Create hq additional vpn profile on the vm :

conn comms1
left=90.90.90.90
leftsubnet=192.168.0.0/16
rightid=@commshq.networks.ww
right=217.33.177.219
rightsubnet=172.16.30.0/24
authby=secret
ikelifetime=1h
keylife=24h
keyingtries=3
rekey=yes
auto=start
esp=3des-md5-96
pfs=yes

Create comms2 additional vpn profile on the vm :

conn comms2
left=90.90.90.90
leftsubnet=172.16.30.0/24
right=216.12.12.12
rightsubnet=192.168.49.0/24
type=tunnel
authby=secret
auth=esp
esp=3des-md5-96
ikelifetime=1h
keylife=24h
keyingtries=3
pfs=yes
rekey=yes
auto=start
dpdaction=restart
dpddelay=15
dpdtimeout=30

Added additional vpn on hq router :

ip access-list extended VPN
remark LAN_TO_LAN
permit ip 172.16.30.0 0.0.0.255 192.168.0.0 0.0.255.255

Added additional vpn on comms2 router :

ip access-list extended VPN
remark LAN_TO_LAN
permit ip 192.168.49.0 0.0.0.255 172.16.30.0 0.0.0.255

Added additional rule to VM on the FORWARD chain to allow traffic
from 192.168.0.0 to 172.16.30.0 :

sudo iptables -I FORWARD 7 -s 192.168.0.0/255.255.0.0 -d 172.16.30.0/255.255.255.0 -j ACCEPT
!
Added additional rule to VM on the FORWARD chain to allow traffic
from
172.16.30.0 to
192.168.0.0 :

sudo iptables -I FORWARD 7 -s 172.16.30.0/255.255.255.0 -d 192.168.0.0/255.255.0.0 -j ACCEPT