All of lore.kernel.org
 help / color / mirror / Atom feed
[parent not found: <200410160653.i9G6rmMc025506@nmibwkms1.nexusmgmt.com>]
[parent not found: <200410152203.i9FM3kMc029703@nmibwkms1.nexusmgmt.com>]
* IPSEC and NAT
@ 2004-10-15 18:00 Emiel Mols
  0 siblings, 0 replies; 7+ messages in thread
From: Emiel Mols @ 2004-10-15 18:00 UTC (permalink / raw)
  To: netfilter-devel

Hi,

 

I've managed to setup a host-to-net ipsec connection with a remote network
on a linux router using (ported) isakmpd and kernel 2.6.8.1. However, I want
to be able to 'share' this ipsec connection with the rest of the network,
but since no ipsecn virtual interface is created in the 2.6 kernels I can't
use ordinary SNAT/MASQUERADE targets in iptables: ipsec packets get
encrypted before entering the POSTROUTING table :(, so the source address of
the encapsulated packet can't be changed anymore. I've read
http://lists.netfilter.org/pipermail/netfilter-devel/2004-January/thread.htm
l#13879, but the supplied patch doesn't work very well.

 

Does anyone have any suggestions on how to get this working?

 

Thanks in advance,

 

Emiel

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2004-10-16 14:59 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <200410151800.i9FI09Mc018462@nmibwkms1.nexusmgmt.com>
2004-10-15 22:02 ` IPSEC and NAT John A. Sullivan III
2004-10-15 22:03   ` Emiel Mols
2004-10-16  1:18   ` Alexander Samad
     [not found] <200410160653.i9G6rmMc025506@nmibwkms1.nexusmgmt.com>
2004-10-16 14:59 ` John A. Sullivan III
     [not found] <200410152203.i9FM3kMc029703@nmibwkms1.nexusmgmt.com>
2004-10-16  2:09 ` John A. Sullivan III
2004-10-16  6:53   ` Emiel Mols
2004-10-15 18:00 Emiel Mols

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.