You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Nebula管理的USG Flex 100与数据中心Kerio路由器/StrongSwan服务器间配置含多子网的Site-to-Site IPSec隧道

如何在Nebula管理的USG Flex 100与数据中心Kerio路由器/StrongSwan服务器间配置含多子网的Site-to-Site IPSec隧道

Hey Dave, let's figure out how to get your multi-subnet site-to-site tunnel up and running between your Nebula-managed USG Flex 100 and the datacenter (either Kerio router or StrongSwan server). Since you mentioned Nebula won't let you add two remote subnets directly, we can work around this by handling the multiple subnets on the datacenter side—here's how to do both options:

方案一:对接数据中心Kerio路由器

This is straightforward if you prefer using the Kerio interface over command-line config:

  • Step 1: Configure the IPSec tunnel on Nebula Console

    • Log into your Nebula account, navigate to your USG Flex 100 device, then go to VPN > Site-to-Site IPSec
    • Create a new tunnel, fill in your Kerio router's public IP as the remote gateway
    • Set local subnet to your office network: 10.5.1.0/24
    • For remote subnet, just enter one of the datacenter ranges first—say 10.1.4.0/24 (we'll add the other on Kerio's side)
    • Match encryption settings on both sides: use AES-256-GCM, SHA-256, and DH Group 14 for best security, plus a shared pre-shared key (make sure it's the same on Kerio)
    • Save and enable the tunnel
  • Step 2: Update Kerio to handle both subnets

    • Log into your Kerio admin interface, go to VPN > IPSec and create a matching tunnel: use the same public IP, encryption suite, and pre-shared key as Nebula
    • For local subnets on Kerio, add both datacenter ranges: 10.1.4.0/24 and 10.8.0.0/23
    • Set remote subnet to your office's 10.5.1.0/24
    • Add a static route to route office traffic through the tunnel: go to Routing > Static Routes, add a route for 10.5.1.0/24 pointing to the IPSec tunnel interface
    • Double-check your Kerio firewall rules to allow bidirectional traffic between all three subnets
    • Test connectivity: ping a device in 10.1.4.0/24 and 10.8.0.0/23 from your office, and vice versa

方案二:对接数据中心StrongSwan Debian服务器

StrongSwan gives you more flexibility for multi-subnet setups, and it's easy to configure via command line:

  • Step 1: Set up the tunnel on Nebula Console

    • Same as the Kerio setup: create a new Site-to-Site IPSec tunnel, use your Debian server's public IP as the remote gateway
    • Local subnet: 10.5.1.0/24, remote subnet can be either 10.1.4.0/24 or 10.8.0.0/23 (StrongSwan will cover both)
    • Match encryption settings and pre-shared key with what you'll set on StrongSwan
    • Save and enable the tunnel
  • Step 2: Configure StrongSwan on Debian

    • First, make sure StrongSwan is installed: run sudo apt install strongswan strongswan-pki if it's not already
    • Edit the IPSec config file /etc/ipsec.conf and add this connection block:
      conn nebula-office-tunnel
          left=%any
          leftsubnet=10.1.4.0/24,10.8.0.0/23  # List both datacenter subnets here
          right=YOUR_USG_FLEX_PUBLIC_IP
          rightsubnet=10.5.1.0/24
          authby=secret
          ike=aes256gcm16-prfsha256-ecp384!
          esp=aes256gcm16-ecp384!
          keyexchange=ikev2
          auto=start
      
    • Add the pre-shared key to /etc/ipsec.secrets:
      YOUR_USG_FLEX_PUBLIC_IP : PSK "your-secure-shared-secret"
      
    • Enable IP forwarding on Debian: edit /etc/sysctl.conf, uncomment or add net.ipv4.ip_forward=1, then run sudo sysctl -p to apply
    • Set up iptables rules to allow IPSec traffic and subnet forwarding:
      # Allow IPSec ports
      sudo iptables -A INPUT -p udp --dport 500 -j ACCEPT
      sudo iptables -A INPUT -p udp --dport 4500 -j ACCEPT
      
      # Allow bidirectional traffic between subnets
      sudo iptables -A FORWARD -s 10.5.1.0/24 -d 10.1.4.0/24 -j ACCEPT
      sudo iptables -A FORWARD -s 10.5.1.0/24 -d 10.8.0.0/23 -j ACCEPT
      sudo iptables -A FORWARD -s 10.1.4.0/24 -d 10.5.1.0/24 -j ACCEPT
      sudo iptables -A FORWARD -s 10.8.0.0/23 -d 10.5.1.0/24 -j ACCEPT
      
      # Masquerade traffic to avoid routing issues
      sudo iptables -t nat -A POSTROUTING -o eth0 -s 10.1.4.0/24 -d 10.5.1.0/24 -j MASQUERADE
      sudo iptables -t nat -A POSTROUTING -o eth0 -s 10.8.0.0/23 -d 10.5.1.0/24 -j MASQUERADE
      
    • Restart StrongSwan to apply changes: sudo systemctl restart strongswan-starter
    • Test connectivity: ping devices across all subnets to confirm traffic flows both ways

Quick Troubleshooting Tip

Before jumping into the workarounds, double-check if your Nebula console version allows comma-separated remote subnets (e.g., 10.1.4.0/24,10.8.0.0/23). Some newer versions support this directly, which would let you skip the datacenter-side extra config entirely.

备注:内容来源于stack exchange,提问作者Dave

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 10:59:31