From: "Kristopher L. Bachtal" <kbachtal@gmail.com>
To: 'Mail List - Netfilter' <netfilter@vger.kernel.org>
Subject: IPSEC VPN Pass-Through/Nat-T Help Needed
Date: Mon, 22 Sep 2008 16:10:13 -0400 [thread overview]
Message-ID: <48D7FBA5.70402@gmail.com> (raw)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,
I have a Fedora Core 5 machine running kernel 2.6.20-1.2320 and
iptables/netfilter acting as a gateway/Nat for a private network to the
internet. I have several client machines (aprox. 10, Running Windows XP)
that are behind this router that need to create individual IPSec VPN
(Cisco IPSec Software Cleint)connections over the internet to a Cisco
VPN Concentrator (Diagram Below). I can only seem to get one client at a
time to work. If I try to start a second VPN connection from another
machine it connects to the VPN Concentrator but will not carry any data.
(i.e. Cant ping, traceroute, etc.) I'm thinking I need some type of
connection tracking kernel module for IPSec Connections (like
nf_conntrack_ftp but for Ipsec instead of FTP) but I cant find any
reference to one in the documentation or google searches that I have
done. Any help would be greatly appreciated.
Clients(10) --> Gateway/Nat ---> Internet ---> Remote Network
(Windows XP) (Fedora Core 5) (Cisco VPN Box)
Private IP Private IP / Public IP Public IP
Thank you,
Kristopher L. Bachtal
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFI1/ulG8acbTj+cSARAkkMAJwPUYm28gw5pSYogD6tZ+FZhjVVDACghRos
V4paWyVloiFRbSBBjFfT/A8=
=TNUn
-----END PGP SIGNATURE-----
next reply other threads:[~2008-09-22 20:10 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-09-22 20:10 Kristopher L. Bachtal [this message]
2008-09-23 3:56 ` IPSEC VPN Pass-Through/Nat-T Help Needed Anton V. Antonenko
2008-09-23 4:40 ` Kristopher L. Bachtal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=48D7FBA5.70402@gmail.com \
--to=kbachtal@gmail.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox