tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: reverse processing order: NAT, IPsec ?



On Fri, Jun 12, 2009 at 04:36:23PM +0200, Hans Rosenfeld wrote:
> 
> Could you use IPsec in transport mode and use a gif tunnel over that?
> IIRC I read somewhere that this is functionally the same as IPsec tunnel
> mode, and it would allow you to use NAT on the gif interface.

Probably, but you'll have no luck getting it configured how the peer
expects if IKE is in use -- racoon has no idea how to do this.

-- 
Thor Lancelot Simon                                        
tls%rek.tjls.com@localhost
    "Even experienced UNIX users occasionally enter rm *.* at the UNIX
     prompt only to realize too late that they have removed the wrong
     segment of the directory structure." - Microsoft WSS whitepaper


Home | Main Index | Thread Index | Old Index