Now that we have our first host-to-host tunnel running, we can attempt to set up a subnet‑to‑subnet tunnel, which you'll find to be just as easy. The following example connection, when installed and activated on both West and East, will create a VPN tunnel between the networks Sunrise and Sunset:
conn sunset-sunrise left=193.110.157.131 leftsubnet=193.111.228.0/24 right=205.150.200.209 rightsubnet=192.0.2.0/24 leftrsasigkey=0sAQ43A1.... rightrsasigkey=0sAQfP63.... auto=start
Remember that we are now abbreviating the key entries; in your file they will be the same as before, covering four lines. Also remember that to set up this new connection, you can edit the config file while Openswan is still running, and run the following command to activate it:
# ipsec auto --add sunset-sunrise
The eroute
command will now show two tunnels:
# ipsec eroute
5 193.110.157.131/32 -> 205.150.200.209/32 => [email protected] 0 193.111.228.0...