Unix Technical Forum

Re: pf & isakmpd: NAT through encryption interface?

This is a discussion on Re: pf & isakmpd: NAT through encryption interface? within the lucky.openbsd.misc forums, part of the OpenBSD category; --> > Hi, Roy: > > Roy Morris wrote: > > > > Yes it does work! I guess I ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:25 AM
Roy Morris
 
Posts: n/a
Default Re: pf & isakmpd: NAT through encryption interface?

> Hi, Roy:
>
> Roy Morris wrote:
> >
> > Yes it does work! I guess I better hold on to these two

> boxes I have. Seems
> > they are the only ones that do! lol
> >
> > I have
> > A. clients on each end behind a vpn/pf box
> > B. enc0 binat from internal client to public IP of other side client
> > C. /etc/hostname.if alias for the binat IP
> > D. isakmpd.conf uses public IP (A) for phase 1, and (B

> internal client nat) for
> > phase 2

>
> I've had a closer look at this...
>
> In my case, the other peer expects a private IP on my
> internal network.
> Your directions involve an alias. Do I need this alias?
>
> Can I not just nat on the encryption interface like so?
>
> nat on $enc_if from $internal_ip to $remote_internal_ip ->
> $private_nat_address?
>
> This is really confusing me.
>
> -Stephen-

Have you actually tried it?
nat on enc0 from $ip_to_be_changed to $peer_net -> $nat_ip

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:31 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com