[Openswan Users] FW: Do vpn gateways work _behind_ NAT?

Frank Wilson frank.wilson at sidonis.com
Mon Apr 27 04:43:11 EDT 2009


I'm resending this because it looks like my last message got messed up:

Do openswan vpn gateways work when they are behind a NAT?
E.g.

	{"peas", 192.168.1.2/24}
			|
{192.168.1.1/24, "rice", 20.20.20.20/24}
			|
		{Internet}
			|
{192.168.2.1/24, "mash", 20.20.20.21/24} 
			|
	{"bangers", 192.168.2.2/24}

(for each NAT, the public interface/ip is on the right)


If "rice" and "mash" provide NAT for their respective networks, can "peas"
and "bangers" connect via an openswan ipsec tunnel? Can they put the rest of
their respective subnets on the new vpn?

I'm having real problems setting up a similar vpn, and I'm wondering whether
I have totally misunderstood the capabilities of NAT-T.

Thanks for your help,

Frank



More information about the Users mailing list