From mboxrd@z Thu Jan 1 00:00:00 1970 From: "dimitri borjac" Subject: iptables and SPI... Date: Wed, 22 Oct 2003 16:44:51 +0000 Sender: netfilter-devel-admin@lists.netfilter.org Message-ID: Mime-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1; format=flowed Return-path: To: netfilter-devel@lists.netfilter.org Errors-To: netfilter-devel-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Unsubscribe: , List-Archive: List-Id: netfilter-devel.vger.kernel.org Hi! i sent this question to the user list but maybe you would have more precise answers ... I'd like to know if it's possible to use the current version of iptables in order to NAT different VPN established between different NATted hosts and 1 remote gateway (the same gateway for all of them) ? Such a NAT would be made by watching both addresses, ports and SPIs... In other words : is it possible for iptables to go and check the SPI field in the ESP Header of the IPsec packet in ESP tunnel mode ? Hope i make me clear enough :) Thanks in advance ! Dimo _________________________________________________________________ MSN Messenger 6 http://g.msn.fr/FR1001/866 : ajoutez une image à votre pseudo pour dialoguer avec vos amis