[Openswan Users] GW doing SNAT+IPsec?? Multiple clients behind the same NAT (IPsec GW)?

J. Pedro Flor pedro.flor at gmail.com
Fri Jun 24 15:36:40 CEST 2005


Hello list,

GW doing SNAT+IPsec?? Multiple clients behind the same NAT (IPsec GW)?

i found some workarounds...

linux-2.6.11
iptables-1.3.1
patch-o-matic-ng-20050504
openswan-2.3.0
ipsec-tools-0.5.1

1) Patch the vanilla kernel with
 -ipsec-01-output-hooks.diff
 -ipsec-02-input-hooks.diff
 -ipsec-03-policy-lookup.diff
 -ipsec-04-policy-checks.diff
 -ipsec-05-iptablescompile.diff
from http://shorewall.net/pub/shorewall/contrib/IPSEC/2.6.11
(ipsec-03, 04 does not patch clean, then patch manually)

and policy (for ipsec) from patch-o-matic-ng

I think that's all.

For more details, check http://www.shorewall.net/IPSEC-2.6.html

--
                       J. Pedro Flor P.


More information about the Users mailing list