News: This forum is now permanently frozen.
Pages: [1]
Topic: ipsecuritas remote network "anywhere" doesn't work... Monowall issue ?  (Read 5180 times)
« on: December 15, 2010, 21:47:31 »
yonailo *
Posts: 25

Hello,

As I am not sure if it is a problem of the latest release of IPSECURITAS software, I would like to share with you this issue.

I can set up the ipsec tunnel between local and remote networks without problems, but if I try to use the "remote network: anywhere" option that comes with IPSECURITAS to route all my traffic through the tunnel, it does nothing, it is like if I had no more connectivity on my Mac laptop.

I would like to know if anybody has tried it out the same option with pfSense, if it works with pfSense then I believe there is a problem with Monowall (racoon version, kernel version, some kind of routing/ipfilter problem....I don't really know).

Any help regarding this issue would be greatly appreciated. I have search the net and I have only found this link:

http://www.lobotomo.com/phpBB/viewtopic.php?t=163

PS: if IPSECURITAS has such a bug, why has not been yet fixed ? I can't believe IPSECURITAS is the culprit here...

Thanks for any input regarding this.

JFRH
« Reply #1 on: June 18, 2012, 20:06:50 »
yonailo *
Posts: 25

Nobody knows ?

Maybe somebody should contact the IPsecuritas guys to let them know, if it has nothing to do with Monowall, I forgot tell you that I have made my tests with version 1.3, but I believe 1.33 will experience the same issue.

Could anybody else confirm this please ?

JFRH
« Reply #2 on: June 20, 2012, 14:12:48 »
yonailo *
Posts: 25

Hey guys,

I am pleased to announce that this is not a Monowall issue, the problem came from my current setup.

I've got my adsl-router in front of Monowall, and it is the adsl-route which makes the NAT functionality.

Therefore, I had to create routing rules in my ADSL router to forward the private addressing in the LAN and OPT1 interfaces to Monowall.

I didn't realize that this is also necessary for the IPSec connection.  My IPSec client uses the IP address 192.168.0.0/24, and without a route for this network towards Monowall, the reverse path of the VPN connection was not working.

After I added this route, everything worked fine.

JFRH
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines