vanhu <va...@freebsd.org> writes: 'Lut Yvan,
> Another way to have this feature is to implement what we call "NAT > before VPN": you can configure your kernel (or do it for specific NAT > rules if you want to do a more flexible implementation) to do NAT > process before doing IPsec stuff. I've used it last week on a 8.0.2 F200. The major drawback is that an existing nat ruleset must be adapted (nomap rules for vpn networks that dont need nat) and that it can cause issues when activated (a reverse proxy located on a machine behind a bidirectionnal map woes when nat before vpn is activated, that's why I have to setup another box for natted vpns...) > OpenBSD's way of doing things seems interesting while reading very > quickly your link, I'll have to take some more time to really see > exactly what they are doing..... I agree with Ermal that duplicating nat information in pf and isakmpd is suboptimal and probably error-prone, but it seems to me that it's less intrusive than altering the ip stack. -- Suffit d'être suffisamment nombreux et tu feras moins le malin. Voter con est une chose, s'en vanter en est une autre... Vous êtes grotesques et dangereux. -+- Rocou In GNU - Le quantitatif supléra-t-il le qualitatif ? -+- _______________________________________________ freebsd-net@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"