You can do one thing on the server side: assign an IP address to the client and do NAT in the tunnel.
This approach saves you the need to implement address allocation extensions in KE protocols :) (IIRC IKEv1 has no standard address allocation feature.) Nico -- _______________________________________________ IPsec mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipsec
