From mboxrd@z Thu Jan 1 00:00:00 1970 From: Nigel Metheringham Subject: Re: NAT and MTU issues Date: Mon, 22 Sep 2003 10:53:05 +0100 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1064224385.6070.8.camel@angua.localnet> References: <1063985328.28941.37.camel@angua.localnet> <1064084662.28506.42.camel@tux.rsn.bth.se> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1064084662.28506.42.camel@tux.rsn.bth.se> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Martin Josefsson Cc: Netfilter On Sat, 2003-09-20 at 20:04, Martin Josefsson wrote: > Gah, I hoped we had fixed all these problems. Getting all the > corner-cases right isn't as easy as one thinks when we perform multiple > translations. :-) > Is the NAT-rules on the machine that has the tunnel? If they are that > might explain a thing or two since the code looks correct for the case > where the packets pass through and another machine down the pipe sends > the icmp message back. Yes - all of this is on one machine. One interface has the effective listening port on it, another interface of the same box has the ipsec0 interface layered on top. Nigel. -- [ Nigel Metheringham Nigel.Metheringham@InTechnology.co.uk ] [ - Comments in this message are my own and not ITO opinion/policy - ]