I have 3 routers A, B and C connected in OSPF. Each has a valid routing table:
Code: Select all
K <----> (internet) <---> A <---> B <---> C
Polices on router A:
Code: Select all
# PEER TUNNEL SRC-ADDRESS DST-ADDRESS PROTOCOL ACTION LEVEL PH2-COUNT
0 T * 0.0.0.0/0 172.20.1.0/24 all
1 DA peer1 yes 0.0.0.0/0 172.20.1.5/32 all encrypt unique 1
2 T 0.0.0.0/0 172.30.1.0/24 all
3 DA peer1 yes 0.0.0.0/0 172.30.1.0/24 all encrypt unique 1
#3 is router C
Both templates have different group, but both peers get IP from the same subnet 172.20.1.0/24 by Mode Configs. So computer K gets as you see 172.20.1.5 and router C gets 172.20.1.21. 172.30.1.0/24 is local subnet of router C.