Re: Completely transparent VPN between NATed sites
"Dave Howe" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
René Matthäi wrote: > Hi, > > do you think it is generally possible to run a setup such as > LAN-A ----- FW/NAT =====(internet)===== FWL/NAT ----- LAN-B > 192.168.1.x 192.168.2.x > so that _everything_ works, including FTP, LDAP, H.323...? remove the "nat" part of the equation (for the vpn at least) and the answer is yes, it is almost trivial. The box FW/NAT really needs to be FW/NAT/VPN - so that it knows to NAT traffic to the raw internet, but VPN traffic to the other lan; then, LAN-A hosts will see LAN-B hosts at their original IP addresses. I have had such a solution up and running using two (discarded) P60s, adsl, and the Bering distribution of LEAF.