[Openswan Users] nat-traversal configure

Michael H. Warfield mhw at WittsEnd.com
Fri Jun 5 15:10:21 EDT 2009


On Wed, 2009-06-03 at 17:35 +0800, chenyq wrote:
> hi ! 
> topology:
> left-vpn---nat----right-vpn

> nat-traversal configure :
 
> if i want to configure nat-traversal, it requires two condition
> nat-traversal=yes and leftid/rightid= ***  ?
 
> if i do not configure leftid/rightid ,how should i configure ? thank
> you !

	Simplify your life.  Use certificates and the DN's in the certificates.
Then it's "leftid=%fromcert" and "rightid=%fromcert".
 
> 2009-06-03 
> 
> ______________________________________________________________________

	Mike
-- 
Michael H. Warfield (AI4NB) | (770) 985-6132 |  mhw at WittsEnd.com
   /\/\|=mhw=|\/\/          | (678) 463-0932 |  http://www.wittsend.com/mhw/
   NIC whois: MHW9          | An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471        | possible worlds.  A pessimist is sure of it!

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 307 bytes
Desc: This is a digitally signed message part
Url : http://lists.openswan.org/pipermail/users/attachments/20090605/f3ffe36c/attachment.bin 


More information about the Users mailing list