<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=big5">
<META content="MSHTML 6.00.2800.1400" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial color=#0000ff size=2>
<DIV><FONT face=Arial color=#0000ff size=2>Paul,</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>I probably need your help
too.</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>My problem is very similar to the one
in the previous conversation.</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>I am using RedHat ES 3 with the
backport. I do found that I have the esp4 module. What I did is I
compiled the userland program using the packing/redhat/openswan.26spec. My
problem is weird, I can connect without any problem if both server
and client is direct connected to the internet. Once my client is
behind the NAT router, the server stay in STATE_MAIN_R2 forever waiting for MI3
to come. Any hint ?</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>My ipsec.conf file (with OE disabled)
is like this</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2>version 2.0</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>config
setup<BR>
interfaces=%defaultroute<BR>
plutodebug=no<BR>
uniqueids=yes<BR>
nat_traversal=yes</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>conn
%default<BR>
keyingtries=1<BR>
compress=yes<BR>
disablearrivalcheck=no<BR>
authby=rsasig<BR>
esp=3des<BR>
leftupdown="/etc/ipsec_updown.sh"<BR>
leftcert=vpn.pem<BR>
left=%defaultroute<BR>
leftrsasigkey=%cert<BR>
right=%any<BR>
rightrsasigkey=%cert<BR>
rightca=%same</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>conn
rwarrior<BR>
leftsubnet=10.0.0.0/8<BR>
auto=add<BR> pfs=yes</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>My ipsec.secrets file is like
this</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2>: RSA vpn.pem</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff size=2></FONT> </DIV>
<DIV><FONT face=Arial color=#0000ff size=2>Thanks,</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff
size=2>Stephen.</FONT></DIV></FONT></DIV></BODY></HTML>