[Openswan Users] Problem with forceencaps

Martin Hicks mort at bork.org
Mon Apr 30 09:30:45 EDT 2007


On Mon, Apr 30, 2007 at 02:48:26PM +0200, steve.morard at epfl.ch wrote:
> I do have "nat_traversal=yes" turned on. I wonder if it's not the gateway to
> which I need to connect that doesn't support UDP encapsulation. Why would
> happen if it was the case and if I use "forceencaps=yes"?

Yes, it could be.  You need NAT traversal on both ends to be able to do
UDP encap.  I struggled with this at one point too.  There are no checks
in openswan to ensure that you have nat traversal enabled when you
specify forceencaps :-(

please always CC the list

mh

-- 
Martin Hicks || mort at bork.org || PGP/GnuPG: 0x4C7F2BEE
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
Url : http://lists.openswan.org/pipermail/users/attachments/20070430/3c3953d8/attachment.bin 


More information about the Users mailing list