Re: Virtual systems using NFMARK in place of eroutes

Jim Carter <[email protected]> Tue, 6 Jan 2004 09:34:19 -0800 (PST)
Newsgroups gmane.network.freeswan.user,gmane.network.freeswan.devel
Message-ID <[email protected]>
On Tue, 6 Jan 2004, Wayne Schroeder wrote:
> an spi identifier in the nfmark field.  I went ahead and changed this to
> mark the packet with the 32bit ipv4 address of the remote gateway from
> where the packet came in.  Now I can do specific routing on this packet
> based on the nfmark (which is static, not dynamic like spi).

On cursory reading, I suspect this technique might help in the longstanding
problem with IPSec-NAT: two different NAT routers (with different public IP
addresses) assign the same private address to their respective clients.
This is very likely to happen, because any one brand of off-the-shelf
router will have the same default DHCP address range for all instances, and
most users take the default for this.

There's the detail that the SA is between the client and the concentrator,
not between the gateway (NAT box) and the concentrator, so the situation is
not quite what's envisioned in the proposal.  Thus, it's possible for two
clients to run through the same NAT box, and different SPIs have to be used
for each.

But I wanted to keep the developers' brains circulating on my problem
topic.

James F. Carter          Voice 310 825 2897    FAX 310 206 6673
UCLA-Mathnet;  6115 MSA; 405 Hilgard Ave.; Los Angeles, CA, USA 90095-1555
Email: [email protected]  http://www.math.ucla.edu/~jimc (q.v. for PGP key)