mirror of
				https://github.com/strongswan/strongswan.git
				synced 2025-11-04 00:00:51 -05:00 
			
		
		
		
	edited description
This commit is contained in:
		
							parent
							
								
									a771dc33d0
								
							
						
					
					
						commit
						4336a1c611
					
				@ -1,5 +1,5 @@
 | 
			
		||||
The hosts <b>alice</b>, <b>venus</b>, <b>carol</b>, and <b>dave</b> set up tunnel connections
 | 
			
		||||
to gateway <b>moon</b> in a spoke-to-hub fashion. Each host requests a <b>virtual IP</b> 
 | 
			
		||||
to gateway <b>moon</b> in a <b>hub-and-spoke</b> fashion. Each host requests a <b>virtual IP</b> 
 | 
			
		||||
with the <b>leftsourceip=%config</b> parameter. Gateway <b>moon</b> assigns virtual
 | 
			
		||||
IP addresses from a pool named <b>extpool</b> [10.3.0.1..10.3.255.254] to hosts connecting
 | 
			
		||||
to the <b>eth0</b> (PH_IP_MOON) interface and virtual IP addresses from a pool named <b>intpool</b>
 | 
			
		||||
@ -9,6 +9,6 @@ respectively, whereas <b>alice</b> and <b>venus</b> get <b>10.4.0.1</b> and <b>1
 | 
			
		||||
respectively.
 | 
			
		||||
<p> 
 | 
			
		||||
By defining the composite IPsec SA: <b>rightsubnet=10.3.0.0/16,10.4.0.0/16</b>, each of the four
 | 
			
		||||
hosts can securely reach any other host via the central hub <b>moon</b>. This is
 | 
			
		||||
spokes can securely reach any other spoke via the central hub <b>moon</b>. This is
 | 
			
		||||
demonstrated by <b>alice</b> and <b>dave</b> pinging the assigned virtual IP addresses
 | 
			
		||||
of <b>carol</b> and <b>venus</b>.
 | 
			
		||||
 | 
			
		||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user