[Openswan Users] Clients/Server Behind NAT

farajian amin amin_o_city at yahoo.com
Wed Mar 17 03:52:33 EDT 2010


Dear All,

 I have two network topology, and because in both cases NAT is used , i do not know how to config openswan servers and clients. 
I have already have subnet-to-subnet config with x509 for authentication. and I use KLIPS with NAT-T patches.
My openswan Servers and clients have two LAN ports.

===============================================================================
The first topology is : (client behind NAT)

(Client Subnet 10.10.10.0/24) 
 \     Openswan           NAT- 
      Internet      Openswan   (Server Subnet)  
   ...  Client  --------- device  =================== Server ... 192.168.1.0/24 
     192.168.0.2        /     \  
             
    /    
\
                      
/       \
                  
/      192.168.1.1   
             192.168.0.1/24   X.X.X.X           Y.Y.Y.Y 




================================================================================
The second topology is: (server and client behind NAT - and i want both sub nets see each others)
 10.10.10.0/24 192.168.0.2                                                                        192.168.1.2 20.20.20.0/24
                    \   /                                                                                                                      \   /
   
    client              NAT- 
      Internet       
NAT-          Server
       openswan  --------- device  =================== device
------ openswan                                                           
                          /     \  
             
     /    
\  
                        
/       \
                  
/   192.168.1.1   
              192.168.0.1/24   X.X.X.X             Y.Y.Y.Y  
                   
                   
                 
     


================================================================================

Can anybody help me in a template config for both client and server sides in both network topologies.
I really don't know if i need any configuration in NAT devices.. 

Thanks in Advance.

Amin Farajian



      


More information about the Users mailing list