this is true, however, provisions have been made with
the patch that allow IKE-based sessions to be
masqueraded, and generally, VPN sessions.. surely the
patch must have put this into consideration...
however, i think i should generalise and say, VPN
connections.. how can these be masq'ed..?..
thanks.. AKNIT
--- Torsten Mueller
Mark Tinka schrieb:
hi list...
i have a user with a VPN client, Checkpoint, using
the
IKE algorithm behind a SuSE 7.2 Pro system with a stock 2.2.19 kernel, being masqueraded to the net using ipchains.... ...
If i remember correctly, you can't use IPSec with masquerading, cause the IP Headers are changed in the masquerading and IPSec also sends a "checksum" which isn't o.k. after masquerading.
But only my 2 cents.
Torsten
__________________________________________________ Do You Yahoo!? Everything you'll ever need on one web page from News and Sport to Email and Music Charts http://uk.my.yahoo.com