Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-09 Thread Vince Hoffman
ort 500 nat on $ext_if from $int_net to any -> $ext_addr1 Havent tried checkpoint though. Vince -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Mok Sent: 07 April 2005 17:15 To: freebsd-net@freebsd.org Subject: FreeBSD Firewall + NAT Traversal + IPs

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-09 Thread John Mok
ED] On Behalf Of John Mok Sent: 07 April 2005 17:15 To: freebsd-net@freebsd.org Subject: FreeBSD Firewall + NAT Traversal + IPsec Hi, I'm new to FreeBSD. Is it possible make a FreeBSD box with firewall + NAT, such that client PC(s) from the NATed internal network could connect to a VPN gat

RE: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-09 Thread Vince
L PROTECTED] On Behalf Of John Mok > Sent: 07 April 2005 17:15 > To: freebsd-net@freebsd.org > Subject: FreeBSD Firewall + NAT Traversal + IPsec > > Hi, > > I'm new to FreeBSD. Is it possible make a FreeBSD box with > firewall + NAT, such that client PC(s) from the

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread John Mok
The problem is that some visitors might need to connect to the home VPN gateway(s) from my work office. Thus, we could not decide which VPN gateway solution they use. On the other hand, what is the status of FreeBSD on the support of NAT-T? Would it be supported in FreeBSD in later issues, e.g.

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread Tom Skeren
John Mok wrote: Dear Tom, Thank you for your quick reply. I would like to know more on the issue. To my understanding, since the source address of the IP packet from the client would be modified on the NAT, normally it would fail AH check on the IPsec VPN gateway, or the FreeBSD NAT has built-in

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread Bjoern A. Zeeb
On Fri, 8 Apr 2005, John Mok wrote: Hi, > Thank you for your quick reply. > > I would like to know more on the issue. To my understanding, since the > source address of the IP packet from the client would be modified on the > NAT, normally it would fail AH check on the IPsec VPN gateway, or the >

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread John Mok
Dear Tom, Thank you for your quick reply. I would like to know more on the issue. To my understanding, since the source address of the IP packet from the client would be modified on the NAT, normally it would fail AH check on the IPsec VPN gateway, or the FreeBSD NAT has built-in compliance with

Re: FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread Tom Skeren
John Mok wrote: Hi, I'm new to FreeBSD. Is it possible make a FreeBSD box with firewall + NAT, such that client PC(s) from the NATed internal network could connect to a VPN gateway on the Internet :- client PC - FreeBSD Firewall + NAT Internet IPsec VPN gateway 192.168.x.x/16

FreeBSD Firewall + NAT Traversal + IPsec

2005-04-07 Thread John Mok
Hi, I'm new to FreeBSD. Is it possible make a FreeBSD box with firewall + NAT, such that client PC(s) from the NATed internal network could connect to a VPN gateway on the Internet :- client PC - FreeBSD Firewall + NAT Internet IPsec VPN gateway 192.168.x.x/16