Re: Problems with NAT on gif interface for VPN

From: Jeremie Le Hen (jeremie_at_le-hen.org)
Date: 10/29/04

  • Next message: Aaron Nichols: "Re: Problems with NAT on gif interface for VPN"
    Date: Fri, 29 Oct 2004 16:14:11 +0200
    To: Aaron Nichols <adnichols@gmail.com>
    
    

    > Rather than a "problem" with ipfw however, I think I've got a
    > fundamental problem with how to do this. If I understand correctly, in
    > order for natd to "reverse" a divert rule (translate the destination
    > IP back to the original IP on return traffic) the packet has to come
    > through the same interface it was originally seen by natd on - is this
    > correct?
    >
    > For whatever reason I still seem to be unable to use gif0 for this
    > purpose, which seems to be the closest thing to an "ipsec interface"
    > available (I'm beginning to think it's nowhere near as useful as enc0
    > on OpenBSD). Thus, I'm stuck translating packets when they either
    > enter the LAN interface or leave the WAN, the former seems the best
    > option.

    IIRC, I read somewhere this is precisely the reason why enc(4) was
    written.

    -- 
    Jeremie Le Hen
    jeremie@le-hen.org
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Aaron Nichols: "Re: Problems with NAT on gif interface for VPN"

    Relevant Pages

    • Re: CAsyncSocket and performance issues
      ... The Nagel Algorithm is one reason the OP can't depend on reading 8 bytes and getting all ... feeding data in to me, I saturated at 1300 packets/min, with an average packet size of 80. ... ever call to Receivedraws on a buffer. ... >There's extra overhead in making extra copies. ...
      (microsoft.public.vc.mfc)
    • Re: Asynchronous vs. Synchronous
      ... fundamentally async. ... The reason is that each system transmitter runs with an unsynchronized ... > to involve character-based transmission with start/stop bits. ... If you think of an entire Ethernet PDU (packet) as a single very wide ...
      (comp.networks.noctools.d)
    • Re: IPTables rejecting packets that should be let through???
      ... > packet from the log entry that IPTables generates? ... This is incoming, not outgoing packet. ... couse connection to be terminated. ... happened was that Postfix closed the connection, and for whatever reason ...
      (Fedora)
    • Re: REQ - taco seasoning mix
      ... I reason I could buy MOST of the ingredients listed on the packet and ... Prev by Date: ...
      (rec.food.cooking)
    • Re: REQ - taco seasoning mix
      ... > [taco seasoning] ... I reason I could buy MOST of the ingredients listed on the packet and ... Prev by Date: ...
      (rec.food.cooking)