[Openswan Users] L2TP/IPsec with double NAT

Jacco de Leeuw jacco2 at dds.nl
Fri Aug 12 22:09:16 CEST 2005


Stefano Pazzaglia wrote:

> Ok for protoport 17/1701 but what about Paul Wouters' suggestion? What I 
> have to put in virtual_private?

I did not remember Paul's e-mail. You wrote that your client is behind
a NAT router on a 37.xxx.xxx.0/21 subnet.

In that case it should be something like:
virtual_private=%v4:10.0.0.0/8,%v4:172.16.0.0/12,%v4:192.168.0.0/16,%v4:37.xxx.xxx.0/21,%v4:!192.168.0.0/24 


But I wonder why you are using a 37.x.x.x subnet for a NATed subnet.
It appears to be IANA reserved address space.

Jacco
-- 
Jacco de Leeuw                         mailto:jacco2 at dds.nl
Zaandam, The Netherlands           http://www.jacco2.dds.nl


More information about the Users mailing list