News: This forum is now permanently frozen.
Pages: [1]
Topic: ipsec site to site, its wrong?  (Read 3525 times)
« on: October 11, 2010, 01:07:44 »
lalo *
Posts: 24

Hello monowall users.
I have a new question for you all.
Im connecting my two monowall with an ipsec vpn tunnel
In a few day my phone company will activate me my adsl for connecting my office on internet.

So i have already configured the two tunnels the first one its my home monowall.

And the second is the office configuration.
I have 3 simple questions:

1) is that the right way to configure the tunnel.
2) does i have to configure a roule to permit INTERFACE IPSEC to pass traffic to DESTINATION LAN SUBNET to permit to see from my office all the home network and from home all the office network??
3) My home network is 10.0.0.1/16 and my office is 10.0.1.1/16 its possible to create a ipsec tunnel with the same class in the ttwo networks?


Sorry for my bad english...


Thank you all


* home.jpg (34.7 KB, 581x466 - viewed 279 times.)

* office.jpg (35.16 KB, 584x467 - viewed 279 times.)
« Reply #1 on: October 19, 2010, 01:23:06 »
lalo *
Posts: 24

Nobody can help me ?  Embarrassed
« Reply #2 on: October 19, 2010, 02:11:03 »
brushedmoss ****
Posts: 446

1) Yes
2) no
3) No, your  pc's won't even consider the router. As the addresses are adjacent to each other, the host will send the packet on the wire to the other host, not destined for its gateway

« Reply #3 on: October 20, 2010, 21:57:27 »
lalo *
Posts: 24

On point 3 if i configure my home network in 10.0.0.1/24 and office in 10.0.1.1/24 can i send request correctly through the vpn?


Thanks a lot for your answer
« Reply #4 on: October 22, 2010, 23:41:17 »
lalo *
Posts: 24

I have 2 ways to resolve it.

1) migrate my home to 10.0.0.1/24 and office to 10.0.1.1/24

2) migrate my mantain my home to 10.0.0.1/16 and migrate the office to 10.1.0.1/16
« Reply #5 on: October 29, 2010, 17:16:52 »
notladstyle **
Posts: 53

as long as every segment (home, office, other office) are all within different networks you are fine. I would avoid using different subnet masks for each network though it gets confusing.
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines