Re: [CentOS] ipsec nat issue

2012-10-13 Thread Steve Clark
Never mind. I got it to work. I already had the ping going when I added the iptables SNAT rule, conntracking or route caching made it not work. I stopped the ping for a minute or so then restarted it and it worked and did the SNATing as I expected. On 10/13/2012 06:04 PM, Steve Clark wrote: > He

[CentOS] ipsec nat issue

2012-10-13 Thread Steve Clark
Hello, I have the following setup on linux 2.6.32... CentOS 6.x : ipsec tunnel eth0-10.255.3.254/25 - eth1-pub add1 <-> eth1-pub add2 - eth0-10.255.5.254/25 I am trying to SNAT remote private address 10.255.5.128/25 packets when they come out of the ipsec tunnel to make it appear like it was fro