update readme
All checks were successful
CI / TruffleHog Secrets Scan (push) Successful in 7s
CI / Terraform Format & Validate (push) Successful in 9s

This commit is contained in:
Mauritz_Uphoff 2025-07-07 11:35:15 +02:00
parent 52ed9a868a
commit 4c8a6673cf
3 changed files with 9 additions and 15 deletions

View file

@ -93,6 +93,13 @@ ping 10.1.1.11
# ✅ Tests project-project routing via SNA transfer network # ✅ Tests project-project routing via SNA transfer network
``` ```
### 💻 From appliance02 (on-prem) to machine02 (cloud internal)
```bash
ping 10.1.2.11
# ✅ Tests project-project routing via SNA transfer network
```
### ❌ From machine01 (cloud) to appliance02 (VPN-disconnected) ### ❌ From machine01 (cloud) to appliance02 (VPN-disconnected)
If you remove the static route that directs 192.168.1.0/24 through appliance01: If you remove the static route that directs 192.168.1.0/24 through appliance01:

View file

@ -40,18 +40,5 @@ runcmd:
- sed -i '/^#\?net.ipv4.ip_forward\s*=/c\net.ipv4.ip_forward=1' /etc/sysctl.conf - sed -i '/^#\?net.ipv4.ip_forward\s*=/c\net.ipv4.ip_forward=1' /etc/sysctl.conf
- sysctl -p - sysctl -p
# Set up iptables rules - ipsec start
# - iptables -t nat -A POSTROUTING -s ${local_subnet} -d ${remote_subnet} -j ACCEPT - ipsec up net-net
# - iptables -t nat -A POSTROUTING -s ${remote_subnet} -d ${local_subnet} -j ACCEPT
# - iptables -t nat -A POSTROUTING -s ${local_subnet} ! -d ${local_subnet} -j MASQUERADE
# Accept IPsec traffic
# - iptables -A INPUT -p udp --dport 500 -j ACCEPT
# - iptables -A INPUT -p udp --dport 4500 -j ACCEPT
# - iptables -A INPUT -p esp -j ACCEPT
# - iptables -A FORWARD -s ${local_subnet} -d ${remote_subnet} -m policy --pol ipsec --dir out -j ACCEPT
# - iptables -A FORWARD -s ${remote_subnet} -d ${local_subnet} -m policy --pol ipsec --dir in -j ACCEPT
# Enable and start strongSwan
# - systemctl enable strongswan-starter
# - systemctl start strongswan-starter

Binary file not shown.

Before

Width:  |  Height:  |  Size: 252 KiB

After

Width:  |  Height:  |  Size: 222 KiB