您好
"ali-ali1": 172.16.201.0/24===172.16.201.175<172.16.201.175>[47.99.52.21]---172.16.207.253...120.79.196.199<120.79.196.199>[10.10.99.137]===10.10.99.0/24; unrouted; eroute owner: #0
"ali1-ali": 10.10.99.0/24===10.10.99.137<10.10.99.137>[120.79.196.199]---10.10.99.253...47.99.52.21<47.99.52.21>[172.16.201.175]===172.16.201.0/24; unrouted; eroute owner: #0
000
[root@izbp160egsopdnsji0py3iz ipsec]# ipsec verify
Verifying installed system and configuration files
Version check and ipsec on-path [OK]
Libreswan 3.23 (netkey) on 3.10.0-514.26.2.el7.x86_64
Checking for IPsec support in kernel [OK]
NETKEY: Testing XFRM related proc values
ICMP default/send_redirects [OK]
ICMP default/accept_redirects [OK]
XFRM larval drop [OK]
Pluto ipsec.conf syntax [OK]
Two or more interfaces found, checking IP forwarding [OK]
Checking rp_filter [OK]
Checking that pluto is running [OK]
Pluto listening for IKE on udp 500 [OK]
Pluto listening for IKE/NAT-T on udp 4500 [OK]
Pluto ipsec.secret syntax [OK]
Checking 'ip' command [OK]
Checking 'iptables' command [OK]
Checking 'prelink' command does not interfere with FIPS [OK]
Checking for obsolete ipsec.conf options [OK]
我安装了openswan,这两个内网网段通,我该如何做安全组的配置的呢?