[Openswan Users] Rhel 3 with natt patch?

Paul Wouters paul at xelerance.com
Mon Sep 13 13:08:43 CEST 2004


On Mon, 13 Sep 2004, Nicole Hähnel wrote:

> Ok, I'll test it.
>
> And what's with the ipsec.conf?

> config setup
>    interfaces=%defaultroute
>    klipsdebug=none
>    plutodebug=none
>    nat_traversal=yes

You also want to add the appropriate virtual_private line there.
For example, if 192.168.0.0/24 is the office, you will want
something like:

 	virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,!%v4:192.168.0.0/24

> I only have to add "nat_traversal=yes" on the server behind the router?
> Or on the other side too?

Both sides need to have it enabled.

Paul


More information about the Users mailing list