[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ESP over UDP



At 09:05 10.8.1999 -0400, you wrote:
>You've got it backwards -- UDP runs over ESP, not the
>other way around.  Although you are correct in saying that
>ISAKMP runs over UDP.  That is true.
>
>The problem is that you are using IP Masquerade.  You will have
>trouble with IPSec across a NAT.  There are a couple of patches
>that exist for Linux to try to get IPSec working across the NAT:
>
>ftp://ftp.rubyriver.com/pub/jhardin/masquerade/ip_masq_vpn.html
>
>-derek
>

I need to run IPsec over every available IP masquerading 
implementation in the world, and therefore I have to send
ESP packets as UDP payloads. Trust me, I know what I'm doing. (tm)

Jörn



Follow-Ups: References: