From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Brent Clark" Subject: RE: kernel 2.6 ipsec and DNAT Date: Mon, 13 Sep 2004 12:29:56 +0200 Sender: netfilter-bounces@lists.netfilter.org Message-ID: References: <1095068909.27900.953.camel@cluster> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1095068909.27900.953.camel@cluster> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" To: Javier Sanchez , netfilter@lists.netfilter.org >Hi all, >i have recently discovered on the list that more people is suffering the >nat problem with ipsec vpn tunnels on 2.6.x kernels, does anyone know if >its fixed on 2.6.8.1 ?? >The unique way i found to bypass the nat problem is using a proxy server >(squid), not the best solution but for now im able to surf the web .-) Hi all Sorry for my ignorance. But why would nat a vpn tunnel be a problem. Are there certain requirement for creating tunnel. Can the vpn server \ client be on the same box as the iptables gateway\router\firewall. If I remember from Anthony Stone (who seems to be missing in action, anyone know why) correctly, its best to not have any services running on fw. just something I was wondering. Kind Regards Brent Clark.