Re: Virtual systems using NFMARK in place of eroutes
Jim Carter <[email protected]> Tue, 6 Jan 2004 09:34:19 -0800 (PST)
| Newsgroups | gmane.network.freeswan.user,gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 6 Jan 2004, Wayne Schroeder wrote: > an spi identifier in the nfmark field. I went ahead and changed this to > mark the packet with the 32bit ipv4 address of the remote gateway from > where the packet came in. Now I can do specific routing on this packet > based on the nfmark (which is static, not dynamic like spi). On cursory reading, I suspect this technique might help in the longstanding problem with IPSec-NAT: two different NAT routers (with different public IP addresses) assign the same private address to their respective clients. This is very likely to happen, because any one brand of off-the-shelf router will have the same default DHCP address range for all instances, and most users take the default for this. There's the detail that the SA is between the client and the concentrator, not between the gateway (NAT box) and the concentrator, so the situation is not quite what's envisioned in the proposal. Thus, it's possible for two clients to run through the same NAT box, and different SPIs have to be used for each. But I wanted to keep the developers' brains circulating on my problem topic. James F. Carter Voice 310 825 2897 FAX 310 206 6673 UCLA-Mathnet; 6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA 90095-1555 Email: [email protected] http://www.math.ucla.edu/~jimc (q.v. for PGP key)