Re: best open NAT-T?

Philipp Buehler <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
On 18/08/2003, David Newman <[email protected]> wrote To [email protected]:
> For an IPSec gateway I'm building, which is the most robust/mature/stable
> open-source code that supports NAT traversal?

please note, that there are possible patent violations if this get's
implemented:

http://www.ietf.org/ietf/IPR/MICROSOFT-NAT-Traversal.txt

and some other i've no URL at hand right now,
it boils down that plain ESP-in-UDP is "free" but -in-TCP would
require a checksum fixup of the inner TCP header after decrypt/decapsulation.

> I am equally illiterate in FreeBSD, OpenBSD, and Linux, so platform choice
> is not important.

for OpenBSD there are inofficial patches, I'd send you - totally
unsupported so far, of course :)

> NAT-T support is required since we sometimes need to tunnel in from client
> sites that themselves use NAT.

<rant>
Say thanks to the IETF that more and more patent "poisoned" techniques
(which are almost pretty generic) can go into an official draft/rfc
</rant>

Ciao
-- 
Philipp Buehler, aka fips | sysfive.com GmbH | BOfH | NUCH | <double-p> 

#1: Break the clue barrier!
#2: Already had buzzword confuseritis ?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.