From mboxrd@z Thu Jan 1 00:00:00 1970 From: "dimitri borjac" Subject: iptables and SPI Date: Wed, 22 Oct 2003 13:26:59 +0000 Sender: netfilter-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" Content-Transfer-Encoding: 7bit To: netfilter@lists.netfilter.org sorry to disturb all of you once more... and thank you Julian for your first answer... but actually i think i wasn't clear enough in my last mail : is it possible to use iptables in order to NAT different VPN established between different NATted hosts and 1 remote gateway (the same gateway for all of them) ? Such a NAT would be made by watching both addresses, ports and SPIs... In other words : is it possible for iptables to go and check the SPI field in the ESP Header of the IPsec packet in ESP tunnel mode ? Hope i make me more clear this time :) Thanks in advance ! Dimo _________________________________________________________________ Hotmail : un compte GRATUIT qui vous suit partout et tout le temps ! http://g.msn.fr/FR1000/9493