Re: IPSEC + natd + IPFW

2001-03-06 Thread Lars Eggert
At 1:43 PM +1100 3/7/01, Stephen Cimarelli wrote: > On 07-Mar-01 Lars Eggert wrote: >> Do you use IPsec tunnel mode, or IPsec transport mode + gif tunnels to do >> the tunneling? > > Well this is where it starts to get funny, I have 2 HOWTOs > Both HOWTO's use gif tunnels, but > the FreeBSD IPsec

Re: IPSEC + natd + IPFW

2001-03-06 Thread Stephen Cimarelli
On 07-Mar-01 Lars Eggert wrote: > Stephen Cimarelli wrote: >> I have managed to get IPsec+gif tunelling to work but am having trouble >> setting >> up firewal rules, it seem that recieved ESP packets pass through the >> firewall >> rule set twice and hit my natd divert rules. > > Do you use IPs

Re: IPSEC + natd + IPFW

2001-03-06 Thread Lars Eggert
Stephen Cimarelli wrote: > I have managed to get IPsec+gif tunelling to work but am having trouble setting > up firewal rules, it seem that recieved ESP packets pass through the firewall > rule set twice and hit my natd divert rules. Do you use IPsec tunnel mode, or IPsec transport mode + gif t

IPSEC + natd + IPFW

2001-03-06 Thread Stephen Cimarelli
Hi All I have managed to get IPsec+gif tunelling to work but am having trouble setting up firewal rules, it seem that recieved ESP packets pass through the firewall rule set twice and hit my natd divert rules. Toget around this I had to add a rule like 00110 and 00115 1 150 20400 cou