StrongSwan IPSec配置问题:限制rightsubnet后客户端公网IP未走服务端的解决方案咨询
Hey there! Let's break down what's happening and fix your config to match your needs.
First, the root cause: When you changed your client's rightsubnet from 0.0.0.0/0 to 10.100.100.2/24, you told the IPSec tunnel to only handle traffic destined for that specific VPN client subnet. All other traffic—like your curl https://checkip.amazonaws.com request—now bypasses the tunnel and uses your client's local internet connection, which is why you see the client's public IP instead of the server's 103.x.x.x.
It sounds like you want two things:
- Keep VPN traffic restricted to the 10.100.100.2/24 client subnet (so clients can only communicate with each other over VPN)
- Have all of your clients' public internet traffic route through the server's public IP (so
checkip.amazonaws.comreturns your server's 103.x.x.x address)
Here's the correct setup to make this work:
Server Config (/etc/ipsec.conf)
We'll configure the server to accept VPN connections from your client subnet, forward public traffic via NAT, and use firewall rules to enforce access restrictions:
conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev2 authby=secret conn client-vpn left=103.x.x.x leftsubnet=0.0.0.0/0 # Allows clients to route public traffic through the server leftauth=psk right=%any rightsubnet=10.100.100.0/24 # Defines your client subnet rightauth=psk auto=add
Server Network Setup
You need to enable IP forwarding and set up NAT masquerading to let clients use the server's public IP for internet access:
# Enable IP forwarding temporarily echo 1 > /proc/sys/net/ipv4/ip_forward # Make it permanent (edit /etc/sysctl.conf and set net.ipv4.ip_forward=1) sysctl -p /etc/sysctl.conf # Set up NAT masquerading (replace eth0 with your server's public network interface) iptables -t nat -A POSTROUTING -s 10.100.100.0/24 -o eth0 -j MASQUERADE # Save iptables rules (use iptables-persistent to keep them after reboot) apt install iptables-persistent netfilter-persistent save
Server Firewall Rules (Enforce Access Restrictions)
To limit clients to only accessing the VPN subnet and public internet, add these iptables rules:
# Allow clients to communicate with each other iptables -A FORWARD -s 10.100.100.0/24 -d 10.100.100.0/24 -j ACCEPT # Allow clients to access public internet via the server iptables -A FORWARD -s 10.100.100.0/24 -o eth0 -j ACCEPT # Block all other traffic from clients iptables -A FORWARD -s 10.100.100.0/24 -j DROP
Client Config (/etc/ipsec.conf)
On each Ubuntu client, set rightsubnet to 0.0.0.0/0 to route all traffic (VPN and public) through the tunnel. The server's firewall will handle restricting access to only the allowed destinations:
conn %default ikelifetime=60m keylife=20m rekeymargin=3m keyingtries=1 keyexchange=ikev2 authby=secret conn server-vpn left=%defaultroute leftsubnet=0.0.0.0/0 leftauth=psk right=103.x.x.x rightsubnet=0.0.0.0/0 rightauth=psk auto=start
Why This Works
- The client's
rightsubnet=0.0.0.0/0ensures all traffic (including public internet) goes through the IPSec tunnel. - The server's firewall rules restrict clients to only accessing the 10.100.100.2/24 subnet and public internet, fulfilling your "limit rightsubnet" requirement without breaking public traffic routing.
- NAT masquerading makes the server's public IP appear as the source for all client internet traffic.
After updating the configs, restart StrongSwan on both server and clients:
ipsec restart
Now when you run curl https://checkip.amazonaws.com from a client, it should return your server's 103.x.x.x IP, and clients will only be able to communicate with each other over the VPN.
备注:内容来源于stack exchange,提问作者kramnitsuj

