Re: isakmpd, preventing subnet clashing using NAT

2005-12-04 Thread Markus Wernig
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 nat on enc0 inet from 192.168.A.A/24 to B.B.B.B/8 - 172.C.C.C Hi Realname not known What do you see if you don't use the nat statement? Do packets from 192.168 get sent to B.B over enc0? If not you still have some other problem. How do you and

Re: isakmpd, preventing subnet clashing using NAT

2005-12-04 Thread OpenBSD-List
hey markus, thanks for your reply. no traffic on enc0 without the nat statement. i too suspect, that its not nat which is giving me headaches. our_fw and ASP_peer auth using a pre-shared key, if thats what you were asking. the tunnel gets established without any glitches. at least isakmpd in

isakmpd, preventing subnet clashing using NAT

2005-12-03 Thread OpenBSD-List
hello people, i'm trying to setup a vpn between us and our ASP. they've assigned us their own private rfc11918 addresses, from which they want us to connect from. basically our topology looks like depicted below: our_internal -- our_fw -- internet -- ASP_peer -- ASP_internal our_internal is