如何在Nebula管理的USG Flex 100与数据中心Kerio路由器/StrongSwan服务器间配置含多子网的Site-to-Site IPSec隧道
Hey Dave, let's figure out how to get your multi-subnet site-to-site tunnel up and running between your Nebula-managed USG Flex 100 and the datacenter (either Kerio router or StrongSwan server). Since you mentioned Nebula won't let you add two remote subnets directly, we can work around this by handling the multiple subnets on the datacenter side—here's how to do both options:
方案一:对接数据中心Kerio路由器
This is straightforward if you prefer using the Kerio interface over command-line config:
Step 1: Configure the IPSec tunnel on Nebula Console
- Log into your Nebula account, navigate to your USG Flex 100 device, then go to VPN > Site-to-Site IPSec
- Create a new tunnel, fill in your Kerio router's public IP as the remote gateway
- Set local subnet to your office network:
10.5.1.0/24 - For remote subnet, just enter one of the datacenter ranges first—say
10.1.4.0/24(we'll add the other on Kerio's side) - Match encryption settings on both sides: use AES-256-GCM, SHA-256, and DH Group 14 for best security, plus a shared pre-shared key (make sure it's the same on Kerio)
- Save and enable the tunnel
Step 2: Update Kerio to handle both subnets
- Log into your Kerio admin interface, go to VPN > IPSec and create a matching tunnel: use the same public IP, encryption suite, and pre-shared key as Nebula
- For local subnets on Kerio, add both datacenter ranges:
10.1.4.0/24and10.8.0.0/23 - Set remote subnet to your office's
10.5.1.0/24 - Add a static route to route office traffic through the tunnel: go to Routing > Static Routes, add a route for
10.5.1.0/24pointing to the IPSec tunnel interface - Double-check your Kerio firewall rules to allow bidirectional traffic between all three subnets
- Test connectivity: ping a device in
10.1.4.0/24and10.8.0.0/23from your office, and vice versa
方案二:对接数据中心StrongSwan Debian服务器
StrongSwan gives you more flexibility for multi-subnet setups, and it's easy to configure via command line:
Step 1: Set up the tunnel on Nebula Console
- Same as the Kerio setup: create a new Site-to-Site IPSec tunnel, use your Debian server's public IP as the remote gateway
- Local subnet:
10.5.1.0/24, remote subnet can be either10.1.4.0/24or10.8.0.0/23(StrongSwan will cover both) - Match encryption settings and pre-shared key with what you'll set on StrongSwan
- Save and enable the tunnel
Step 2: Configure StrongSwan on Debian
- First, make sure StrongSwan is installed: run
sudo apt install strongswan strongswan-pkiif it's not already - Edit the IPSec config file
/etc/ipsec.confand add this connection block:conn nebula-office-tunnel left=%any leftsubnet=10.1.4.0/24,10.8.0.0/23 # List both datacenter subnets here right=YOUR_USG_FLEX_PUBLIC_IP rightsubnet=10.5.1.0/24 authby=secret ike=aes256gcm16-prfsha256-ecp384! esp=aes256gcm16-ecp384! keyexchange=ikev2 auto=start - Add the pre-shared key to
/etc/ipsec.secrets:YOUR_USG_FLEX_PUBLIC_IP : PSK "your-secure-shared-secret" - Enable IP forwarding on Debian: edit
/etc/sysctl.conf, uncomment or addnet.ipv4.ip_forward=1, then runsudo sysctl -pto apply - Set up iptables rules to allow IPSec traffic and subnet forwarding:
# Allow IPSec ports sudo iptables -A INPUT -p udp --dport 500 -j ACCEPT sudo iptables -A INPUT -p udp --dport 4500 -j ACCEPT # Allow bidirectional traffic between subnets sudo iptables -A FORWARD -s 10.5.1.0/24 -d 10.1.4.0/24 -j ACCEPT sudo iptables -A FORWARD -s 10.5.1.0/24 -d 10.8.0.0/23 -j ACCEPT sudo iptables -A FORWARD -s 10.1.4.0/24 -d 10.5.1.0/24 -j ACCEPT sudo iptables -A FORWARD -s 10.8.0.0/23 -d 10.5.1.0/24 -j ACCEPT # Masquerade traffic to avoid routing issues sudo iptables -t nat -A POSTROUTING -o eth0 -s 10.1.4.0/24 -d 10.5.1.0/24 -j MASQUERADE sudo iptables -t nat -A POSTROUTING -o eth0 -s 10.8.0.0/23 -d 10.5.1.0/24 -j MASQUERADE - Restart StrongSwan to apply changes:
sudo systemctl restart strongswan-starter - Test connectivity: ping devices across all subnets to confirm traffic flows both ways
- First, make sure StrongSwan is installed: run
Quick Troubleshooting Tip
Before jumping into the workarounds, double-check if your Nebula console version allows comma-separated remote subnets (e.g., 10.1.4.0/24,10.8.0.0/23). Some newer versions support this directly, which would let you skip the datacenter-side extra config entirely.
备注:内容来源于stack exchange,提问作者Dave

