Re: letting traffic flow through a SG by default

Jim Carter <[email protected]> Thu, 13 Mar 2003 11:04:44 -0800 (PST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
On Wed, 12 Mar 2003, Michael Richardson wrote:
>   The solution to above is to make sure that packets emerging from KLIPS
> are marked in some way with the tunnel that they came from. This is currently
> done in 2.xx by setting the nfmark bits with the SAref value. (Mind you,
> there is no convincing test for this yet, so it might not work)

That's good news.  Now I have to figure out how to get conntrack to
recognize packets from the same address (192.168.0.1) but with different
marks to be considered as different connections, for the purpose of NAT as
the packet leaves the secure gateway.  And, of course, for it to put the
right marks on de-NATted answer packets, so KLIPS can (in theory) route
them to the correct tunnel.

Just trying to make sure that it isn't forgotten, that people with
closed-source residential gateways with NAT would also like to participate
in the "privacy by default" movement.

James F. Carter          Voice 310 825 2897    FAX 310 206 6673
UCLA-Mathnet;  6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA  90095-1555
Email: [email protected]    http://www.math.ucla.edu/~jimc (q.v. for PGP key)