NAT-T and openswan ?

From: Dave Harrison (David.Harrison_at_sensorynetworks.com)
Date: 09/02/04

  • Next message: Steve Mandelmore: "Re: Can't dial up"
    Date: Thu, 2 Sep 2004 13:54:04 +1000
    To: debian-user@lists.debian.org
    
    

    Hi all,

    I'm trying out NAT-T and I'm finding the following problem.

    I have a NAT firewall in between my VPN gateway [1] and another VPN endpoint
    box [2] (specifically and IPCop 1.3.0 box - it is such a box for ease of
    configuration at the remote end by the remote people).

      +-----+ +-----------+ +----+
      | 1 | <- switch --| Firewall | --switch-> | 2 |
      +-----+ +-----------+ +----+
    <-10.0.3.1
      10.0.2.2-> <-10.0.2.1
                                NAT
                              10.0.0.2-> <-10.0.0.3
                                                     10.0.1.1->

    Machine 1 is nat'd, while 2 is not (2 is simulting a remote end point).
    Machine 1 is running a 2.6 kernel with OpenSWan 2.1.5, machine 2 is
    running IPCop1.3.0 with SuperFreeSwan 1.99_kb2c

    What I'm seeing in terms of packet flow is they try to negotiate an SA,
    but get a no-proposal-chosen response from the remote end.

    The configs that I have for them are :

    config setup
        interfaces="..."
        nat_traversal=yes
        virtual_private=vnet:%all

    conn %default
        keyingtries=0

    conn test
        authby=secret
        left=10.0.2.2
        leftnexthop=%direct
        compress=no
        leftsubnet=10.0.3.0/24
        right=10.0.0.3
        rightsubnet=10.0.1.0/24
        rightnexthop=%direct
        auto=start

    Any help is appreciated. Cheers,
    Dave

    -- 
    Dave Harrison, Systems Administrator, Sensory Networks
        email:          David.Harrison@sensorynetworks.com
        phone:          [W] +61-2-8302-2700 
        fingerprint:    E29F 2D6A FA27 5B0B B429  F8D3 5318 22D6 E775 2241
    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Steve Mandelmore: "Re: Can't dial up"

    Relevant Pages

    • Re: [fw-wiz] VPN Gateway And Nat
      ... The configuration you describe is not supported in a Check Point enviroment, ... the VPN Gateway must always have a public IP address. ... > ClientSecuremote doesn't access the real IP Adress of the VPNGATEWAY, ... > Neither SOCIETE GENERALE nor any of its subsidiaries or affiliates shall ...
      (Firewall-Wizards)
    • Re: Remote Desktop Problem
      ... Here's the new configuration below...and when I try to change the Wan IP to ... Ethernet adapter Internal LAN: ... Connection-specific DNS Suffix. ... the firebox and then thru the Remote Desktop one day and the next day ...
      (microsoft.public.windows.server.sbs)
    • Joining Networks over the Internet with a Gateway to Gateway VPN - Loose Internet Browsing
      ... remote VPN clients. ... Gateway properly (all you know is that they can't use the ... >My Configuration: ... >can navigate in the Internet without problems. ...
      (microsoft.public.isa)
    • Problem joining Windows domain from remote VPN/PPTP box
      ... server OK with administrator rights (configured via Routing and Remote ... On client there exists static route for remote network that points to ... following information can help you troubleshoot your DNS configuration. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Anynet connection with different NetIDs
      ... OK for remote, but why for QAPPNLCL? ... configuration that does not work, have a coffee or whatever you want, ... Could you post the passthru command, ...
      (comp.sys.ibm.as400.misc)