All of lore.kernel.org
 help / color / mirror / Atom feed
* PREROUTING, DNAT and IPSEC
@ 2005-04-18 10:53 danci
  2005-04-18 18:15 ` Taylor, Grant
  0 siblings, 1 reply; 2+ messages in thread
From: danci @ 2005-04-18 10:53 UTC (permalink / raw)
  To: netfilter

Hi!

I have three networks which are connected via IPSEC. One of them is 
'primary' - that means it is used for all incoming stuff (mail, web, ...), 
the other are 'remote'.

I need to allow some clients to connect to specific hosts inside of those 
networks - two TCP connections in each network.

Since I'd like to keep things centralised and network performance is not a 
huge issue, I was going to do a PREROUTING DNAT for those connection, 
using unique listening ports and DNAT-ing them to three internal IPs - one 
of them is in the 'primary' network, the other two are on the 'remote' 
networks.

While this works fine for the IP in the 'primary' network, it doesn't work 
for the other two. I guess it has something to do with IPSEC, but I can't 
figure it out.

Any ideas?

  Danilo

PS: The 'primary' IPSEC server is SuSE 9.1 with 2.6.5 kernel and 
freeswan-2.04_1.5.4 installed - it has no ipsec0 interface. The other 
IPSEC machines have older distibtutions, kernel and freeswan (1.91_0.9.1 
in one case).


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: PREROUTING, DNAT and IPSEC
  2005-04-18 10:53 PREROUTING, DNAT and IPSEC danci
@ 2005-04-18 18:15 ` Taylor, Grant
  0 siblings, 0 replies; 2+ messages in thread
From: Taylor, Grant @ 2005-04-18 18:15 UTC (permalink / raw)
  To: danci; +Cc: netfilter

Danilo could we get an example network layout including IPs and subnets and information on what your IPSec structure looks like as well as a desired traffic setup?



Grant. . . .


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2005-04-18 18:15 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-04-18 10:53 PREROUTING, DNAT and IPSEC danci
2005-04-18 18:15 ` Taylor, Grant

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.