Linux Netfilter discussions
 help / color / mirror / Atom feed
* IPSec Transport Mode
@ 2004-07-07 13:35 Arnst, Rainer
  2004-07-07 13:53 ` Antony Stone
  0 siblings, 1 reply; 13+ messages in thread
From: Arnst, Rainer @ 2004-07-07 13:35 UTC (permalink / raw)
  To: NetFilter Mailling List

Hello,

I have a question regarding IPSec in Transport Mode and IPTables. I must
admitted my knowledge concerning IPSec is quite limited and so far what
I have heard about IPSec's transport and tunnel mode is not really clear
to me.

Setup is like this:

The Firewall (iptables - ipcop) has a fixed IP, the Client (MS Windows
XP) has a dynamic IP. IPSec Server is a Windows 2003 Server Box.

IPSec-Client (Internet) --> Firewall --> IPSec Server (internal)

Usually, as far as I understand, transport mode is not an option here
because of NAT being performed by the "Firewall"/Gateway.

Using MS NAT-T works fine, but we want to switch to something non-MS
soon (hopefully real soon). So it's not really an option.

With this Setup, is there anything that can be done with IPTables to
make the transport mode work w/o NAT-T?

Any comments are very appreciated.

Regards,
Rainer Arnst



^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2004-07-09 16:51 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-07-07 13:35 IPSec Transport Mode Arnst, Rainer
2004-07-07 13:53 ` Antony Stone
2004-07-07 14:21   ` Arnst, Rainer
2004-07-07 20:54     ` Antony Stone
2004-07-07 21:11       ` Sven Schuster
2004-07-07 21:42         ` Antony Stone
2004-07-07 23:53           ` Cedric Blancher
2004-07-08 12:00       ` Rainer Arnst
2004-07-09 15:38       ` Rainer Arnst
2004-07-09 16:13         ` Cedric Blancher
2004-07-09 16:25           ` Rainer Arnst
2004-07-09 16:51             ` ming fu
2004-07-07 14:32   ` listuser

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox