Re: [Shorewall-users] IPsec with 1:1 NAT

2025-05-19 Thread Tuomo Soini via Shorewall-users
On Mon, 19 May 2025 06:39:06 + Reinhard Vicinus via Shorewall-users wrote: > I am trying to get an 1:1 NAT configured prior to sending the > packages into an IPsec tunnel, but as far as I can tell the NAT is > never applied and the packages also never get into the tunnel. 1:1 nat and IPsec a

Re: [Shorewall-users] IPsec with 1:1 NAT

2025-05-19 Thread Tuomo Soini via Shorewall-users
On Mon, 19 May 2025 06:39:06 + Reinhard Vicinus via Shorewall-users > I am confused, why I do not see packages with source 10.191.2.229 > going out eth0.1903 in the tcpdump output and why the trace ends with > the nat:10.191.2.229:rule line. Has someone an idea what I am doing > wrong or how I

[Shorewall-users] IPsec with 1:1 NAT

2025-05-18 Thread Reinhard Vicinus via Shorewall-users
I am trying to get an 1:1 NAT configured prior to sending the packages into an IPsec tunnel, but as far as I can tell the NAT is never applied and the packages also never get into the tunnel. The IPsec tunnel configuration: conn rz2trz1   auto=route   closeaction=restart   esp=aes256-sha256-ecp