On Wed, Aug 30, 2006 at 06:49:43PM +0200, Stefan Sczekalla-Waldschmidt wrote: > Hi, > > I had a subnet 192.168.110.0 to subnet 10.11.12.0 IPSEC Tunnel running > fine. > > Now the owner of the remote end of the vpn-tunnel asks if I can change > vpn-config and do Nat to 172.3.4.0 because he has some trouble routing > packets from my 192.168.110.0 network. > > I don't hav any problems to change the vpn-config to fit his needs, but > is there a way to nat at my incoming(LAN)if so, that the packets gets > natted ( masqueraded ) before they enter the tunnel ?
This is a painful proposition, and has been discussed before; did you read the archives? (You are not exactly the first to ask, you know...) Joachim