna IPsec VPN). Ostatni klienti (Linux network-mananger so strongswan pluginom, strongswan [1] (stary config ipsec.conf, aj novy swanctl.conf), Apple, Android [2]...) pouziju vzdy len prvy definovany rozsah a ostatne ignoruju. [1] Tu sa mi podarilo dosiahnut pozadovany stav definovanim samostatnej conn, resp. children, pre kazdy subnet. [2] V Android-e (strongswan app) sa daju rucne zadat split-tunneling rozsahy, takze tu to ako tak funguje. Lokalne siete viem pretlacit cez jeden vacsi subnet, ale potrebujem pridat este dalsie uplne ine rozsahy. Na nete som nasiel viac takychto pripadov, ale ziadne riesenie. Vdaka.
split-include (list of IP prefix; Default: ) List of subnets in CIDR format, which to tunnel. Subnets will be sent to the peer using CISCO UNITY extension, remote peer will create specific dynamic policies.Ten plugin existuje a je zminovany i v napovede, ale pouze pro IKEv1.
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.