Re: IPNAT with IPSEC

This is a discussion on Re: IPNAT with IPSEC within the IPFilter forums, part of the System Security and Security Related category; On Wed, Jun 25, 2003 at 07:28:40PM +1000, Carl Morley wrote: > > Private IP | (A) | | | | (B) | | Private &...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-26-2003
Guido van Rooij
 
Posts: n/a
Default Re: IPNAT with IPSEC

On Wed, Jun 25, 2003 at 07:28:40PM +1000, Carl Morley wrote:
>
> Private IP | (A) | | | | (B) | | Private
> IP
> subnets at----| FIREWALL |-----| INTERNET |-----| FIREWALL |---| subnet
> at
> company (A) | | | | | | | company
> (B)
>
> Firewall (B) is expecting all IPSEC traffic to be coming from the public
> IP address on Firewall (A), as tunnelled private IP subnet
> 10.99.99.0/30.
>
> I am trying to NAT all the internal subnets at (A) to 10.99.99.1. But
> it does not seem to work whichever way I try.
>
> Questions:
>
> 1. On which interface should I alias the 10.99.99.1 IP on Firewall (A).
> Choices seem to be internal (fxp2), external (fxp1), loopback (lo0) or
> some gif0 combination. Any other suggestions?


alias? You mean NAT. NAT rewrites source addresses on outgoing interfaces.
This means that you should do IPSEC on a different system after the ipfilter
host.

-Guido
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:28 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0