>
> So the question on "what did you expect" may be that you were surprised
> either way if you expected normal routing rules when iked doesn't do
> normal, or expecting isakmpd behaviour if iked is different.
>
> Yes, I would say, question is not what I expected, but what I did not
> expected.
>
> If we have tunnel between 1.1.1.1 and 2.2.2.2, the packet from lan goes to
> router, src address is natted to 1.1.1.1 and after that, it supposed to go
> to 2.2.2.2 through ipsec link as if src address is 1.1.1.1, but it does
> not.
> This is what I did not expected, and this is the main question, why is it
> like that?
>

Because ipsec is looking at the packet immediately as it enters, matching
only against FROM and DEST. If it matches exactly it steals the packet and
encrypts and sends it off encrypted.

Nat:ing on the other hand is done late, when the routing decisions already
have decided that the packet is for 2.2.2.2 and is about to leave on the
interface best suited to reach the network containing 2.2.2.2, and the
outgoing packets source ip gets rewritten to the 1.1.1.1 interface IP so
the return path becomes correct. So the two parts (ipsec and source-nat)
are working at completely different levels and parts of the whole tcp/ip
stack.

-- 
May the most significant bit of your life be positive.

Reply via email to