Unix Technical Forum

IPSEC VPN ISAKMPD Conflicting Address Ranges

This is a discussion on IPSEC VPN ISAKMPD Conflicting Address Ranges within the mailing.openbsd.tech forums, part of the OpenBSD category; --> I really hope an IPSEC guru can enlighten me on the following.. Using: Linux Kernel 2.6.4 using kernel level ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 07:55 AM
Jansen
 
Posts: n/a
Default IPSEC VPN ISAKMPD Conflicting Address Ranges

I really hope an IPSEC guru can enlighten me on the following..

Using:

Linux Kernel 2.6.4 using kernel level ipsec
ISAKMPD as the IKE daemon
Small office routers running on NET A & B


Topology as follows:


Network A Network B
192.168.0.0/24 192.168.0.0/24
--- ---
router with public IP router with public IP
--- ---
| |
| |
| |
| dA' NET |
-----------------------------------------
|
|
|
---
router with public IP
---
|
Network C
10.0.0.0/25


Situation.

The router on network C is running linux kernel 2.6.4 with ipsec and
ISAKMPD for IKE. This box is used as a VPN concentrator. The problem,
illustrated in the diagram is fairly apparent - Both networks A and B
have the same address range, and for reasons beyond my control I
cannot re-number either. Both tunnels also need to be on
simultaneously. I have googled till exaustion with no return. The
closest I get to an example is a double NAT solution, that doesn't
really map across. I was thinking that a solution could be to
translate the Network A and B subnets to unique networks. using
POSTROUTING and PREROUTING iptable chains. The problem is that ipsec
on 2.6 does create user level interfaces (I can't see them) so I can't
use iptables to translate and then route via the ipsec interface.

2.6 seems to attach the tunnel directly to the machine, which you then
bind to any local interface.

I'm all out of ideas. HELP!!!


Any comments suggestions or alternatives solutions welcome....
Thanks

Jansen
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 02-18-2008, 07:55 AM
Riddler
 
Posts: n/a
Default Re: IPSEC VPN ISAKMPD Conflicting Address Ranges

Jansen wrote:

> I really hope an IPSEC guru can enlighten me on the following..
>
> Using:
>
> Linux Kernel 2.6.4 using kernel level ipsec
> ISAKMPD as the IKE daemon
> Small office routers running on NET A & B
>
>
> Topology as follows:
>
>
> Network A Network B
> 192.168.0.0/24 192.168.0.0/24
> --- ---
> router with public IP router with public IP
> --- ---
> | |
> | |
> | |
> | dA' NET |
> -----------------------------------------
> |
> |
> |
> ---
> router with public IP
> ---
> |
> Network C
> 10.0.0.0/25
>
>
> Situation.
>
> The router on network C is running linux kernel 2.6.4 with ipsec and
> ISAKMPD for IKE. This box is used as a VPN concentrator. The problem,
> illustrated in the diagram is fairly apparent - Both networks A and B
> have the same address range, and for reasons beyond my control I
> cannot re-number either. Both tunnels also need to be on
> simultaneously. I have googled till exaustion with no return. The
> closest I get to an example is a double NAT solution, that doesn't
> really map across. I was thinking that a solution could be to
> translate the Network A and B subnets to unique networks. using
> POSTROUTING and PREROUTING iptable chains. The problem is that ipsec
> on 2.6 does create user level interfaces (I can't see them) so I can't
> use iptables to translate and then route via the ipsec interface.
>
> 2.6 seems to attach the tunnel directly to the machine, which you then
> bind to any local interface.
>
> I'm all out of ideas. HELP!!!
>
>
> Any comments suggestions or alternatives solutions welcome....
> Thanks
>
> Jansen


unless netA and B are underused enough to have unique host on each segment,
ie: 192.168.0.51 only on netA, in which case you can assign static routes
on the netC router, I believe your going to have to nat netA or B at the
respective gateway.

put a case together on time and maintenance to make this work, you just
might make the 'reasons beyond my control' to be insignificant compared to
the benefit.

-riddler
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:15 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com