Re: IPSEC/NAT issues

2002-10-18 Thread Matthew Zahorik
On Fri, 18 Oct 2002, Andrew P. Lentvorski wrote: > You cannot NAT an IPSEC packet. NAT rewrites the IP headers and the > packet will get rejected when it reaches the other IPSEC node. Not exactly true. I use a Windows Nortel Contivity client behind NAT just fine. If you're using an AH associat

Re: IPsec and dynamically assigned IPs

2002-05-17 Thread Matthew Zahorik
On Fri, 17 May 2002, Barry Irwin wrote: > B [client] - {internet} - [vpngw] - [server] It would be a tunnel like B. The "[vpngw]" on the client side is software running on the client. The "[vpngw]" on the other side is a contivity switch. I'm trying to reach servers on the other side of the c

IPsec and dynamically assigned IPs

2002-05-16 Thread Matthew Zahorik
All: I am unclear regarding spdadd arguments and my VPN setup. I'm attempting to replace Nortel's Contivity Extranet Client on Windows with a racoon/ipsec solution. I'm unsure if this is a "tunnel" or "transport" connection. I contact a fixed server at 205.173.93.x. This is a contivit