L
L
Lasha2020-09-14 01:50:43
VPN
Lasha, 2020-09-14 01:50:43

How to raise an IPSec Site to Site network through public IP addresses?

hello everyone
, I'm trying to raise an IPSec Site to Site network through public IP addresses.
I have multiple servers and two subnets from multiple addresses

first subnet is 11.11.11.2-10/24
server 10: billing - 11.11.11.3
server 11: web - 11.11.11.4
server 12: RouterOS CHR - 11.11.11.5. servers are not connected through this router in any way, it is only for IPSec the

second subnet is 22.22.22.10-15/24
server 20: web - 22.22.22.10
server 21: RouterOS CHR - 22.22.22.11. servers are not connected through this router in any way, it is only for IPSec

the fact is that when the IPSec connection rises and I see active connections in Active Peers and Installed SAs, then the server does not ping, but if we take local addresses like 10.1.0.0/24 instead of public addresses, then everything works, in Firewall NAT too configured, src=0.0.0.0/0 dst=11.11.11.0/24, and also in a different subnet, but the servers themselves, when accessing different services, do not go through IPSec.

maybe someone can help, there is an idea through a router, to conduct a network from servers so that the servers have gateway=11.11.11.5, but have not tried it yet

5f5ea23686e2e596037939.png

Answer the question

In order to leave comments, you need to log in

1 answer(s)
C
CityCat4, 2020-09-14
@CityCat4

There is no routing in IPSec, it is replaced by policies. As you write policies, traffic will go. But the policy cannot include the gate, because packets are transmitted through it, so it will have to be written for each IP separately. If you want to avoid such a garden - use RFC1918 addresses for servers behind the gate.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question