/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hi,
I have a problem connecting to a CheckPoint FW1 VPN server on the
internet, from a masqueraded client machine in my intranet.
The masquerade works well, the client can connect to the server and
exchanges keys, but when it comes to the actual authentication and
traffic tunnelling, it fails.
I recorded a few sample sessions with tcpdump, and found that the problem
could be in the fact that the authentication is performed using
UDP packets, source port == dest port == 259.
Since they come thru the masquerade, their source port changes and it
may actually be that that fucks up the session.
Anyone ever experienced the same problems, and if so, any idea how to
fix that? I'd go and fix ip_masq.c by hand in the kernel, but there
may be a better way of doing it. (and oh yes, i could do it since
I only have 1 machine using securemote in the intranet, so no worry
about multiple sessions to handle).
Thanks,
nicolas
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.