ipsec and NAT

From: nkrall (nkrall_at_reflex.at)
Date: 02/19/04


Date: Thu, 19 Feb 2004 16:59:27 GMT

I have the following configuration:

clients 192.168.0.10:192.168.0.20 --- IPsec --> [ 192.168.0.1 gateway
-> NAT ] -----> internet

I can ping from the clients to the gateway,
from the gateway to the internet but
I CANNOT ping from the clients to the internet

ip_forward is enabled and iptable's policies are all set to ACCEPT to
make sure nothing is blocked

Thanks for your hints in advance.

Nikolaus

Here is my configuration:

Client:
conn wireless
        left=%any
        right=192.168.0.1
        rightsubnet=192.168.0.0/255.255.255.0
        rightca="C=AT,S=Vienna,CN=Name CA,Email=ca@name.at"
        network=auto
        auto=start
        disablearrivalcheck=no
        pfs=yes

Server:

config setup
         interfaces="ipsec0=eth1"
         klipsdebug=none
         plutodebug=none
         plutoload=%search
         plutostart=%search
         uniqueids=yes

conn %default
         keyingtries=1
         compress=yes
         disablearrivalcheck=no
         authby=rsasig
         leftrsasigkey=%cert
         rightrsasigkey=%cert

conn wireless
         right=%any
         left=192.168.0.1
         leftsubnet=192.168.0.0/255.255.255.0
         leftcert=gateway.pem
         auto=add
         pfs=yes

Routing table:
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use
Iface
192.168.0.10 192.168.0.10 255.255.255.255 UGH 0 0 0
ipsec0
192.168.0.0 * 255.255.255.0 U 0 0 0
eth1
192.168.0.0 * 255.255.255.0 U 0 0 0
ipsec0
123.145.165.0 * 255.255.255.0 U 0 0 0
eth0
default gateway_name 0.0.0.0 UG 0 0 0
eth0



Relevant Pages

  • Re: ICS isnt working??
    ... >I set up my computer as the gateway to the internet. ... >my computer and the other clients. ... and enable each client's network connection. ...
    (microsoft.public.windowsxp.network_web)
  • Joining Networks over the Internet with a Gateway to Gateway VPN - Loose Internet Browsing
    ... remote VPN clients. ... Gateway properly (all you know is that they can't use the ... >My Configuration: ... >can navigate in the Internet without problems. ...
    (microsoft.public.isa)
  • Re: Routing Problem
    ... Checked gateway on client is 132.149.2.75? ... This is my lan configuration.. ... On that time i can able to access the internet through mozilla. ... It gives "Connection timed Out" ...
    (comp.os.linux.security)
  • RE: Win2008 TSGateway adn XP Clients across Internet - [WP]
    ... by default gateway value I do mean what you have written. ... Please check that the default gateway value of the connection is not ... clients see while making a connection. ... Vista clients had no issues connecting internally or across the internet. ...
    (microsoft.public.windows.terminal_services)
  • RE: Win2008 TSGateway adn XP Clients across Internet - [WP]
    ... by default gateway value I do mean what you have written. ... Please check that the default gateway value of the connection is not ... clients see while making a connection. ... Vista clients had no issues connecting internally or across the internet. ...
    (microsoft.public.windows.terminal_services)