Networking Forums

Networking Forums > Computer Networking > Linux Networking > Linux kernel 2.4.x and IPSEC masquerade

Reply
Thread Tools Display Modes

Linux kernel 2.4.x and IPSEC masquerade

 
 
Olivier Roset
Guest
Posts: n/a

 
      05-31-2005, 12:58 PM
Hi.

First, sorry for my english, but it's not my first language.

My problem is this :

I have a router/firewall who is running on a x86 box under linux redhat
7.2, with kernel 2.4.19.
The router is doing traffic masquerade and nat.

Behind this router/firewall, I have a lot of pc stations running windows xp.

I want to run checkpoint VPN-1 on some of this machines to connect to a
VPN server somewhere on the internet.
This software can use ipsec/ike to connect to this VPN server.

How can i (simply or not) masquerade the IPSEC traffic on the
router/firewall ?

Do I have to upgrade my linux kernel or install a third party software
on the router/firewall ???


Thanks for your help.

Olivier.
 
Reply With Quote
 
 
 
 
Dam
Guest
Posts: n/a

 
      05-31-2005, 09:11 PM
Olivier Roset wrote:

> Hi.
>
> First, sorry for my english, but it's not my first language.
>
> My problem is this :
>
> I have a router/firewall who is running on a x86 box under linux redhat
> 7.2, with kernel 2.4.19.
> The router is doing traffic masquerade and nat.
>
> Behind this router/firewall, I have a lot of pc stations running windows
> xp.
>
> I want to run checkpoint VPN-1 on some of this machines to connect to a
> VPN server somewhere on the internet.
> This software can use ipsec/ike to connect to this VPN server.
>
> How can i (simply or not) masquerade the IPSEC traffic on the
> router/firewall ?
>
> Do I have to upgrade my linux kernel or install a third party software
> on the router/firewall ???
>
>
> Thanks for your help.
>
> Olivier.



L2TP is port 1701/udp *
IPSec ESP is IP *protocol* (not port) 50 *
IKE (IPsec's authentication protocol) is port 500/udp *
NAT-T is port 4500/udp

Damiano

 
Reply With Quote
 
Olivier Roset
Guest
Posts: n/a

 
      06-01-2005, 12:01 PM
Dam a écrit :
> Olivier Roset wrote:
>
>
>>Hi.
>>
>>First, sorry for my english, but it's not my first language.
>>
>>My problem is this :
>>
>>I have a router/firewall who is running on a x86 box under linux redhat
>>7.2, with kernel 2.4.19.
>>The router is doing traffic masquerade and nat.
>>
>>Behind this router/firewall, I have a lot of pc stations running windows
>>xp.
>>
>>I want to run checkpoint VPN-1 on some of this machines to connect to a
>>VPN server somewhere on the internet.
>>This software can use ipsec/ike to connect to this VPN server.
>>
>>How can i (simply or not) masquerade the IPSEC traffic on the
>>router/firewall ?
>>
>>Do I have to upgrade my linux kernel or install a third party software
>>on the router/firewall ???
>>
>>
>>Thanks for your help.
>>
>>Olivier.

>
>
>
> L2TP is port 1701/udp *
> IPSec ESP is IP *protocol* (not port) 50 *
> IKE (IPsec's authentication protocol) is port 500/udp *
> NAT-T is port 4500/udp


Thanks for your help but I already know that.
I think the 2.4.x kernel don't support the IPSec masquerading or NAT
traversal.
Is there a patch somewhere for kernel 2.4.x that allow IPSec masquerade
or NAT traversal ?

Olivier.
 
Reply With Quote
 
Tim Lingard
Guest
Posts: n/a

 
      06-11-2005, 09:54 PM
On Wed, 01 Jun 2005 14:01:04 +0200, Olivier Roset wrote:

> Dam a écrit :
>> [quoted text muted]

>
> Thanks for your help but I already know that.
> I think the 2.4.x kernel don't support the IPSec masquerading or NAT
> traversal.
> Is there a patch somewhere for kernel 2.4.x that allow IPSec masquerade
> or NAT traversal ?
>
> Olivier.



http://www.openswan.org/code/

--tim
 
Reply With Quote
 
Olivier Roset
Guest
Posts: n/a

 
      06-19-2005, 04:26 PM
Tim Lingard a écrit :
> On Wed, 01 Jun 2005 14:01:04 +0200, Olivier Roset wrote:
>
>
>>Dam a écrit :
>>
>>>[quoted text muted]

>>
>>Thanks for your help but I already know that.
>>I think the 2.4.x kernel don't support the IPSec masquerading or NAT
>>traversal.
>>Is there a patch somewhere for kernel 2.4.x that allow IPSec masquerade
>>or NAT traversal ?
>>
>>Olivier.

>
>
>
> http://www.openswan.org/code/


Yes, It was the solution.
Now, it's ok.
Thanks for your help.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Native ipsec in 2.6 kernel and openS/WAN guruteck@gmail.com Linux Networking 0 07-31-2006 05:40 AM
IPSec (i.e. Freeswan 2.x), Linux kernel 2.6 no longer masquerading (NAT'ing) connections John T. Ellis Linux Networking 1 05-25-2004 06:56 AM
Kernel 2.6 IPSEC and Firewall Nadav Linux Networking 0 02-07-2004 10:06 PM
iptables kernel 2.6 and ip masquerade Jauss Linux Networking 0 12-08-2003 12:49 PM
VPN / ipchains / masquerade linux 2.4.22 Thijs Metsch Linux Networking 1 10-20-2003 12:24 AM



1 2 3 4 5 6 7 8 9 10 11