Networking Forums

Networking Forums > Computer Networking > Linux Networking > Racoon with SNAT

Reply
Thread Tools Display Modes

Racoon with SNAT

 
 
Can2002
Guest
Posts: n/a

 
      07-08-2005, 09:14 AM
I have established an IPSEC tunnel between a Linux host and a Check Point
firewall using the inbuilt IPSEC support of the 2.6 kernel together with
Racoon.

My problem is that I have two networks behind the Linux host, one of which
conflicts with the subnet behind the CP firewall. I only need to initiate
connections from the Linux side on the conflicting network, so I want to
translate the source IP of packets passing over the tunnel to that of my
other Linux-based network.

I've created the NAT rule (using fwbuilder); however the firewall is routing
the packet rather than passing it over the IPSEC tunnel.

Does anyone know if what I'm trying to achieve is possible on my Linux host?

Cheers,
Can


 
Reply With Quote
 
 
 
 
Bill Davidsen
Guest
Posts: n/a

 
      08-10-2005, 05:25 PM
Can2002 wrote:
> I have established an IPSEC tunnel between a Linux host and a Check Point
> firewall using the inbuilt IPSEC support of the 2.6 kernel together with
> Racoon.
>
> My problem is that I have two networks behind the Linux host, one of which
> conflicts with the subnet behind the CP firewall. I only need to initiate
> connections from the Linux side on the conflicting network, so I want to
> translate the source IP of packets passing over the tunnel to that of my
> other Linux-based network.
>
> I've created the NAT rule (using fwbuilder); however the firewall is routing
> the packet rather than passing it over the IPSEC tunnel.
>
> Does anyone know if what I'm trying to achieve is possible on my Linux host?


Assuming this is still of interest (I haven't been following the group)
I think you can use the MARK feature to identify the packets to be sent,
and then source routing to force the packets out the tunneled interface.

--
bill davidsen
SBC/Prodigy Yorktown Heights NY data center
http://newsgroups.news.prodigy.com
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Racoon problems nickscott Linux Networking 0 08-30-2010 03:12 AM
VPN with racoon Phase 2 issue xscream@gmail.com Linux Networking 6 03-04-2008 12:45 PM
IPsec tunnel using racoon dee Linux Networking 2 07-16-2007 08:53 AM
Racoon ---> NetScreen (Help PLZ). Saad Malik Linux Networking 0 09-02-2004 05:18 PM
Racoon routing Hans Fugal Linux Networking 0 06-03-2004 07:59 PM



1 2 3 4 5 6 7 8 9 10 11