[Openswan Users] Forcing udp-encaps when not on a NAT'd connection?

Nate Carlson natecars at natecarlson.com
Thu Jun 10 10:49:06 CEST 2004


Hey all,

I'm wondering if there is a way to force Openswan to use UDP Encapsulation 
when you're not on a NAT'd connection. This would be useful, for example, 
when you've got a public IP address, but there is a firewall somewhere in 
the middle that blocks ESP.

If it's not something do-able right now, it'd be a nice feature to get
added, especially if it could be defined on a per-connection basis. This
is, of course, if it can be done without breaking anything.  :)  While I'm
dreaming, it'd also be nice to be able to tweak port numbers - IE, have
global options to listen on additional udp ports besides 500 and 4500, and
have per-connection options to use different ports.

------------------------------------------------------------------------
| nate carlson | natecars at natecarlson.com | http://www.natecarlson.com |
|       depriving some poor village of its idiot since 1981            |
------------------------------------------------------------------------


More information about the Users mailing list