Александр Карабанов
default via 148.251.66.65 dev eth0
10.8.8.0/24 via 148.251.66.76 dev eth0
148.251.66.64/27 via 148.251.66.65 dev eth0
148.251.66.64/27 dev eth0 proto kernel scope link src 148.251.66.76
Александр Карабанов
В теории понятно, что с одной сети в другую и обратно.
Вот ipsec.conf
Я менял ip на внешние но кеннекта не было...
conn inteltek2
# left=
left=10.8.8.1
leftsubnet=10.8.8.1/32
leftfirewall=yes
# leftauth=psk
leftid=148.251.66.76
right=213.74.193.76
# rightauth=psk
rightsubnet=172.29.106.0/24
rightid=213.74.193.76
auto=route
ike=3des-sha1-modp1024!
esp=3des-sha1!
keyexchange=ikev1
dpdaction=restart
dpddelay=10s
forceencaps=yes
type=tunnel
# rekey=no
margintime=5m
Александр Карабанов
root@vpnServer:~# ip a
1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 14:da:e9:98:06:1e brd ff:ff:ff:ff:ff:ff
inet 192.168.1.238/24 brd 192.168.1.255 scope global eth0
valid_lft forever preferred_lft forever
inet6 fe80::16da:e9ff:fe98:61e/64 scope link
valid_lft forever preferred_lft forever
root@vpnServer:~# ip l
1: lo: mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000
link/ether 14:da:e9:98:06:1e brd ff:ff:ff:ff:ff:ff
root@vpnServer:~# ip r
default via 192.168.1.1 dev eth0 proto static metric 1024
192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.238
Александр Карабанов
root@Debian-84-jessie-64-LAMP ~ # ip a
1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: mtu 1500 qdisc mq state UP group default qlen 1000
link/ether 30:5a:3a:75:59:b0 brd ff:ff:ff:ff:ff:ff
inet 148.251.66.76/27 brd 148.251.66.95 scope global eth0
valid_lft forever preferred_lft forever
inet 10.8.8.1/32 scope global eth0
valid_lft forever preferred_lft forever
inet6 2a01:4f8:202:304b::2/64 scope global
valid_lft forever preferred_lft forever
inet6 fe80::325a:3aff:fe75:59b0/64 scope link
valid_lft forever preferred_lft forever
3: eth1: mtu 1500 qdisc noop state DOWN group default qlen 1000
link/ether 30:5a:3a:75:59:b1 brd ff:ff:ff:ff:ff:ff
root@Debian-84-jessie-64-LAMP ~ # ip l
1: lo: mtu 65536 qdisc noqueue state UNKNOWN mode DEFAULT group default
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: mtu 1500 qdisc mq state UP mode DEFAULT group default qlen 1000
link/ether 30:5a:3a:75:59:b0 brd ff:ff:ff:ff:ff:ff
3: eth1: mtu 1500 qdisc noop state DOWN mode DEFAULT group default qlen 1000
link/ether 30:5a:3a:75:59:b1 brd ff:ff:ff:ff:ff:ff
root@Debian-84-jessie-64-LAMP ~ # ip r
default via 148.251.66.65 dev eth0
148.251.66.64/27 via 148.251.66.65 dev eth0
148.251.66.64/27 dev eth0 proto kernel scope link src 148.251.66.76
root@Debian-84-jessie-64-LAMP ~ #
Александр Карабанов
Почему просто? Я очистил все правила и заново все ввел, сделал форвардинг двух сетей разрешил порты. сделал нат маскуарад и ваше правило добавил.
jff.name