expanded ikev2/ip-two-pools-db to a spoke-to-hub network using virtual IP addresses
This commit is contained in:
@@ -1,9 +1,14 @@
|
||||
The hosts <b>alice</b> and <b>carol</b> set up a tunnel connection each to gateway <b>moon</b>.
|
||||
Both hosts request a <b>virtual IP</b> via the IKEv2 configuration payload by using the
|
||||
<b>leftsourceip=%config</b> parameter. Gateway <b>moon</b> assigns virtual IP
|
||||
addresses from a pool named <b>extpool</b> [10.3.0.1..10.3.255.254] to hosts connecting
|
||||
The hosts <b>alice</b>, <b>venus</b>, <b>carol</b>, and <b>dave</b> set up tunnel connections
|
||||
to gateway <b>moon</b> in a spoke-to-hub fashion. Each host requests a <b>virtual IP</b>
|
||||
with the <b>leftsourceip=%config</b> parameter. Gateway <b>moon</b> assigns virtual
|
||||
IP addresses from a pool named <b>extpool</b> [10.3.0.1..10.3.255.254] to hosts connecting
|
||||
to the <b>eth0</b> (PH_IP_MOON) interface and virtual IP addresses from a pool named <b>intpool</b>
|
||||
[10.4.0.1..10.4.255.254] to hosts connecting to the <b>eth1</b> (PH_IP_MOON1) interface.
|
||||
<p>
|
||||
Thus <b>carol</b> is assigned <b>PH_IP_CAROL1</b> whereas <b>alice</b> gets <b>10.4.0.1</b> and
|
||||
both ping the gateway <b>moon</b>.
|
||||
Thus <b>carol</b> and <b>dave</b> are assigned <b>PH_IP_CAROL1</b> and <b>PH_IP_DAVE1</b>,
|
||||
respectively, whereas <b>alice</b> and <b>venus</b> get <b>10.4.0.1</b> and <b>10.4.0.2</b>,
|
||||
respectively.
|
||||
<p>
|
||||
By defining the composite IPsec SA: <b>rightsubnet=10.3.0.0/16,10.4.0.0/16</b>, each of the four
|
||||
hosts can securely reach any other host via the central hub <b>moon</b>. This is
|
||||
demonstrated by <b>alice</b> and <b>dave</b> pinging the assigned virtual IP addresses
|
||||
of <b>carol</b> and <b>venus</b>.
|
||||
|
||||
Reference in New Issue
Block a user