Hi, On Tue, Jun 04, 2013 at 08:19:21AM +0200, Gerhard Wiesinger wrote: > I've a usecase with OpenVPN and NAT with UDP where the commercial firewall > changes NAT binding. Keep alive is 30s, so short enough. Also float option > doesn't help because it accepts packets but doesn't do the source port > change. Details find below. This behaviour is reproduceable on different > installations with this firewall.
Use a different firewall? Use "ping 10 30" on the client to keep the NAT state alive? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany g...@greenie.muc.de fax: +49-89-35655025 g...@net.informatik.tu-muenchen.de
pgpAOb7w6gxtx.pgp
Description: PGP signature