[fw-wiz] NAT vs. GRE tunnel

From: Milon Papezik (mmp_at_actinet.cz)
Date: 08/27/03

  • Next message: Bartek Krajnik: "Re: Setting up H323 IP telephony etc - was Re: [fw-wiz] Apple's iSight and Firewalls"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Wed, 27 Aug 2003 21:03:07 +0200
    
    

    Hi all,

    one of our customers asked me following questions:

    Is it possible to pass GRE tunnel throught a many-to-one NAT (hide NAT, PAT) ?
    What FW product is capable of processing such conversion "transparently"?

    I reviewed both RFC 1701 and RFC 2784 and I came to conclusion that it is not
    generally possible by definition of GRE tunnel to translate it through NAT.

    What would be your expert's answer ?

            Thanks in advance for any thoughts,
            Milon

    --
    mmp@actinet.cz
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Bartek Krajnik: "Re: Setting up H323 IP telephony etc - was Re: [fw-wiz] Apple's iSight and Firewalls"

    Relevant Pages

    • Re: GRE tunnel with NAT information
      ... I'm looking to find information on creating a GRE tunnel with NAT. ... Private IP's and public IP's. ... CCO search of "GRE tunnel configuration" will yeild you ...
      (comp.dcom.sys.cisco)
    • Re: Symantec Enterprise (Raptor)
      ... > Have you running your VPN through a GRE tunnel? ... >> I'm working on setting up VPN for a Raptor Firewall, ... >> I'm using NAT, and it is all set up just like the book wants me to. ...
      (comp.security.firewalls)
    • Re: PPTP VPN pass-thru
      ... establish a GRE tunnel. ... For this to work with NAT, ... able to NAT GRE traffic. ... the router has to be able to NAT AH/ESP traffic. ...
      (uk.comp.sys.mac)
    • Re: PPTP VPN pass-thru
      ... establish a GRE tunnel. ... For this to work with NAT, the router must be able to NAT GRE traffic. ... the initial authentication and negotiation is done using UDP on port 500, then the 2 end-points establish either an AH or ESP tunnel, and again for this to work with NAT, the router has to be able to NAT AH/ESP traffic. ...
      (uk.comp.sys.mac)
    • Re: Order significance for PIX nat / global statements?
      ... >> Studying PIX firewall configuration I'm confused by some contradictions ... > addition to the two nat statements shown above. ... >> PAT address pool? ... > The PIX will NAT first, then PAT. ...
      (comp.security.firewalls)