Re: IPSec VPN & NATD (problem with alias_address vs redirect_address)

From: Stephen J. Bevan (stephen_at_dino.dnsalias.com)
Date: 11/22/03

  • Next message: Odhiambo Washington: "Installing apache2 on FreeBSD 5.1-REL"
    Date: Fri, 21 Nov 2003 22:35:54 -0800
    To: cjclark@alum.mit.edu
    
    

    Crist J. Clark writes:
    > Two different ESP end points behind many-to-one NAT connected to a
    > single ESP end point on the other side of the NAT? I'd be very curious
    > to get the documentation on how they are cheating to get that to work.

    A cheat is to use the sequence number in the ESP header to matchup the
    SPI on the inbound packet with the SPI on the outbound packet. This
    only works if the NAT box doesn't have multiple ESP connections all
    starting at the same time (otherwise there would obviously be no way
    to tell which outbound SPI a packet with ESP sequence number 1 should
    match). A workaround for that is to have the NAT box delay the IKE
    negotiation for one connection if another one has not completed and
    resulted in traffic being sent. It all has a bit of a bad smell to it
    but then NAT isn't exactly sweet smelling either.
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Odhiambo Washington: "Installing apache2 on FreeBSD 5.1-REL"

    Relevant Pages

    • Re: IPSEC from behind dumb NAT. How?
      ... IPsec VPN to not work if your NAT router does not support IPsec passthrough. ... I believe ESP also gives you the option of authenticating ...
      (microsoft.public.win2000.security)
    • Re: IPSec VPN & NATD (problem with alias_address vs redirect_address)
      ... > single ESP end point on the other side of the NAT? ... A cheat is to use the sequence number in the ESP header to matchup the ... SPI on the inbound packet with the SPI on the outbound packet. ...
      (freebsd-net)
    • Re: VPN-1 Secureremote pass-through on a PIX 506
      ... I understand the ISAKMP Nat traversal command but not sure on the ... >>I've got hold of a second hand PIX 506. ... >You do not need to configure anything to "let through" AH or ESP, ...
      (comp.dcom.sys.cisco)
    • Re: how can i redirect traffic temporarily to another IP?
      ... > The DNAT HOWTO is your fwend. ... > esp section ... Make sure the packets are accepted on the INPUT or ... NAT is Network Address ...
      (comp.os.linux.security)
    • Re: Linksys: NAT better than SPI?
      ... > I get the impression not all SPI implementations are created equal. ... The TCP FIN scanning is able to pass undetected through most ... > personal firewalls, packet filters, and scan detection programs. ... You are always running NAT, ...
      (comp.security.firewalls)