[OT] Was: ESP does not hit the nat table

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi all,

Thanks for the reply, I know I messed up the iptables syntax - I did not include the chain…

 

My main problem however was that ESP packets do not hit the nat table, but it does traverse mangle/filter table. Is this normal? I am mainly looking at SNAT/MASQUERADING ipsec traffic and I am not able to find any documentation on doing this, especially since there is no point in putting a "iptables -t nat -A PREROUTING -p 50 -j SNAT --to-source <me>". -p 50 means ESP as you can already guess.

Am I missing something here? How do I masquerade ipsec traffic? (assuming my ipsec-VPN client/server is fine with it…)

 

Thanks!

Ashwin

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~            \|/ ____ \|/ 
Ashwin Kashyap                                   @~/ ,. \~@ 
Member Technical Staff                          /_( \__/ )_\ 
Thomson - Corporate Research                       \__U_/ 
                                                Don't Panic!

 


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux