strongswan route traffic to specified IPs onlystrongSwan IPsec server with AWS EC2 VPC VPN clientStrongswan vpn tunnel connected but the traffic is not routed through itstrongswan: entirely virtual subnetstrongSwan server with Windows 7 clients doesn't route trafficAWS StrongSwan IPSec VPNRoute all traffic through StrongSwan VPNAllow Strongswan roadwarrior to access local LANStrongswan RA and Strongswan site-2-site with ASAstrongSwan: multiple rightsubnet using IKEv1Is it possible to push a route when a client connects to Strongswan server?
What is the offset in a seaplane's hull?
If a centaur druid Wild Shapes into a Giant Elk, do their Charge features stack?
What do you call words made from common English words?
Why is the design of haulage companies so “special”?
Is ipsum/ipsa/ipse a third person pronoun, or can it serve other functions?
Can I find out the caloric content of bread by dehydrating it?
What causes the sudden spool-up sound from an F-16 when enabling afterburner?
Symmetry in quantum mechanics
How could a lack of term limits lead to a "dictatorship?"
Is Social Media Science Fiction?
Does the average primeness of natural numbers tend to zero?
Why do we use polarized capacitors?
Can I legally use front facing blue light in the UK?
Calculate Levenshtein distance between two strings in Python
Email Account under attack (really) - anything I can do?
extract characters between two commas?
Is there a way to make member function NOT callable from constructor?
What happens when a metallic dragon and a chromatic dragon mate?
Is there a name of the flying bionic bird?
I see my dog run
Shall I use personal or official e-mail account when registering to external websites for work purpose?
Information to fellow intern about hiring?
Doomsday-clock for my fantasy planet
What is the command to reset a PC without deleting any files
strongswan route traffic to specified IPs only
strongSwan IPsec server with AWS EC2 VPC VPN clientStrongswan vpn tunnel connected but the traffic is not routed through itstrongswan: entirely virtual subnetstrongSwan server with Windows 7 clients doesn't route trafficAWS StrongSwan IPSec VPNRoute all traffic through StrongSwan VPNAllow Strongswan roadwarrior to access local LANStrongswan RA and Strongswan site-2-site with ASAstrongSwan: multiple rightsubnet using IKEv1Is it possible to push a route when a client connects to Strongswan server?
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
In my company we have a strongswan vpn that we use to be able to access a git server, The problem is that we are facing MTU issues, so for example when we do something like pip install -r requirements.txt the packages that are located outside of our git server can not be reached.
Is there are a way to route throught strongswan only the traffic to the git server ip with client side config only?
currently we are using network manager to connect to the vpn which always 0.0.0.0/0 for the remote network
vpn strongswan
New contributor
add a comment |
In my company we have a strongswan vpn that we use to be able to access a git server, The problem is that we are facing MTU issues, so for example when we do something like pip install -r requirements.txt the packages that are located outside of our git server can not be reached.
Is there are a way to route throught strongswan only the traffic to the git server ip with client side config only?
currently we are using network manager to connect to the vpn which always 0.0.0.0/0 for the remote network
vpn strongswan
New contributor
add a comment |
In my company we have a strongswan vpn that we use to be able to access a git server, The problem is that we are facing MTU issues, so for example when we do something like pip install -r requirements.txt the packages that are located outside of our git server can not be reached.
Is there are a way to route throught strongswan only the traffic to the git server ip with client side config only?
currently we are using network manager to connect to the vpn which always 0.0.0.0/0 for the remote network
vpn strongswan
New contributor
In my company we have a strongswan vpn that we use to be able to access a git server, The problem is that we are facing MTU issues, so for example when we do something like pip install -r requirements.txt the packages that are located outside of our git server can not be reached.
Is there are a way to route throught strongswan only the traffic to the git server ip with client side config only?
currently we are using network manager to connect to the vpn which always 0.0.0.0/0 for the remote network
vpn strongswan
vpn strongswan
New contributor
New contributor
New contributor
asked Apr 5 at 1:00
jperezjperez
12
12
New contributor
New contributor
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
While the client always proposes 0.0.0.0/0 as remote traffic selector, the server is free to narrow this to a smaller subnet (or multiple subnets/IPs). So if you change the server's configuration (its local traffic selector) to the IPs you want, the client will only tunnel traffic to them and the rest will bypass the VPN.
You could also look into fixing the MTU/MSS issue (e.g. via TCPMSS
target for iptables).
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
jperez is a new contributor. Be nice, and check out our Code of Conduct.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961611%2fstrongswan-route-traffic-to-specified-ips-only%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
While the client always proposes 0.0.0.0/0 as remote traffic selector, the server is free to narrow this to a smaller subnet (or multiple subnets/IPs). So if you change the server's configuration (its local traffic selector) to the IPs you want, the client will only tunnel traffic to them and the rest will bypass the VPN.
You could also look into fixing the MTU/MSS issue (e.g. via TCPMSS
target for iptables).
add a comment |
While the client always proposes 0.0.0.0/0 as remote traffic selector, the server is free to narrow this to a smaller subnet (or multiple subnets/IPs). So if you change the server's configuration (its local traffic selector) to the IPs you want, the client will only tunnel traffic to them and the rest will bypass the VPN.
You could also look into fixing the MTU/MSS issue (e.g. via TCPMSS
target for iptables).
add a comment |
While the client always proposes 0.0.0.0/0 as remote traffic selector, the server is free to narrow this to a smaller subnet (or multiple subnets/IPs). So if you change the server's configuration (its local traffic selector) to the IPs you want, the client will only tunnel traffic to them and the rest will bypass the VPN.
You could also look into fixing the MTU/MSS issue (e.g. via TCPMSS
target for iptables).
While the client always proposes 0.0.0.0/0 as remote traffic selector, the server is free to narrow this to a smaller subnet (or multiple subnets/IPs). So if you change the server's configuration (its local traffic selector) to the IPs you want, the client will only tunnel traffic to them and the rest will bypass the VPN.
You could also look into fixing the MTU/MSS issue (e.g. via TCPMSS
target for iptables).
answered Apr 5 at 7:21
ecdsaecdsa
2,042915
2,042915
add a comment |
add a comment |
jperez is a new contributor. Be nice, and check out our Code of Conduct.
jperez is a new contributor. Be nice, and check out our Code of Conduct.
jperez is a new contributor. Be nice, and check out our Code of Conduct.
jperez is a new contributor. Be nice, and check out our Code of Conduct.
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f961611%2fstrongswan-route-traffic-to-specified-ips-only%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown