Re: [SLUG] Why does IPsec cause NAT to fail?

From: Ian C. Blenke (icblenke@nks.net)
Date: Wed Jun 11 2003 - 15:00:44 EDT


On Wednesday 11 June 2003 12:49, Vanessa May wrote:
> Hi,
>
> I've just been a lurker for awhile, but now I have a question and I'm
> hoping someone can help. Trying to create a VPN server using Free Swan on
> a RH firewall for XP clients. When I turn on IPsec the internal clients can
> no longer get to the internet. Is there something I need to do with IPsec
> or NAT?

Also, more in-tune with your question, if you are trying to run IPSEC
internally to your network, you might try the "opportunistic" IPSEC support
of the latest version of Freeswan. Add a few keys to DNS, and viola, instant
IPSEC on your LAN.

If you're having problems terminating endpoints internally and then NATting
out the unencrypted packets, I'd have a look at your routing rules and
iptables filters.

-- 
- Ian C. Blenke <icblenke@nks.net>

(This message bound by the following: http://www.nks.net/email_disclaimer.html)



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 16:27:47 EDT