Re: [fw-wiz] ipsec nat transversal

From: Patrick M. Hausen (hausen@punkt.de)
Date: 02/20/03

  • Next message: John Adams: "Re: [fw-wiz] Query on OS hardening"
    From: "Patrick M. Hausen" <hausen@punkt.de>
    To: SimonChan@lifeisgreat.com.sg
    Date: Thu, 20 Feb 2003 10:12:48 +0100 (CET)
    

    Hi!

    > I have an existing Firewall / VPN gateway and we have remote users vpn
    > client connecting to it.
    >
    > We are in the process of putting an additional firewall in front of the
    > existing firewall.
    > If both Firewalls are running NAT, can the remote vpn client connect to the
    > 2nd Firewall.
    >
    > I understand that the term "ipsec Nat transversal" function is required on
    > the 1st firewall
    > in order to allow IPSec traffic to pass through.
    >
    > Is that Correct ?

    Both the VPN client and your existing firewall need to support
    that. NAT traversal is an IETF draft proposing to encapsulate
    IPSec packets in another layer of UDP so any NAT along the path
    doesn't try to alter the IP header (which is protected by AH).

    Look here:

    http://www.sandelman.ottawa.on.ca/ipsec/2000/07/msg00109.html
    http://www.ietf.org/internet-drafts/draft-ietf-ipsec-nat-t-ike-05.txt

    This is what google gave me at the first try, you may need to search
    a little more.

    HTH,
    Patrick

    -- 
    punkt.de GmbH         Internet - Dienstleistungen - Beratung
    Scheffelstr. 17 a     Tel. 0721 9109 -0 Fax: -100
    76135 Karlsruhe       http://punkt.de
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    


    Relevant Pages

    • Re: SNAT
      ... ISA2K always performs NAT between LAT and> the rest of interfaces when works in firewall or integrated mode. ... Clear the default gateway property at the clients IP configuration thus> making them to not be a snat client. ... To grant internet access for those> computers you have to make them either firewall or webproxy client. ...
      (microsoft.public.isa)
    • Re: SNAT
      ... NATing could cause any problems with outbound/inbound internet access. ... Get rid of your external NAT box. ... Choose the upcoming ISA2K4 as your firewall solution. ... computers you have to make them either firewall or webproxy client. ...
      (microsoft.public.isa)
    • Re: VPN not working when client behind another firewall
      ... The latest is that we have tested the ports and GRE ... >place a hardwarebased firewall router out in front of SBS ... This area is NAT-T over IPSec across ... >server to work when behind a NAT. ...
      (microsoft.public.windows.server.sbs)
    • Presentation: Bypassing client application protection techniques with notepad
      ... Bypassing client application protection techniques ... Kerio Personal Firewall 4.0 ... Last years were revolutionary for network services infrastructure ...
      (NT-Bugtraq)
    • Presentation: Bypassing client application protection techniques with notepad
      ... Bypassing client application protection techniques ... Kerio Personal Firewall 4.0 ... Last years were revolutionary for network services infrastructure ...
      (Bugtraq)