Re : OpenBSD ipsec gateway behind a router

2011-11-19 Thread Mik J
> MJ> LAN1 (192.168.10.0/24) <--> OpenBSD .99 <--> .254 Router IPx <--> Internet <--> IPy IPSec_GW (Vendor) <--> LAN2 (192.168.20.0/24) > MJ> As you can see the OpenBSD 4.9 server sits on the LAN1 and has one physical interface. > MJ> When it wants to access to the internet, its address 192.168.10.

Re : OpenBSD ipsec gateway behind a router

2011-11-17 Thread Mik J
ot. Also, if two ipsec gateways > are not natted but I want to force nat-t would that be possible ? > > > Thanks > > > > - Mail original - >> De : Joosep >> @ : misc@openbsd.org >> Cc : >> Envoyi le : Lundi 14 Novembre 2011 14h08 >> Objet : Re:

Re: OpenBSD ipsec gateway behind a router

2011-11-16 Thread Mentesan
would that be possible ? > Thanks > > > > ----- Mail original - >> De : Joosep >> @ : > misc@openbsd.org >> Cc : >> Envoyi le : Lundi 14 Novembre 2011 14h08 >> Objet : > Re: OpenBSD ipsec gateway behind a router >> >> On Mon, Nov 14

Re : OpenBSD ipsec gateway behind a router

2011-11-16 Thread Mik J
nal - > De : Joosep > @ : misc@openbsd.org > Cc : > Envoyi le : Lundi 14 Novembre 2011 14h08 > Objet : Re: OpenBSD ipsec gateway behind a router > > On Mon, Nov 14, 2011 at 2:00 PM, Mentesan wrote: > >> Hi :) >> >> I'm trying to do exactly this setu

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Mentesan
Hello, Can anyone validate, or give some advice in this setup: LAN (10.20/16) <> OpenBSD (public fixed IP) <--> (public dynamic IP) LAN ROUTER <-> OpenBSD <-> LAN (10.10.11/24) There's a *need* to have that "LAN ROUTER" on the client side. Let's call the first OpenBSD box "Server

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Boris Goldberg
Hello Mik, Sunday, November 13, 2011, 8:06:32 AM, you wrote: MJ> I would like to know if such configuration is possible. MJ> LAN1 MJ> (192.168.10.0/24) <--> OpenBSD .99 <--> .254 Router IPx <--> Internet <--> IPy MJ> IPSec_GW (Vendor) <--> LAN2 (192.168.20.0/24) MJ> As you can see the OpenBSD

Re : OpenBSD ipsec gateway behind a router

2011-11-14 Thread Mik J
voyi le : Lundi 14 Novembre 2011 13h00 > Objet : Re: OpenBSD ipsec gateway behind a router > > Hi :) > > I'm trying to do exactly this setup, between two OpenBSD boxes - 4.4 > (central > office) and 4.9 (branch office). > With the following setup I can bring the tunnel

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Joosep
On Mon, Nov 14, 2011 at 2:00 PM, Mentesan wrote: > Hi :) > > I'm trying to do exactly this setup, between two OpenBSD boxes - 4.4 > (central > office) and 4.9 (branch office). > With the following setup I can bring the tunnel up, but the networks can't > talk to each other: > > Central ipsec.conf

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Mentesan
Hi :) I'm trying to do exactly this setup, between two OpenBSD boxes - 4.4 (central office) and 4.9 (branch office). With the following setup I can bring the tunnel up, but the networks can't talk to each other: Central ipsec.conf - ike passive esp tunnel from 10.20.0.0/16

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Stuart Henderson
This basically works but there are incompatibilities between nat-t in OpenBSD and that from certain vendors, notably cisco. On 2011-11-13, Mik J wrote: > Hello, > > I would like to know if such configuration is possible. > > LAN1 > (192.168.10.0/24) <--> OpenBSD .99 <--> .254 Router IPx <--> Int

OpenBSD ipsec gateway behind a router

2011-11-13 Thread Mik J
Hello, I would like to know if such configuration is possible. LAN1 (192.168.10.0/24) <--> OpenBSD .99 <--> .254 Router IPx <--> Internet <--> IPy IPSec_GW (Vendor) <--> LAN2 (192.168.20.0/24) As you can see the OpenBSD 4.9 server sits on the LAN1 and has one physical interface. When it wants to