Subject: IPSec/VPN missing something(ip_forwarding)
To: None <current-users@NetBSD.org>
From: Steve Pribyl <spribyl@peel.com>
List: current-users
Date: 10/12/2007 14:55:18
I have set up a VPN using these instructions.
http://www.netbsd.org/docs/network/ipsec/rasvpn.html
and have been able to make a connection and ssh into the vpn node.

However, I unable to contact other nodes on the network.

Things of interest.
NetBsd 4 rc 2 (VPN Node)
Runing pf on vpn node.
Fedora 7 remote node
vpn node = 192.168.0.10(wm2) and 192.168.0.1(carp1)
internal node= 192.168.0.100 - gw 192.168.0.1
remote node = 192.168.0.200

tcpdump on internal node while ping from vpn node.
09:54:00.883379 IP 192.168.0.10 > 192.168.0.100: ICMP echo request, id
55127, seq 5, length 64
09:54:00.883387 IP 192.168.0.100 > 192.168.0.10: ICMP echo reply, id
55127, seq 5, length 64

tcpdump on internal node while ping from remote node.
09:54:13.216800 IP 192.168.0.200 > 192.168.0.100: ICMP echo request, id
34102, seq 1, length 64


I also see this
09:56:16.197056 arp who-has 192.168.0.200 tell 192.168.0.100

What did I miss?
Thanks
-- 
Steve Pribyl
Infrastructure Practitioner