Hi all, Thanks for the reply, I know I messed up the iptables syntax
- I did not include the chain… My main problem however was that ESP packets do not hit the
nat table, but it does traverse mangle/filter table. Is this normal? I am
mainly looking at SNAT/MASQUERADING ipsec traffic and I am not able to find any
documentation on doing this, especially since there is no point in putting a
"iptables -t nat -A PREROUTING -p 50 -j SNAT --to-source <me>".
-p 50 means ESP as you can already guess. Am I missing something here? How do I masquerade ipsec
traffic? (assuming my ipsec-VPN client/server is fine with it…) Thanks! Ashwin ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ \|/ ____ \|/ Ashwin Kashyap @~/ ,. \~@ Member Technical Staff /_( \__/ )_\ Thomson - Corporate Research \__U_/ Don't Panic! |