Re: letting traffic flow through a SG by default
Jim Carter <[email protected]> Thu, 13 Mar 2003 11:04:44 -0800 (PST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 12 Mar 2003, Michael Richardson wrote: > The solution to above is to make sure that packets emerging from KLIPS > are marked in some way with the tunnel that they came from. This is currently > done in 2.xx by setting the nfmark bits with the SAref value. (Mind you, > there is no convincing test for this yet, so it might not work) That's good news. Now I have to figure out how to get conntrack to recognize packets from the same address (192.168.0.1) but with different marks to be considered as different connections, for the purpose of NAT as the packet leaves the secure gateway. And, of course, for it to put the right marks on de-NATted answer packets, so KLIPS can (in theory) route them to the correct tunnel. Just trying to make sure that it isn't forgotten, that people with closed-source residential gateways with NAT would also like to participate in the "privacy by default" movement. James F. Carter Voice 310 825 2897 FAX 310 206 6673 UCLA-Mathnet; 6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA 90095-1555 Email: [email protected] http://www.math.ucla.edu/~jimc (q.v. for PGP key)