Project

General

Profile

Issue #773

The PLAN --- Can we get this done with strongSwan ?

Added by Matthew Ferry almost 11 years ago. Updated almost 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
configuration
Affected version:
5.2.1
Resolution:
No change required

Description

Attached is a PDF.

I need to "Many Moons" out in the field to connect back to a central "SUN".
The moons will have two NICs. One will connect to their existing network. Obtain an IP from their DHCP server.

This is the connection MOON will use to make an outbound connection back to SUN.
Moon most of the time will be behind a NAT firewall.

I don't want to make changes to the firewall. This is why I want Moon to make an "Outbound" connection back to SUN.

The second NIC on the Moon(s) will attach to a management switch.
This switch will have the server(s) I need to have access to back at my location with SUN.

On myside, SUN is behind a NAT firewall, but its mine. I can open what ports are needed with no problem.

On the MOON side / Concerns ---
I want make sure they can't just plug a station in to the management switch and get an IP.
With an IP they would be on the management network.

I am not sure how many IPs i need on a Moon location.
Or I dont know how many locations I am going to have in a few years.

I am not sure how strongSwan does stuff like IPs or allocations, etc.

Please review and point me in the right direction.

Thanks Matt

ssh_management_vpn.pdf (35.5 KB) ssh_management_vpn.pdf Matthew Ferry, 22.11.2014 15:19

History

#1 Updated by Matthew Ferry almost 11 years ago

UPDATE ---

The SUN location has a static IP.
The MOON locations will not have a static IP.

Thanks,

#2 Updated by Tobias Brunner almost 11 years ago

  • Status changed from New to Feedback
  • Priority changed from Urgent to Normal

I'd say this is probably possible to do, but your description doesn't specify what subnets are used where. Such hub and spoke setups could get tricky if multiple locations use the same or overlapping subnets.

Anyway, this is not really the right platform to ask such questions. Please use our Users mailing list or the IRC channel.

#3 Updated by Matthew Ferry almost 11 years ago

I have subscribed to your USER mailing list.

#4 Updated by Tobias Brunner almost 11 years ago

  • Status changed from Feedback to Closed
  • Resolution set to No change required