You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

StrongSwan IPSec配置问题:限制rightsubnet后客户端公网IP未走服务端的解决方案咨询

StrongSwan IPSec配置问题:限制rightsubnet后客户端公网IP未走服务端的解决方案咨询

Hey there! Let's break down what's happening and fix your config to match your needs.

First, the root cause: When you changed your client's rightsubnet from 0.0.0.0/0 to 10.100.100.2/24, you told the IPSec tunnel to only handle traffic destined for that specific VPN client subnet. All other traffic—like your curl https://checkip.amazonaws.com request—now bypasses the tunnel and uses your client's local internet connection, which is why you see the client's public IP instead of the server's 103.x.x.x.

It sounds like you want two things:

  • Keep VPN traffic restricted to the 10.100.100.2/24 client subnet (so clients can only communicate with each other over VPN)
  • Have all of your clients' public internet traffic route through the server's public IP (so checkip.amazonaws.com returns your server's 103.x.x.x address)

Here's the correct setup to make this work:

Server Config (/etc/ipsec.conf)

We'll configure the server to accept VPN connections from your client subnet, forward public traffic via NAT, and use firewall rules to enforce access restrictions:

conn %default
    ikelifetime=60m
    keylife=20m
    rekeymargin=3m
    keyingtries=1
    keyexchange=ikev2
    authby=secret

conn client-vpn
    left=103.x.x.x
    leftsubnet=0.0.0.0/0  # Allows clients to route public traffic through the server
    leftauth=psk
    right=%any
    rightsubnet=10.100.100.0/24  # Defines your client subnet
    rightauth=psk
    auto=add

Server Network Setup

You need to enable IP forwarding and set up NAT masquerading to let clients use the server's public IP for internet access:

# Enable IP forwarding temporarily
echo 1 > /proc/sys/net/ipv4/ip_forward

# Make it permanent (edit /etc/sysctl.conf and set net.ipv4.ip_forward=1)
sysctl -p /etc/sysctl.conf

# Set up NAT masquerading (replace eth0 with your server's public network interface)
iptables -t nat -A POSTROUTING -s 10.100.100.0/24 -o eth0 -j MASQUERADE

# Save iptables rules (use iptables-persistent to keep them after reboot)
apt install iptables-persistent
netfilter-persistent save

Server Firewall Rules (Enforce Access Restrictions)

To limit clients to only accessing the VPN subnet and public internet, add these iptables rules:

# Allow clients to communicate with each other
iptables -A FORWARD -s 10.100.100.0/24 -d 10.100.100.0/24 -j ACCEPT

# Allow clients to access public internet via the server
iptables -A FORWARD -s 10.100.100.0/24 -o eth0 -j ACCEPT

# Block all other traffic from clients
iptables -A FORWARD -s 10.100.100.0/24 -j DROP

Client Config (/etc/ipsec.conf)

On each Ubuntu client, set rightsubnet to 0.0.0.0/0 to route all traffic (VPN and public) through the tunnel. The server's firewall will handle restricting access to only the allowed destinations:

conn %default
    ikelifetime=60m
    keylife=20m
    rekeymargin=3m
    keyingtries=1
    keyexchange=ikev2
    authby=secret

conn server-vpn
    left=%defaultroute
    leftsubnet=0.0.0.0/0
    leftauth=psk
    right=103.x.x.x
    rightsubnet=0.0.0.0/0
    rightauth=psk
    auto=start

Why This Works

  • The client's rightsubnet=0.0.0.0/0 ensures all traffic (including public internet) goes through the IPSec tunnel.
  • The server's firewall rules restrict clients to only accessing the 10.100.100.2/24 subnet and public internet, fulfilling your "limit rightsubnet" requirement without breaking public traffic routing.
  • NAT masquerading makes the server's public IP appear as the source for all client internet traffic.

After updating the configs, restart StrongSwan on both server and clients:

ipsec restart

Now when you run curl https://checkip.amazonaws.com from a client, it should return your server's 103.x.x.x IP, and clients will only be able to communicate with each other over the VPN.

备注:内容来源于stack exchange,提问作者kramnitsuj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 11:04:33