RE: VPN between multiple LANs

"Tony Langdon (ATC)" <[email protected]> Thu, 27 Jan 2005 08:43:52 +1100
Newsgroups gmane.comp.encryption.cipe
Message-ID <61646882C848D81185530048546447F433C174@mel-exchange.atctraining.com.au>
> If you use the same IP for all cipe adapters, what do you route by?

I'm not sure I see the problem.  Routing is based on _destination_ IP
address (let's leave policy routing aside for the moment, though that isn't
an issue either in the real world), and all tunnels lead to different IPs on
the remote end.

Here's a real world example.  4 networks linked in total, 3 CIPE links
between each of the remote network and the local network.  In all cases, the
CIPE devices are using the same IP address.

I've added some comments

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use
Iface

Host routes to remote tunnel endpoints.
192.168.7.1     0.0.0.0         255.255.255.255 UH    0      0        0
cipcb2
10.200.200.2    0.0.0.0         255.255.255.255 UH    0      0        0
cipcb0
192.168.181.1   0.0.0.0         255.255.255.255 UH    0      0        0
cipcb1

Network routes for cipcb0
202.12.87.160   10.200.200.2    255.255.255.248 UG    0      0        0
cipcb0
202.12.87.152   10.200.200.2    255.255.255.248 UG    0      0        0
cipcb0

Local LAN routes
192.168.15.0    0.0.0.0         255.255.255.128 U     0      0        0 eth0
192.168.15.128  0.0.0.0         255.255.255.128 U     0      0        0 eth0

Network route for cipcb1
192.168.181.0   192.168.181.1   255.255.255.0   UG    0      0        0
cipcb1

Network route to ISP
211.28.37.0     0.0.0.0         255.255.255.0   U     0      0        0 eth1

Linux seems to setup an autoconfig route for some reason..
169.254.0.0     0.0.0.0         255.255.0.0     U     0      0        0 eth1

Network route for cipcb2
192.168.0.0     192.168.7.1     255.255.0.0     UG    0      0        0
cipcb2

Looopback
127.0.0.0       0.0.0.0         255.0.0.0       U     0      0        0 lo

Default route (Internet)
0.0.0.0         211.28.37.1     0.0.0.0         UG    0      0        0 eth1

Oh, and the interfaces...

OK, the first one is using an oddball address, but that's because it's
linked to a Windows host on the far end, which had to work that way, not
because I had routing issues on my end.

cipcb0    Link encap:IPIP Tunnel  HWaddr
          inet addr:10.200.200.1  P-t-P:10.200.200.2  Mask:255.255.255.255
          UP POINTOPOINT NOTRAILERS RUNNING NOARP  MTU:1442  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:4315 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:0 (0.0 b)  TX bytes:465732 (454.8 Kb)

The rest use the same IP as eth0

cipcb1    Link encap:IPIP Tunnel  HWaddr
          inet addr:192.168.15.1  P-t-P:192.168.181.1  Mask:255.255.255.255
          UP POINTOPOINT NOTRAILERS RUNNING NOARP  MTU:1442  Metric:1
          RX packets:155401 errors:1 dropped:0 overruns:0 frame:1
          TX packets:167960 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:12743584 (12.1 Mb)  TX bytes:22187936 (21.1 Mb)

cipcb2    Link encap:IPIP Tunnel  HWaddr
          inet addr:192.168.15.1  P-t-P:192.168.7.1  Mask:255.255.255.255
          UP POINTOPOINT NOTRAILERS RUNNING NOARP  MTU:1442  Metric:1
          RX packets:2716998 errors:1409 dropped:0 overruns:0 frame:1409
          TX packets:3038908 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:460282800 (438.9 Mb)  TX bytes:400079776 (381.5 Mb)

And for reference....

eth0      Link encap:Ethernet  HWaddr 00:E0:29:9D:BA:4F
          inet addr:192.168.15.1  Bcast:192.168.15.127  Mask:255.255.255.128
          inet6 addr: 2001:388:c027:1::1/64 Scope:Global
          inet6 addr: fe80::2e0:29ff:fe9d:ba4f/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:5209146 errors:0 dropped:0 overruns:0 frame:0
          TX packets:5225013 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:584746849 (557.6 Mb)  TX bytes:1748568057 (1667.5 Mb)
          Interrupt:9 Base address:0x9000

--
Message sent by the [email protected] mailing list.
Unsubscribe: mail [email protected], "unsubscribe cipe-l" in body
Other commands available with "help" in body to the same address.
CIPE info and list archive: <URL:http://sites.inka.de/~bigred/devel/cipe.html>