Re: AH and ESP nat-ing

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thursday 2010-05-06 18:55, ratheesh k wrote:

>On Thu, May 6, 2010 at 8:36 PM, Jan Engelhardt <jengelh@xxxxxxxxxx> wrote:
>> On Thursday 2010-05-06 16:08, ratheesh k wrote:
>>
>>>I googled and found that  AH protocol pkt cannot be NATed  , And ESP
>>>protocol pkt  NATing wont work in  some use cases .
>>>
>>>Is this problem is solved in newer kernels ?
>>
>> This is not a kernel problem.
>>
>>>Is there any ALG for nating this packets  ?
>>
>> No, it's cryptographically signed, so any modification would be visible.
>>
>
>
>I am able to establish pptp/ipsec connection  from my client machine
>,connected to a  Router (broadcom ) . it doesnt have any  debug
>terminal .
>Could you tell me , how this is possible  ?

PPTP and ESP can be udptunneled, see google et al.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux